Orbiq

← Trust & governance

Vendor Risk Assessment — Groq

The review of the AI provider: what it receives, where it processes, and the no-store / no-train terms that make that acceptable.

Version
Approved (with mitigations)
Effective
April 13, 2026
Compliance mapping
CSA STAR STA

Download as PDF

Published with a small redaction set applied — a neighbourhood-level address, an internal contact alias, and the names of infrastructure components whose exposure would help an attacker. Nothing about what we do with your data is removed.

Vendor Risk Assessment: Groq Inc.

Vendor Name: Groq Inc.

Service Provided: AI-driven financial transaction categorization.

Assessment Date: April 13, 2026

Status: Approved (with mitigations)

1. Data Processing Context

2. Technical Safeguards & Certifications

3. Contractual & Regulatory Controls

4. Residual Risk & Mitigations

Risk Factor Assessment Orbiq Mitigation
US CLOUD Act US authorities may legally compel access to data on US soil. Prompt Sanitization: The data sent is de-identified, making it useless to authorities without the local Orbiq database.
Data Residency Data leaves Canada for processing in the US. Disclosure & Consent: Users are notified of US processing during onboarding and in the Privacy Policy.
Model Leakage Risk of prompts being used for global model training. ZDR Policy: Groq's contractual ZDR policy explicitly forbids training on API inference data.

5. Continuous Oversight Plan