Nemotron 3.5 Content Safety

NVIDIA Nemotron 3.5 Content Safety is a compact 4B-parameter multimodal guardrail model from NVIDIA, fine-tuned from Google Gemma-3-4B. It moderates both inputs to and responses from LLMs and VLMs, accepting text and image input and returning text output: a safe/unsafe classification for the user prompt and the response, safety category labels, and an optional reasoning trace. It covers 12 languages with a context window of up to 128K tokens.

It is suited for prompt and response moderation, content classification, safety pipelines, and enterprise AI guardrails with policy enforcement, and includes a togglable reasoning mode. It is part of the NVIDIA Nemotron family of open models for agentic AI.

nvidia/nemotron-3.5-content-safety
Organization
Nvidia
Family
nemotron
Providers
6
Context
128,000
Output limit
8,192
Knowledge
—
Release
2026-06-04
Updated
2026-06-04
Weights
Open
Input
text, image
Output
text
Capabilities
Reasoning, Temperature

Providers

Compare every cataloged offer for this model, including its provider, route, token limits, price, and capabilities.

8 offers · USD per million tokens
ProviderModel IDContextOutputInput / output · 1MReasoningToolsStructuredDetails
Kilo Gateway
nvidia/nemotron-3.5-content-safety
131,072117,964$0.20 / $0.20YesNoNo
View
Kilo Gateway
nvidia/nemotron-3.5-content-safety:free
128,0008,192$0.00 / $0.00YesNoNo
View
NanoGPT
nvidia/nemotron-3.5-content-safety
131,07232,768$0.05 / $0.15YesNoNo
View
Nvidia
nvidia/nemotron-3.5-content-safety
128,0008,192$0.00 / $0.00YesNo—
View
DeepInfravia OpenRouter
nvidia/nemotron-3.5-content-safety
bf16
131,072117,964$0.20 / $0.20YesNoNo
View
Nvidiavia OpenRouter
nvidia/nemotron-3.5-content-safety:free
unknown
128,0008,192$0.00 / $0.00YesNoNo
View
Requesty
nemotron-3.5-content-safety
131,0728,192$0.00 / $0.00YesNoNo
View
Vultr
nemotron-3.5-content-safety
131,0728,192$0.05 / $0.15YesNo—
View

Prices and limits apply to each offer. A dash means the value is not provided. OpenRouter offers show the hosting provider and routing channel separately.

Pricing

Compare token rates and cache charges across available routes and hosting configurations.

USD per million tokens
Input from$0.00Per 1M input tokens
Output from$0.00Per 1M output tokens
Available offers8Across 6 providers

Lowest listed input and output prices across the offers above; they may belong to different providers. These are base rates, before conditional pricing, discounts or additional fees.

Endpoint price comparisonLatest observed snapshot · 2 lowest-priced configurations
InputOutput
Nvidianvidia
$0.00$0.00
DeepInfradeepinfra/bf16
$0.20$0.20
nvidia/nemotron-3.5-content-safetyObserved
Input
$0.20
Output
$0.20
nvidia/nemotron-3.5-content-safety:freeObserved
Input
$0.00
Output
$0.00
Hosting prices through OpenRouter All endpoints and cache rates
EndpointInput / 1MOutput / 1MCache read / 1MCache write / 1M
DeepInfradeepinfra/bf16$0.20$0.20——
Nvidianvidia$0.00$0.00——

Each row is a hosting configuration. Open an offer in Providers for its full pricing conditions and additional fees. Endpoint observations may differ from the routing catalog's base price.

Performance

Review reported latency and output-throughput percentiles from the latest observed rolling window.

Latest 30-minute observation

Time to first token · milliseconds

Latency distributionRolling 30-minute snapshot · 1 endpoint
P50P75P90P99
Nvidianvidia
410–7,050.27 ms
All latency percentiles 1 endpoints
EndpointP50P75P90P99
Nvidianvidia410 ms875.75 ms1,568.8 ms7,050.27 ms

Output throughput · tokens per second

Throughput distributionRolling 30-minute snapshot · 1 endpoint
P50P75P90P99
Nvidianvidia
65–91 t/s
All throughput percentiles 1 endpoints
EndpointP50P75P90P99
Nvidianvidia65 t/s73 t/s81 t/s91 t/s

Percentiles describe the observed request distribution. These are snapshots of a rolling window, not a historical time series.

Uptime

Compare successful request rates across the latest 5-minute, 30-minute, and 24-hour observations.

Successful requests by window
Availability by endpointCurrent overlapping windows · 2 endpoints
Endpoint5 minutes30 minutes24 hours
DeepInfradeepinfra/bf16
Nvidianvidia

Reported by OpenRouter at the time of collection; rate-limited requests are excluded. A dash means no measurement was reported. This is not a live availability check.

Technical details & API

Explore specifications, supported parameters, reasoning controls, and API identifiers for each OpenRouter route.

Current route specifications
nvidia/nemotron-3.5-content-safetyObserved
Context
131,072
Maximum output
117,964
Tokenizer
Other
Input
text, image
Output
text
Moderation
No
Added to OpenRouter
2026-06-04
Base URLhttps://openrouter.ai/api/v1
Model IDnvidia/nemotron-3.5-content-safety
Version IDnvidia/nemotron-3.5-content-safety-20260604
Weights IDnvidia/Nemotron-3.5-Content-Safety

Reasoning

Required
No
Enabled by default
Yes
Default effort
—
Supported efforts
—

Supported parameters

  • frequency_penalty
  • include_reasoning
  • logit_bias
  • max_tokens
  • min_p
  • presence_penalty
  • reasoning
  • repetition_penalty
  • seed
  • stop
  • temperature
  • top_k
  • top_p
nvidia/nemotron-3.5-content-safety:freeObserved
Context
128,000
Maximum output
8,192
Tokenizer
Other
Input
text, image
Output
text
Moderation
No
Added to OpenRouter
2026-06-04
Base URLhttps://openrouter.ai/api/v1
Model IDnvidia/nemotron-3.5-content-safety:free
Version IDnvidia/nemotron-3.5-content-safety-20260604
Weights IDnvidia/Nemotron-3.5-Content-Safety

Reasoning

Required
No
Enabled by default
Yes
Default effort
—
Supported efforts
—

Supported parameters

  • include_reasoning
  • max_tokens
  • reasoning
  • seed
  • temperature
  • top_p

Frequently asked questions

Answers based on the model metadata and serving offers currently in the catalog.

How much does Nemotron 3.5 Content Safety cost?

Listed rates start at $0.00 per million input tokens and $0.00 per million output tokens. Prices vary by provider and configuration; see Pricing for details.

Which providers offer Nemotron 3.5 Content Safety?

There are 8 cataloged offers across 6 providers. Compare model IDs, prices and limits in Providers.

What is the context window?

The cataloged model context is 128,000 tokens. Each serving endpoint may apply a different limit.

Does it support tools and structured output?

Tool calling: No. Structured output: Not reported. Support can vary by endpoint.

Catalog history · 2 recorded revisions

Metadata observations since this model was first cataloged. These are not model release versions.

  • · 3aaefb85c6dc
  • · 8d8822b5875b