90 Days Gen AI Risk Trial -Start Now
Book a demo
Image Gen·API credits ($0.01/credit); Community License free under $1M ARR; Enterprise custom·stability.ai

Stable Diffusion

Stable Diffusion is Stability AI's family of open-weights diffusion models (SD 3.5, SDXL, Stable Image) accessible as downloadable weights or via Stability's hosted API platform.

Risk Score
Low
3/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Stable Diffusion refers to Stability AI's broad family of diffusion models for image generation, including Stable Diffusion 3.5 (Medium, Large, Large Turbo) and Stable Image Ultra. Models are distributed under the Stability AI Community License (free for research, non-commercial, and commercial use under $1M ARR) and an Enterprise License for larger organizations, plus a hosted Developer Platform API at platform.stability.ai with credit-based pricing. For enterprises the risk profile depends heavily on deployment mode: self-hosting weights on private infrastructure keeps prompts and outputs in-tenant, while the hosted API sends prompts to Stability's servers. Stability AI publishes a privacy policy and Trust Center (trust.stability.ai), supports GDPR data subject requests, and retains data for up to one year per its policy; SOC 2 status for the hosted platform should be confirmed during procurement. The base training set has faced copyright scrutiny, so outputs carry higher IP risk than commercial-safe alternatives.

Risk factors

3
  • Open-weights model can be self-hosted, reducing data exposure
  • API usage may involve third-party data handling
  • Limited information on data retention policies

Recommendations

8
  • Prefer self-hosting weights on private infrastructure for sensitive prompts and brand assets
  • Confirm revenue threshold and obtain Enterprise License if ARR exceeds $1M
  • Review Stability AI Trust Center and request SOC 2 / pen-test reports before hosted API use
  • Apply corporate safety filters and prompt moderation on top of base models
  • Track which team uses Community vs Enterprise license to avoid compliance drift
  • Assess IP risk on outputs; avoid commercial use that relies on recognizable copyrighted styles
  • Block face generation of real individuals without documented consent
  • Monitor downstream forks and LoRAs loaded in self-hosted deployments for supply-chain risk

Data handling

Storage
Hosted API stores prompts, reference images, and outputs on Stability AI infrastructure; self-hosted deployments keep all data in customer environment.
Retention
Stability AI privacy policy caps retention at one year; after that data is deleted, anonymized, or securely isolated.
Training on inputs
Stability AI does not commit to training on user API inputs; base models were pre-trained on large-scale web datasets; self-hosted weights have no vendor data flow.