Contact
Implement · Together AI

Can you run it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input B ยท 75.2/100

This page is a projection of the one entry record, the Doesn't fail you and Data control factors that Implement covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Doesn't fail you
  • UseDoesn't fail you
  • SupportTransparency

API integration

Together's OpenAI-compatibility docs (read this session) describe an OpenAI-compatible /v1 REST API at api.together.ai/v1 alongside Python and TypeScript SDKs. The practical consequence is that an existing OpenAI client integrates by changing the base URL and API key

  • chat/completions, streaming, tool use and structured outputs follow familiar shapes, so integration is largely a configuration change rather than a rewrite. One gotcha the docs flag: Together model IDs are namespaced (e.g. openai/gpt-oss-20b), so bare OpenAI model strings return a 404.

Authentication & account setup

Per the same docs, authentication uses a bearer API key (TOGETHER_API_KEY) supplied to the OpenAI-compatible client. Fine-grained organisation/project key scoping and rotation policy were not detailed in the sources read this session, so if key-scoping is a control requirement, confirm the available granularity in the account console before rollout.

Region & ZDR configuration

Zero data retention is the default posture per the Privacy Policy, so no toggle is needed for the core no-store behaviour. Together's support KB shows that EU region selection and dedicated region-pinned endpoints are gated to the Scale/Enterprise tiers - they are provisioned commercially rather than flipped on in a self-serve settings panel. Plan for a sales/onboarding step if EU residency is mandatory.

Portability & exit

Because Together speaks the OpenAI-compatible API (documented and read this session) over portable open-weight checkpoints, the exit path is clean: independent third-party analysis confirms the same Llama / DeepSeek / Qwen / Mistral / gpt-oss models run across many providers and self-hosted stacks. Switching cost is dominated by re-pointing the base URL and re-validating outputs, not by re-engineering - the strongest argument for adopting an open-weight inference provider over a closed API.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

3

Doesn't fail youDoes it stay up and stay secure?

Moderate

SOC 2 Type II is announced via an independent audit and the security docs describe encryption and pen-testing, but there is no public uptime SLA, status page or SOC 2 report obtained this session.

How this scores (AOI sub-dimensions)
Reliability2/5whether it stays up, with an SLA and status historyNo incidents surfaced in research, but no public uptime SLA, status page or failover documentation was found or independently verified this session.
Security4/5the controls protecting your traffic and dataThe SOC 2 announcement and security docs describe encryption in transit and at rest, audit logging, MFA/RBAC and regular pen-testing, and the DPA requires encryption of controller data in transit and storage.
Compliance4/5which independent certifications and attestations it holdsSOC 2 Type II is announced via an independent multi-month audit, and a GDPR DPA (read this session) binds Together to EU Standard Contractual Clauses.
4

Doesn't extract your dataDo the binding terms keep your data and IP yours?

Moderate

The Terms (read this session) leave you owning Your Content and Output, and ZDR-by-default with training opt-in/off keeps your data yours - but the no-retention guarantee is self-attested, and the US HQ plus DPA-confirmed North America default routing carry standing CLOUD Act exposure even for EU-hosted workloads.

How this scores (AOI sub-dimensions)
Data governance4/5retention, training-on-inputs and data ownershipGrounded in the binding Privacy Policy and Terms of Service, both read this session: inputs and outputs are not stored by default (ZDR), training on your data requires explicit org-admin opt-in and is off by default, and you retain ownership of Your Content and Output.
Residency4/5where your data is processed and storedA support KB (read this session) confirms EU data centres and dedicated endpoints including EU locations, and the DPA confirms EU transfers under SCCs.
What this means for adoptionYou own your workloads here in the ways that matter most: the Terms leave you owning your inputs and outputs, ZDR-by-default with no-training keeps them yours, and the open-weight catalogue on an OpenAI-compatible API is a clean portable exit. But overall ownership is partial, not substantial: the no-retention posture is Together's own self-attestation rather than independently audited, and the US HQ with DPA-confirmed North America default routing carries standing CLOUD Act exposure even for EU-hosted workloads, so data-control is moderate rather than strong. Pin the EU region on a paid tier if residency matters, and teams needing an audited no-retention guarantee should contract it in the DPA rather than rely on the default terms.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Privacy Policyread2026-07-25
Privacy Policy: inputs and outputs are not stored by default (zero data retention); under ZDR content is not stored, retained, or used for model training or product improvement except as needed to provide the Services; temporary caching may be used for performance; training on data is opt-in and off by default, controlled by an org-admin Privacy & Security setting.
Documentationread2026-07-25
Privacy and security docs: HIPAA-aligned data encryption in transit and at rest, audit logging and business associate agreements; layered security architecture with MFA/RBAC, continuous monitoring and regular vulnerability assessments; ZDR restated.
Vendor announcementread2026-07-25
SOC 2 Type II announcement: achieved via an independent, multi-month audit validating access management, data encryption, incident response and change management; regular penetration testing.
Documentationread2026-07-25
EU data centres and dedicated model deployment - dedicated endpoints on targeted data centres including EU locations (Sweden GPU capacity) - are available only on Scale and Enterprise tier plans.
Vendor announcementunverified2026-07-25
Serverless per-token pricing page (live rates not read from source this session): gpt-oss-120B ~$0.15/$0.60, Qwen3-235B ~$0.20/$0.60, DeepSeek-V3 ~$1.25/M - approximate and move frequently.
Documentationread2026-07-25
OpenAI-compatibility docs: an OpenAI-compatible /v1 REST API at api.together.ai/v1, used by pointing an existing OpenAI client at Together's base URL and API key (TOGETHER_API_KEY), with chat/completions, streaming, tool use and structured outputs across the open-weight catalogue.
Terms of serviceread2026-07-25
Terms of Service: as between you and Company you exclusively own all right, title and interest in Your Content and Output, granting Company only a limited license to operate them to provide the Services; Together does not use your data to train its models without your explicit opt-in and consent; the Company owns Company IP and Usage Data.
Third-party analysisread2026-07-25
Independent third-party price/performance analysis of Together AI corroborates the approximate serverless rates and shows the same open-weight models served across many providers (portability).
Data Processing Addendumread2026-07-25
Data Processing Addendum: Together (US) Inc.