xAI has published details regarding its API security practices, data handling policies, and compliance certifications. The information addresses how customer data is used, stored, and protected when interacting with xAI's API.
The company clarifies its stance on training models with customer data and provides guidance on managing API keys and monitoring account activity.
Key Points
- xAI does not train on customer API inputs or outputs without explicit permission.
- API requests and responses are temporarily stored on xAI servers for 30 days for audit purposes.
- This stored data is automatically deleted after 30 days.
- xAI is SOC 2 Type 2 compliant.
- Customers with a signed NDA can access the Trust Center for certification and data governance information.
- Team admins can view an audit log of user interactions with the API server via the xAI Console.
- xAI partners with GitHub's Secret Scanning program to detect leaked API keys.
Context
According to xAI, the company provides specific policies regarding the use of customer data submitted through its API. This includes a clear statement on model training and a defined retention period for API request and response data. The company also highlights its compliance with industry security standards and offers tools for administrators to monitor API usage.
Why It Matters
Builders and organizations deploying applications with xAI's API need to understand the company's data privacy and security policies. This information helps in assessing compliance, managing sensitive data, and implementing secure practices for API key management.
What To Do
- Note xAI's policy on not training on API requests without explicit permission.
- Review the 30-day data retention policy for API requests and responses.
- For organizations requiring specific agreements, complete the BAA Questionnaire.
- If you are an admin, familiarize yourself with the audit log feature in the xAI Console.
- Implement secure practices for API key management, including regular rotation and avoiding public exposure.
- Watch for notifications from xAI regarding leaked keys detected by GitHub's Secret Scanning program.
