Models / NVIDIA/ Nemotron 3.5 Content Safety

Nemotron 3.5 Content Safety

NVIDIA · released May 22, 2026 · nvidia/Nemotron-3.5-Content-Safety

Input: text and images. Output: text.InputOutput
Type
Open weightsCustom licence
Params
4.3B
Context
131K

about 98K words of context · download allowed, licence restricts use

Our take

Written Sep 5, 2026

Nemotron 3.5 Content Safety is a vision-language classifier from NVIDIA that flags unsafe text and images. It handles up to 131,072 tokens in a single request and carries flat, predictable pricing across every host we list.

Who should pick it

Use this for content-moderation pipelines that need image-plus-text classification at flat-rate pricing, or for long-document safety screening where 131K tokens of context matters. Skip it if you need measured accuracy data, clear licence terms, or guaranteed throughput on every host.

The case for it

  • Flat pricing with no output premium on all three current offers.
  • 131,072-token request limit for extended documents or conversations.
  • One host discloses 135.5 tokens per second throughput.

The case against it

  • No benchmark scores or measured safety-accuracy data in our records.
  • Licence terms unverified despite downloadable weights — commercial use and redistribution rights are unclear.
  • Throughput undisclosed on two of three hosts.
00

How good is it?

We hold no score for this model.

So there is no figure here for everyday use, coding, agent work or writing. That is a gap in our data, not a low score.

Where these scores come from →

01

Can you run it yourself?

Comfortable fit

A card many people ownFits in memory

GeForce RTX 4090 · 24 GB

Weights at 2.7 / 24 GBest
Spare memory18.5 GB spare
Usable context131K of 131K
Decode speed309 tok/sest

Room to spare. 18.5 GB spare means a 10% error in the size would not change the answer.

One step upFits in memory

GeForce RTX 5090 · 32 GB

Weights at 2.7 / 32 GBest
Spare memory26.5 GB spare
Usable context131K of 131K
Decode speed550 tok/sest

Room to spare. 26.5 GB spare means a 10% error in the size would not change the answer.

On a MacFits in memory

Apple M2 (8-core GPU, 8GB unified) · 8 GB

Weights at 2.7 / 8 GBest
Spare memory1.7 GB spare
Usable context8K of 131K
Decode speed27 tok/sest

Room to spare. 1.7 GB spare means a 10% error in the size would not change the answer.

Your hardware
Checking your profile…

Memory use by level

Against a 24 GB card.

What is quantisation? →
recommended
2.7 GBest
Fits in memory
3.2 GBest
Fits in memory
4.8 GBest
Fits in memory
This model on every device we track71 devicesThe Q4 build most people download, on each device: what the weights come to, how much context the memory leaves, and whether it runs. Smallest device that runs it first.
iPhone 15 Pro4.4 GB2.7 GBest2KFits in memoryest
iPhone 164.4 GB2.7 GBest2KFits in memoryest
iPhone 16 Pro4.4 GB2.7 GBest2KFits in memoryest
iPhone 174.4 GB2.7 GBest2KFits in memoryest
GeForce GTX 1660 SUPER6 GB2.7 GBest8KFits in memory
Android phone · 12 GB · 2023 or newer6 GB2.7 GBest8KFits in memory
iPhone 17 Pro6.6 GB2.7 GBest16KFits in memory
GeForce RTX 3060 8GB8 GB2.7 GBest16KFits in memory
GeForce RTX 4060 8GB8 GB2.7 GBest16KFits in memory
Radeon RX 66008 GB2.7 GBest16KFits in memory
Apple M2 (8-core GPU, 8GB unified)8 GB2.7 GBest8KFits in memory
Android phone · 16 GB · 2024 or newer8 GB2.7 GBest16KFits in memory
Apple M1 (8-core GPU, 8GB unified)8 GB2.7 GBest8KFits in memory
GeForce RTX 3080 10GB10 GB2.7 GBest33KFits in memory
Arc B57010 GB2.7 GBest33KFits in memory
Arc B58012 GB2.7 GBest33KFits in memory
GeForce RTX 4070 SUPER12 GB2.7 GBest33KFits in memory
GeForce RTX 507012 GB2.7 GBest33KFits in memory
GeForce RTX 3060 12GB12 GB2.7 GBest33KFits in memory
GeForce RTX 4070 Ti SUPER16 GB2.7 GBest66KFits in memory
GeForce RTX 4080 SUPER16 GB2.7 GBest66KFits in memory
GeForce RTX 5060 Ti 16GB16 GB2.7 GBest66KFits in memory
GeForce RTX 5070 Ti16 GB2.7 GBest66KFits in memory
GeForce RTX 508016 GB2.7 GBest66KFits in memory
Radeon RX 907016 GB2.7 GBest66KFits in memory
Radeon RX 9070 XT16 GB2.7 GBest66KFits in memory
GeForce RTX 4060 Ti 16GB16 GB2.7 GBest66KFits in memory
Apple M1 (8-core GPU)16 GB2.7 GBest33KFits in memory
Radeon RX 7900 XT20 GB2.7 GBest66KFits in memory
GeForce RTX 309024 GB2.7 GBest131KFits in memory
GeForce RTX 3090 Ti24 GB2.7 GBest131KFits in memory
GeForce RTX 409024 GB2.7 GBest131KFits in memory
Radeon RX 7900 XTX24 GB2.7 GBest131KFits in memory
Apple M2 (10-core GPU)24 GB2.7 GBest66KFits in memory
Apple M3 (10-core GPU)24 GB2.7 GBest66KFits in memory
GeForce RTX 509032 GB2.7 GBest131KFits in memory
Apple M1 Pro (16-core GPU)32 GB2.7 GBest131KFits in memory
Apple M2 Pro (19-core GPU)32 GB2.7 GBest131KFits in memory
Apple M5 (10-core GPU)32 GB2.7 GBest131KFits in memory
Apple M4 (10-core GPU)32 GB2.7 GBest131KFits in memory
Apple M3 Pro (18-core GPU)36 GB2.7 GBest131KFits in memory
L40S48 GB2.7 GBest131KFits in memory
RTX 6000 Ada48 GB2.7 GBest131KFits in memory
Apple M5 Max (32-core GPU)64 GB2.7 GBest131KFits in memory
Apple M4 Max (32-core GPU)64 GB2.7 GBest131KFits in memory
Apple M1 Max (32-core GPU)64 GB2.7 GBest131KFits in memory
Apple M5 Pro (20-core GPU)64 GB2.7 GBest131KFits in memory
Apple M4 Pro (20-core GPU)64 GB2.7 GBest131KFits in memory
A100 80GB SXM80 GB2.7 GBest131KFits in memory
H100 80GB SXM80 GB2.7 GBest131KFits in memory
RTX PRO 6000 Blackwell96 GB2.7 GBest131KFits in memory
Apple M2 Max (38-core GPU)96 GB2.7 GBest131KFits in memory
Apple M1 Ultra (64-core GPU)128 GB2.7 GBest131KFits in memory
Apple M4 Max (40-core GPU)128 GB2.7 GBest131KFits in memory
Apple M5 Max (40-core GPU)128 GB2.7 GBest131KFits in memory
Apple M3 Max (40-core GPU)128 GB2.7 GBest131KFits in memory
NVIDIA DGX Spark (GB10)128 GB2.7 GBest131KFits in memory
Ryzen AI Max+ 395 (Radeon 8060S)128 GB2.7 GBest131KFits in memory
H200 141GB SXM141 GB2.7 GBest131KFits in memory
Apple M2 Ultra (76-core GPU)192 GB2.7 GBest131KFits in memory
B200 (SXM 192GB)192 GB2.7 GBest131KFits in memory
Instinct MI300X192 GB2.7 GBest131KFits in memory
Apple M3 Ultra (80-core GPU)512 GB2.7 GBest131KFits in memory
Android phone · 8 GB · 2020–20224 GB2.7 GBestnot calculatedToo largeest
Android phone · 8 GB · 2023 or newer4 GB2.7 GBestnot calculatedToo largeest
iPhone 143.3 GB2.7 GBestnot calculatedToo large
iPhone 153.3 GB2.7 GBestnot calculatedToo large
Android phone · 6 GB3 GB2.7 GBestnot calculatedToo large
iPhone 132.2 GB2.7 GBestnot calculatedToo large
iPhone SE (3rd gen)2.2 GB2.7 GBestnot calculatedToo large
Android phone · 4 GB2 GB2.7 GBestnot calculatedToo large

Check against your own machine → · Where to rent it hosted →

02

Or rent it from someone else

Prices checked 2 hours ago — each listing carries its own date.

Cheapest published offer

Cheapest of 2 live listings.

per 1M tokens
$0.20 in / $0.20 out
Context served
131K
Throughput
Not measured
Current provider offers with price, context and prompt-privacy answers
ProviderIn / out per 1M tokensContextThroughputTrains on promptsLogs promptsZero retention
OpenRouterOpenRouter's own listing$0.20 / $0.20checked 2 hours ago131Knot measuredUnknownUnknownUnknown
DeepInfrabf16Direct and through OpenRouter$0.20 / $0.20checked 2 hours ago131K118K max reply through OpenRouter46 tok/sthrough OpenRouterDirectUnknownThrough OpenRouterNoDirectUnknownThrough OpenRouterNoDirectUnknownThrough OpenRouterConfirmed

Across the 2 listings we hold: 1 says it does not train on prompts (only through OpenRouter), 0 say they do and 1 does not say. 1 appears in the zero-retention registry we check (only through OpenRouter); the rest are unknown to us.

What each host's API supports

From the parameter list each endpoint publishes. Streaming is omitted: nothing we hold reports it, for any model.

API features per host
ProviderTool callingJSON outputStrict schema
OpenRouterOpenRouter's own listing✗✗✗
DeepInfrabf16Direct and through OpenRouter✗✗✗

Tool calling: 0 of 2 listings say yes, 2 say no. JSON output: 0 of 2 listings say yes, 2 say no. Strict schema: 0 of 2 listings say yes, 2 say no.

03

When we formed this view

Recent changes

Sep 4, 2026ListedListed on LLMap
What movedfirst indexed by our pipeline
May 22, 2026AnnouncedNemotron 3.5 Content Safety announced by NVIDIA

Each date is the day we first saw the change, or the day the maker announced it.

What we do not know about this model yet

  • We hold no measured file for it, so all 3 sizes on this page are calculated from the parameter count.
  • No independent board has scored it, so we hold no quality figures at all.
  • Nothing we hold says whether an endpoint streams, so we do not show it either way.
  • 1 of 2 listings does not say whether it trains on prompts, and 1 answers only through OpenRouter, not for its own listing.
  • We hold no cached-input rate for any of its listings.
  • We hold no batch or off-peak rate for any of its listings.
  • We hold a decode speed for it, but no prompt-processing (prefill) figure, so how long the input side of a job takes is unknown to us.
04

Licence and identifiers

What the licence allowsCustom licence, what it allows commercially, and the identifiers you need to pull this model — its Hugging Face repo, our slug and a machine-readable card.

Licence

Custom licence

Open, with restrictionsCustom licence — review the terms

This model ships custom license terms that don't map to a known template. We haven't parsed them, so commercial use, redistribution and derivatives are unverified — review the original terms before shipping.

Identifiers

Architecture
Dense
Takes in, gives back
Text and images in, text out
Catalogue slug
nvidia-nemotron-3-5-content-safety

Machine-readable model card (omc.json) →

Something wrong on this page? Tell us