Skip to content

Compliance & model licensing

Last updated

The answers procurement and security review usually ask for, in one place. If something you need is missing, ask us rather than assuming the answer.

1. Model licensing

Every model we serve is open-weight and published under its own licence. We do not serve proprietary models through undisclosed arrangements, and nothing in your stack depends on a grey-area resale relationship.

The model’s licence governs your use of its output. Our terms do not override it. Most licences here are permissive, but some carry conditions — acceptable-use clauses, attribution, or restrictions above a user-count threshold. If your use is commercial, read the licence for the specific model you intend to use.

ModelPublisherLicence
Qwen-ImageAlibabaApache 2.0
Qwen3 235B A22BAlibabaApache 2.0
Qwen3 Embedding 8BAlibabaApache 2.0
Qwen3 Max InstructAlibabaApache 2.0
Wan 2.2 I2V A14BAlibabaApache 2.0
Wan 2.2 T2V A14BAlibabaApache 2.0
BGE-M3BAAIMIT
FLUX.2 [schnell]Black Forest LabsApache 2.0
DeepSeek V4 FlashDeepSeekMIT
DeepSeek V4 ProDeepSeekMIT
Mochi 1GenmoApache 2.0
HiDream-I1HiDreamMIT
LTX-2.5LightricksLTXV Open Weights
Llama 4 MaverickMetaLlama 4 Community
MiniMax M2MiniMaxMIT
Mistral Large 3Mistral AIApache 2.0
Kimi K2.6Moonshot AIModified MIT
Kimi K3Moonshot AIModified MIT
GPT-OSS 120BOpenAIApache 2.0
Stable Diffusion 3.5 LargeStability AIStability Community
HunyuanVideo 1.5TencentTencent Hunyuan Community
GLM-5.2Z.aiMIT
GLM-5.2 AirZ.aiMIT
CogVideoX-5BZhipu AIApache 2.0

2. Data handling

We bill on metadata, not content. Prompts and outputs are not written to our long-term stores, do not appear in usage history, and are never used to train any model. The privacy policy states this in full, including the two exceptions.

Retention windows, subprocessors and international transfer mechanisms are set out at /privacy#retention. We will sign a DPA; request one at affiliate@xark.io.

3. Security practices

  • TLS for all traffic, in transit end to end.
  • API keys stored as hashes. A key is displayed once, at creation, and cannot be recovered afterwards — only rotated.
  • Per-key spending caps, so a leaked key has a bounded blast radius.
  • Least-privilege access to production, limited to staff who need it, and logged.
  • Authentication delegated to Clerk, which supports SSO, MFA and session revocation. We never handle your password.
  • Card data handled entirely by a PCI-DSS compliant processor. Full card numbers never reach our systems.

We do not currently hold a SOC 2 or ISO 27001 attestation, and we are not going to imply otherwise. If your procurement process requires one, tell us at affiliate@xark.io so we can tell you where that work stands rather than leaving you to guess.

4. Vulnerability disclosure

Report security issues to affiliate@xark.io. Include enough detail to reproduce. We acknowledge within two business days and will keep you updated until it is resolved.

We will not pursue legal action over good-faith research that respects user privacy, avoids degrading the service, and does not access, modify or exfiltrate data belonging to anyone other than you. Please give us a reasonable window to fix an issue before publishing.

5. Acceptable use

Prohibited uses are listed in the terms of service. In summary: nothing illegal, no CSAM, no non-consensual intimate imagery, no targeted harassment, no malware, no impersonation intended to deceive.

Report abuse originating from the platform to affiliate@xark.io.

6. Export control and sanctions

The service is not available to users in jurisdictions subject to comprehensive sanctions, or to parties on applicable restricted-party lists. By using it you confirm you are not such a party and will not re-export access in violation of applicable law.

7. Incidents

Live service status is at /status. For a security incident affecting your data, we notify affected account holders by email without undue delay, and regulators where the law requires it — including within 72 hours under the GDPR.