90 Days Gen AI Risk Trial -Start Now
Book a demo
Image Gen·API credit-based (1 credit = $0.01); SDXL ~$0.002-0.01/image; self-host free·stability.ai

Stable Diffusion XL

Stability AI's open-weight text-to-image model, usable via the official Stability Developer Platform API, self-hosted, or through dozens of third-party inference providers.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Stable Diffusion XL (SDXL) is Stability AI's 3.5-billion-parameter open-weight text-to-image model, released under a permissive community license and widely deployed for product imagery, game assets, and marketing visuals. The official Stability AI Developer Platform offers SDXL behind a credit-based API ($0.002-$0.01 per image depending on model) alongside SD 3.5 and Stable Image Ultra. Because weights are openly distributed, enterprises encounter SDXL across three distinct surfaces: the Stability AI API (SOC 2 Type II and SOC 3 certified as of 2024), self-hosted deployments on internal GPUs, and third-party re-sellers with widely varying privacy practices. The Stability API default tier scored here does not train on customer inputs and retains data for up to one year per the privacy policy.

Risk factors

3
  • API usage may involve third-party data handling
  • Potential for data training on user inputs
  • No clear enterprise controls mentioned

Recommendations

8
  • If using the API, route through the official Stability Developer Platform (SOC 2 Type II)
  • Require DPA signature before any production workload
  • Inventory all internal SDXL deployments, including self-hosted ComfyUI and Automatic1111 instances
  • Block known unvetted third-party SDXL gateways at the network egress
  • Implement prompt and output logging for audit and IP-review purposes
  • Keep safety and NSFW filters enabled in all sanctioned deployments
  • Review the SDXL community license against expected commercial revenue thresholds
  • Attach C2PA or watermarking to all externally published assets

Data handling

Storage
Stability Developer Platform hosted on AWS US regions; Trust Center publishes SOC 2 Type II and SOC 3 reports.
Retention
Personal information retained no longer than one year per privacy policy; API prompts not retained beyond operational needs.
Training on inputs
Stability AI Developer Platform API does not use customer prompts or outputs to train models by default. Self-hosted deployments are fully customer-controlled.