Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Together AI is a US-incorporated inference operator (Together Computer, Inc.) whose default serverless serving path runs entirely on North American infrastructure, with EU-region residency available only through a separately negotiated dedicated or VPC deployment rather than by default. This structural exposure to CLOUD Act/FISA jurisdiction, combined with a subprocessor list that is only viewable through a dynamic, non-machine-verifiable trust-center widget, makes legal_exposure and serving_residency the clear weak points of this profile. Offsetting that, Together's serving-side privacy engineering is strong: zero data retention is the stated default, training on customer prompts is opt-in and off by default, and the operator holds current, sourced SOC 2 Type II, HIPAA, and ISO/IEC 27001:2022 certifications with no known breach history. A published DPA and clearly named contracting entity give reasonable contractual footing, though SCC and audit-rights specifics aren't independently confirmed. Given strong retention and security controls sitting alongside unresolved US jurisdictional and residency gaps, Stav treats Together AI as routed-only for EEA workloads on the standard serverless tier; sovereign EEA serving would require a specifically contracted dedicated/VPC deployment and confirmation of its subprocessor and SCC terms.
Default serverless inference runs on Together's own North American infrastructure with no region selection; EU-region processing exists only via a negotiated dedicated/VPC deployment, not the default serving path.
Certifications & legal documents
The contracting entity, Together Computer, Inc., is a US corporation subject to CLOUD Act/FISA regardless of deployment location, and the live subprocessor roster is only viewable via a dynamic Vanta widget rather than a verifiable static disclosure.
Zero data retention is the stated default and training on customer data is opt-in and disabled by default, though documented ambiguity around temporary performance caching slightly undercuts the strict ZDR claim.
Together holds current, sourced SOC 2 Type II, HIPAA, and ISO/IEC 27001:2022 (A-LIGN/ANAB-accredited) certifications with documented encryption, MFA, and monitoring controls, and no identified breach history.
A published DPA, Terms of Service, and Privacy Policy clearly name Together Computer, Inc. as the legal counterparty, but explicit SCC/audit-rights language and the live subprocessor list are not independently verifiable from static sources.
Risk assessment
The contracting entity is Together Computer, Inc., a US corporation, so US lawful-access regimes (CLOUD Act/FISA) apply to the operator regardless of where a given dedicated/VPC deployment's hardware physically sits. source ↗
LEGAL_EXPOSUREServerless endpoints do not offer region selection and third-party open-weight models (DeepSeek, Qwen, Mistral, etc.) served via Together run on Together's own North American data centers; EU-region processing is only available via a dedicated endpoint or negotiated private-networking/VPC deployment, not the default serving path. source ↗
DATA_RESIDENCYTogether publishes a subprocessor list at trust.together.ai/subprocessors, but the page is rendered dynamically via a Vanta trust-center widget, making the actual current sub-processor names/locations non-machine-readable/non-verifiable via a simple fetch — customers must access the interactive portal directly to review the live list. source ↗
SUBPROCESSINGTemporary caching of prompts/outputs 'may be used to improve performance unless otherwise configured' even though zero data retention is the stated default, leaving some ambiguity about what is cached, for how long, and how to fully disable it. source ↗
SERVING_RETENTIONSafeguards
Together does not store inputs/outputs by default and supports zero data retention (ZDR); training on a customer's data is opt-in and disabled by default, controlled via an organization-level privacy toggle. source ↗
Together AI holds SOC 2 Type II, HIPAA compliance (with BAAs), and ISO/IEC 27001:2022 certification (issued by A-LIGN, an ANAB-accredited body) covering its ISMS, corporate HQ, and third-party colocation/hosting data centers. source ↗
Encryption in transit and at rest, network segmentation, continuous monitoring, automated threat detection, MFA and role-based access control are documented as part of the SOC 2 Type II control set. source ↗
For customers with GDPR-driven EU-region or other data-residency requirements, Together offers private networking and VPC-based dedicated deployments, including in EU regions, on single-tenant isolated GPUs. source ↗
A Data Processing Addendum is published and downloadable, alongside published Terms of Service and Privacy Policy naming the contracting entity (Together Computer, Inc.) and a dedicated privacy contact. source ↗
Together operates a public Vanta-hosted Trust Center listing certifications and a subprocessor disclosure page. source ↗
Together AI maintains a public, third-party (Better Stack) status page for real-time and historical system performance/uptime. source ↗
Privacy-policy issues
No default EU data residency on serverless tier source ↗
Standard serverless endpoints do not allow region selection and run on Together's own North American infrastructure, so EU customers must proactively negotiate a dedicated/VPC deployment to keep inference in-region.
Ambiguous caching retention under ZDR source ↗
Temporary caching of prompts/outputs may occur to improve performance 'unless otherwise configured,' which is not fully consistent with a strict zero-data-retention claim.
Opt-in training uses customer data for third-party/partner models source ↗
If an org admin opts in, 'Allow organization's data for training' permits use of that data for training models released by Together AI and partners, not just Together's own models.