Compliance & model licensing
Last updated
The answers procurement and security review usually ask for, in one place. If something you need is missing, ask us rather than assuming the answer.
1. Model licensing
Every model we serve is open-weight and published under its own licence. We do not serve proprietary models through undisclosed arrangements, and nothing in your stack depends on a grey-area resale relationship.
The model’s licence governs your use of its output. Our terms do not override it. Most licences here are permissive, but some carry conditions — acceptable-use clauses, attribution, or restrictions above a user-count threshold. If your use is commercial, read the licence for the specific model you intend to use.
| Model | Publisher | Licence |
|---|---|---|
| Qwen-Image | Alibaba | Apache 2.0 |
| Qwen3 235B A22B | Alibaba | Apache 2.0 |
| Qwen3 Embedding 8B | Alibaba | Apache 2.0 |
| Qwen3 Max Instruct | Alibaba | Apache 2.0 |
| Wan 2.2 I2V A14B | Alibaba | Apache 2.0 |
| Wan 2.2 T2V A14B | Alibaba | Apache 2.0 |
| BGE-M3 | BAAI | MIT |
| FLUX.2 [schnell] | Black Forest Labs | Apache 2.0 |
| DeepSeek V4 Flash | DeepSeek | MIT |
| DeepSeek V4 Pro | DeepSeek | MIT |
| Mochi 1 | Genmo | Apache 2.0 |
| HiDream-I1 | HiDream | MIT |
| LTX-2.5 | Lightricks | LTXV Open Weights |
| Llama 4 Maverick | Meta | Llama 4 Community |
| MiniMax M2 | MiniMax | MIT |
| Mistral Large 3 | Mistral AI | Apache 2.0 |
| Kimi K2.6 | Moonshot AI | Modified MIT |
| Kimi K3 | Moonshot AI | Modified MIT |
| GPT-OSS 120B | OpenAI | Apache 2.0 |
| Stable Diffusion 3.5 Large | Stability AI | Stability Community |
| HunyuanVideo 1.5 | Tencent | Tencent Hunyuan Community |
| GLM-5.2 | Z.ai | MIT |
| GLM-5.2 Air | Z.ai | MIT |
| CogVideoX-5B | Zhipu AI | Apache 2.0 |
2. Data handling
We bill on metadata, not content. Prompts and outputs are not written to our long-term stores, do not appear in usage history, and are never used to train any model. The privacy policy states this in full, including the two exceptions.
Retention windows, subprocessors and international transfer mechanisms are set out at /privacy#retention. We will sign a DPA; request one at affiliate@xark.io.
3. Security practices
- TLS for all traffic, in transit end to end.
- API keys stored as hashes. A key is displayed once, at creation, and cannot be recovered afterwards — only rotated.
- Per-key spending caps, so a leaked key has a bounded blast radius.
- Least-privilege access to production, limited to staff who need it, and logged.
- Authentication delegated to Clerk, which supports SSO, MFA and session revocation. We never handle your password.
- Card data handled entirely by a PCI-DSS compliant processor. Full card numbers never reach our systems.
We do not currently hold a SOC 2 or ISO 27001 attestation, and we are not going to imply otherwise. If your procurement process requires one, tell us at affiliate@xark.io so we can tell you where that work stands rather than leaving you to guess.
4. Vulnerability disclosure
Report security issues to affiliate@xark.io. Include enough detail to reproduce. We acknowledge within two business days and will keep you updated until it is resolved.
We will not pursue legal action over good-faith research that respects user privacy, avoids degrading the service, and does not access, modify or exfiltrate data belonging to anyone other than you. Please give us a reasonable window to fix an issue before publishing.
5. Acceptable use
Prohibited uses are listed in the terms of service. In summary: nothing illegal, no CSAM, no non-consensual intimate imagery, no targeted harassment, no malware, no impersonation intended to deceive.
Report abuse originating from the platform to affiliate@xark.io.
6. Export control and sanctions
The service is not available to users in jurisdictions subject to comprehensive sanctions, or to parties on applicable restricted-party lists. By using it you confirm you are not such a party and will not re-export access in violation of applicable law.
7. Incidents
Live service status is at /status. For a security incident affecting your data, we notify affected account holders by email without undue delay, and regulators where the law requires it — including within 72 hours under the GDPR.