Together AI
United States · www.together.ai · 50 vendors
Together Computer, Inc., operating as Together AI, is a research-driven AI company that provides a full-stack AI platform, known as the AI Native Cloud. It enables developers and researchers to train, fine-tune, and deploy generative AI models. The company offers high-performance infrastructure, optimized software, and developer tools, with a strong focus on open-source AI.
Resilience scores
- Digital Sovereignty: 82
- Digital Resilience: 7
- Financial Resilience: 7
Disruption prediction
Together AI has a 76% probability of disruption in the next 6 months.
All systems operational (last checked 2026-09-18 14:55 UTC)
26 of Together AI's 50 vendors monitored for disruptions.
Technology vendors
- Dealfront — Technology — Germany
- Demandware — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 52 more
Services catalogue
2 services in catalogue across 2 categories; runs on 50 sub-vendors.
- AI Platform
- LLM Model Finetuning
Insights
Last updated 2026-08-16 · revision 8
50 direct vendors, 383 subvendors
Direct vendors by controlling owner country (sample)
- Canada: 1
- United States: 41
- Slovenia: 1
Subvendors by controlling owner country (sample)
- Germany: 11
- France: 13
- Norway: 7
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Together AI exhibits high migration readiness, primarily driven by its modern, cloud-native, and highly flexible technology stack. The platform extensively utilizes containerization (Docker) and orchestration (Kubernetes), enabling modular and portable deployments. Its core offerings are built around open-source AI models and an OpenAI-compatible REST API, which significantly reduces vendor lock-in for customers and simplifies migration pathways to or from other OpenAI-compatible services. The availability of various inference options (Serverless, Batch, Provisioned, Dedicated) and GPU clusters, along with managed fine-tuning and custom training services, provides customers with a wide array of flexible deployment and operational models. The main challenges for migration readiness stem from regulatory and data residency complexities. The lack of public certifications for key compliance standards like SOC2 and ISO 27001, and unconfirmed GDPR audit evidence, could pose hurdles for enterprise customers with stringent regulatory requirements when migrating to or from Together AI. While Together AI offers Zero Data Retention, the general policy of international data transfers and the need for specific arrangements for data localization in certain jurisdictions (e.g., EU, China, Russia) could complicate migrations for customers with strict data residency mandates. The unknown financial growth history also makes it difficult to assess Together AI's long-term capacity to invest in and support complex migration scenarios. The ambiguity of 'Total Vendors: 0' and 'Vendor Lock-in Risk: Unknown' for Together AI's own dependencies means we cannot fully assess how their internal vendor relationships might impact their flexibility in supporting customer migrations.
Compliance
6 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
Together AI is a cloud services provider offering AI inference APIs, GPU clusters, fine-tuning, and managed storage — all service categories for which SOC 2 Type II is considered a baseline enterprise expectation. The company's Terms of Service (Section 1.3) state it 'will maintain a security program in accordance with industry standards,' which is consistent with SOC 2 preparation but does not confirm certification. No SOC 2 report is publicly available on the website. Risk is Medium because: (1) enterprise and regulated-industry customers (finance, healthcare-adjacent, government) increasingly require SOC 2 Type II as a vendor prerequisite; (2) absence of a public SOC 2 report may limit Together AI's ability to serve compliance-sensitive enterprise segments; (3) the company has raised $800M Series C and is scaling rapidly, increasing the urgency and expectation for formal third-party attestation. The risk is not High because the company is US-based and SOC 2 is voluntary, but commercial pressure from enterprise customers makes this a significant gap.
Evidence: https://www.together.ai/terms-of-service, https://www.together.ai
ISO 27001 (source) — Assessment Required
ISO 27001 is an internationally recognized information security management standard increasingly required by enterprise and government customers globally. Together AI operates a large-scale cloud AI platform processing customer data, model weights, and API traffic. No ISO 27001 certification is publicly disclosed. Risk is Medium because: (1) the company serves global enterprise customers who may contractually require ISO 27001; (2) EU customers subject to GDPR and NIS2 often require ISO 27001 as a supply chain security control; (3) the company's rapid growth ($800M Series C) and expanding enterprise customer base increase the commercial and reputational risk of lacking this certification; (4) ISO 27001 is voluntary but its absence may be a competitive disadvantage in regulated industries. Risk is not High because the company is US-based and ISO 27001 is not legally mandated in the US.
Evidence: https://www.together.ai/terms-of-service, https://www.together.ai/privacy
CCPA — Partially Compliant
Together AI is incorporated in Delaware and headquartered in San Francisco, California, making CCPA directly applicable. The company's Privacy Policy (Section 6, 'California') includes a dedicated CCPA compliance section. Positive signals: explicit statement that the company does not sell personal data; enumeration of California consumer rights (access, deletion, data portability, do-not-sell opt-out); response timeline commitment (45 days, extendable to 90); contact mechanism (privacy@together.ai). Risk is Medium because: (1) CPRA (California Privacy Rights Act, effective 2023) expanded CCPA obligations including sensitive personal information categories, opt-out of sharing for cross-context behavioral advertising, and data minimization — these are not explicitly addressed in the current policy; (2) no mention of a Privacy Notice at Collection as required by CPRA; (3) no explicit reference to contractor/employee CCPA rights; (4) enforcement by the California Privacy Protection Agency (CPPA) is active and increasing.
Evidence: https://www.together.ai/privacy
Financials
Three-year financials
- 2025:
- 2024: revenue $100M
- 2023: revenue $12M
Financial Resilience Score: 7/10
Together AI demonstrates strong short- to medium-term financial resilience thanks to a very large recent capital base. The company has raised over US$1.3bn in disclosed equity funding, culminating in an US$800m Series C in July 2026, supplemented by separately capitalized commitments for more than 500 MW of compute capacity. This provides multi-year runway even under heavy GPU-driven cash burn, and the strategic investor base — including NVIDIA, Aramco/Prosperity7, Salesforce Ventures, General Catalyst, Vista Equity, Pegatron and SE Ventures — secures preferential access to GPUs, energy, and data-center partnerships, which are the key bottlenecks in AI infrastructure. Operationally, the company benefits from a strong research moat (FlashAttention, ThunderKittens, Mamba, Hyena, RedPajama, ATLAS) that translates into cost and latency advantages versus commodity GPU renters, and a blue-chip AI-native customer base (Cursor, Cognition, ElevenLabs, Salesforce, Zoom, Zoho, SK Telecom, LG AI Research, Mozilla). Press-reported ARR reportedly scaled from ~US$10–15m in late 2023 to ~US$100m during 2024, implying very rapid growth. However, resilience is constrained by extreme capital intensity, likely significant ongoing operating losses (undisclosed), and aggressive price competition from hyperscalers (AWS, Azure, GCP) and specialized peers (CoreWeave, Fireworks, Groq, Anyscale, Lambda, Baseten, Modal). Customer concentration among early-stage AI-native firms adds cyclical risk, and the absence of any audited financial disclosure (no revenue, EBIT, equity, cash burn, or debt data) means the resilience assessment carries meaningful uncertainty.
Key strengths: US$800m Series C raised in July 2026 plus >500 MW of separately committed compute capacity, Cumulative disclosed equity funding exceeding US$1.3bn since 2022, Strategic investor base including NVIDIA, Aramco, Salesforce, General Catalyst securing GPU and data-center access, Research moat via FlashAttention, ThunderKittens, Mamba, RedPajama giving cost/latency advantage, Blue-chip AI-native customer roster (Cursor, Cognition, ElevenLabs, Salesforce, Zoom, SK Telecom), Diversified revenue mix across serverless inference, dedicated inference, GPU clusters, and fine-tuning, Rapid ARR growth from ~US$10–15m (2023) to ~US$100m (2024) per press reports
Risk factors: Extreme capital intensity requiring continuous multi-hundred-million-dollar GPU investment, Likely significant ongoing operating cash losses (undisclosed), Customer concentration among early-stage AI-native companies vulnerable to AI spending slowdown, Intense competition from hyperscalers (AWS Bedrock, Azure AI, Google Vertex) and specialized inference players (CoreWeave, Fireworks, Groq, Anyscale, Lambda, Baseten, Modal), Commoditization and aggressive price cuts pressuring inference unit economics, Dependence on NVIDIA GPU supply (partially mitigated by NVIDIA as investor), No public financial transparency — margins, burn rate, debt, deferred revenue all undisclosed
Revenue by geography
- North America: 75%
- EMEA: 15%
- APAC: 10%
Revenue by product/service
- GPU Clusters / Dedicated & Provisioned Inference: 65%
- Serverless / API Inference: 25%
- Fine-tuning, Custom Training, Sandbox, Managed Storage: 10%
Workforce by country
- United States: 250
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.