Nemotron 3.5 Content Safety
NVIDIA · released May 22, 2026 · nvidia/Nemotron-3.5-Content-Safety
- Type
- Open weightsCustom licence
- Params
- 4.3B
- Context
- 131K
about 98K words of context · download allowed, licence restricts use
Our take
Written Sep 5, 2026Nemotron 3.5 Content Safety is a vision-language classifier from NVIDIA that flags unsafe text and images. It handles up to 131,072 tokens in a single request and carries flat, predictable pricing across every host we list.
Use this for content-moderation pipelines that need image-plus-text classification at flat-rate pricing, or for long-document safety screening where 131K tokens of context matters. Skip it if you need measured accuracy data, clear licence terms, or guaranteed throughput on every host.
The case for it
- Flat pricing with no output premium on all three current offers.
- 131,072-token request limit for extended documents or conversations.
- One host discloses 135.5 tokens per second throughput.
The case against it
- No benchmark scores or measured safety-accuracy data in our records.
- Licence terms unverified despite downloadable weights — commercial use and redistribution rights are unclear.
- Throughput undisclosed on two of three hosts.
How good is it?
We hold no score for this model.
So there is no figure here for everyday use, coding, agent work or writing. That is a gap in our data, not a low score.
Can you run it yourself?
Comfortable fit
GeForce RTX 4090 · 24 GB
Room to spare. 18.5 GB spare means a 10% error in the size would not change the answer.
GeForce RTX 5090 · 32 GB
Room to spare. 26.5 GB spare means a 10% error in the size would not change the answer.
Apple M2 (8-core GPU, 8GB unified) · 8 GB
Room to spare. 1.7 GB spare means a 10% error in the size would not change the answer.
Memory use by level
Against a 24 GB card.
What is quantisation? →This model on every device we track71 devicesThe Q4 build most people download, on each device: what the weights come to, how much context the memory leaves, and whether it runs. Smallest device that runs it first.
Check against your own machine → · Where to rent it hosted →
Or rent it from someone else
Prices checked 2 hours ago — each listing carries its own date.
- per 1M tokens
- $0.20 in / $0.20 out
- Context served
- 131K
- Throughput
- Not measured
| Provider | In / out per 1M tokens | Context | Throughput | Trains on prompts | Logs prompts | Zero retention |
|---|---|---|---|---|---|---|
| OpenRouterOpenRouter's own listing | $0.20 / $0.20checked 2 hours ago | 131K | not measured | Unknown | Unknown | Unknown |
| DeepInfrabf16Direct and through OpenRouter | $0.20 / $0.20checked 2 hours ago | 131K118K max reply through OpenRouter | 46 tok/sthrough OpenRouter | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterConfirmed |
Across the 2 listings we hold: 1 says it does not train on prompts (only through OpenRouter), 0 say they do and 1 does not say. 1 appears in the zero-retention registry we check (only through OpenRouter); the rest are unknown to us.
What each host's API supports
From the parameter list each endpoint publishes. Streaming is omitted: nothing we hold reports it, for any model.
| Provider | Tool calling | JSON output | Strict schema |
|---|---|---|---|
| OpenRouterOpenRouter's own listing | ✗ | ✗ | ✗ |
| DeepInfrabf16Direct and through OpenRouter | ✗ | ✗ | ✗ |
Tool calling: 0 of 2 listings say yes, 2 say no. JSON output: 0 of 2 listings say yes, 2 say no. Strict schema: 0 of 2 listings say yes, 2 say no.
When we formed this view
Recent changes
What moved
first indexed by our pipelineEach date is the day we first saw the change, or the day the maker announced it.
What we do not know about this model yet
- We hold no measured file for it, so all 3 sizes on this page are calculated from the parameter count.
- No independent board has scored it, so we hold no quality figures at all.
- Nothing we hold says whether an endpoint streams, so we do not show it either way.
- 1 of 2 listings does not say whether it trains on prompts, and 1 answers only through OpenRouter, not for its own listing.
- We hold no cached-input rate for any of its listings.
- We hold no batch or off-peak rate for any of its listings.
- We hold a decode speed for it, but no prompt-processing (prefill) figure, so how long the input side of a job takes is unknown to us.
Licence and identifiers
What the licence allowsCustom licence, what it allows commercially, and the identifiers you need to pull this model — its Hugging Face repo, our slug and a machine-readable card.
Licence
Custom licence
This model ships custom license terms that don't map to a known template. We haven't parsed them, so commercial use, redistribution and derivatives are unverified — review the original terms before shipping.
Identifiers
- Hugging Face
- nvidia/Nemotron-3.5-Content-Safety
- Architecture
- Dense
- Takes in, gives back
- Text and images in, text out
- Catalogue slug
- nvidia-nemotron-3-5-content-safety