Assess · Baseten
Can you own it?
Ownership levelSubstantialnone·limited·partial·substantial·fullAnalytical input B ยท 73.6/100
This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
Which domain expands which factor
- AssessUse & modify + Transparency
- ImplementData control + Reliability
- UseReliability
- SupportTransparency
Data governance - retention, ZDR & training
Baseten's security-practices page (independently browser-confirmed, verbatim) states: "ZDR
is the default configuration for the customer's use of the inference products" for Model APIs
and Dedicated Inference - Zero Data Retention is the default, not an opt-in or
enterprise-gated feature. Correction: this default lives on the Security Practices page, not
the Terms directly - Terms Sec 2.5 merely honours whatever posture Security Practices designates.
The one exception is Async Inference, which queues inputs for up to 72 hours before
deletion (outputs are never stored on that path either). Terms & Conditions Sec 6.3 bars Baseten
from using Customer Content - including deployed model weights and outputs - to train,
fine-tune, or otherwise develop its own models.
Data & IP ownership
Terms & Conditions Sec 6.1 (independently browser-confirmed): "Customer reserves all rights,
title, and interest in and to Customer Content," a definition that includes deployed Customer
Models and Model Outputs. A MUTUAL confidentiality clause (Sec 11.1-11.2) - confirmed
on two separate live fetches - requires both parties to protect confidential information
"with the same degree of care it uses for its own (but no less than reasonable care),"
surviving three years after termination (trade secrets indefinitely, Sec 11.4) - a genuine,
independently-verified positive, stronger than several peers' one-directional or disclaimed
clauses. The sub-processor list (trust.baseten.co) exists with a 15-day pre-notification
commitment (DPA Sec 7.1), though its actual named contents remain unread - the portal is a
JS-gated Vanta page that returns only a meta description on every path tried.
Residency & sovereignty
No published, named EU region exists for the managed service. A "regional environments"
feature can route a deployment to a designated region, but the docs direct customers to contact
support to confirm availability - there is no self-serve, published region list. The practical
EU-residency path is Baseten Self-Hosted, which runs the entire workload plane inside the
customer's own VPC/cloud in any region, including the EU.
CLOUD Act disclosure: Baseten is US-headquartered (San Francisco); standard US jurisdiction
applies to the managed service.
Compliance & attestations
SOC 2 Type II is confirmed, with a named audit firm (Sensiba San Filippo LLP) and a clean
opinion across Security/Availability/Processing Integrity/Confidentiality/Privacy criteria.
HIPAA and a GDPR DPA are both confirmed directly. Correction: a prior claim of ISO
27001 certification is retracted - an independent browser pass found no trace of it anywhere,
not even self-attested; ISO 27701, PCI DSS, FedRAMP, and CSA STAR remain
unconfirmed - the Vanta Trust Center that would carry such certificates is fully JS-gated.
Security controls
Correction (description, not substance): independently browser-confirmed isolation is
logical namespace separation for shared use (access controls, unique customer identifiers) plus
Dedicated single-tenant Kubernetes namespaces with Calico/Cilium network policies ("Baseten
never shares GPUs across users") and Self-Hosted deployment inside the customer's own VPC -
not an explicit "three-tier" model as previously described, though the practical effect is
similar. Encryption is TLS 1.2+ in transit and AES-256 at rest; access is
least-privilege with enforced MFA for all personnel. Baseten states it engages qualified
third-party firms for periodic penetration testing (confirmed verbatim); no public
bug-bounty programme was found.
Pricing & cost model
Per-token pricing for hosted Model APIs and per-GPU-minute pricing for dedicated deployments are
both published directly on Baseten's pricing page, across Basic/Pro/Enterprise tiers. Example
rates: GLM-5.3 $1.40/$0.14-cached/$4.40 per 1M tokens; DeepSeek V4.1 Flash
$0.30/$0.03-cached/$1.20; dedicated GPU-minute rates from T4 $0.01052 up to H100 80GB $0.10833
(~$6.50/hr).
Reliability posture
Correction: a real, committed SLA exists and was independently browser-read at
baseten.co/service-level-agreement - "ninety-nine point nine percent (99.9%)" committed
uptime for both Dedicated Inference and Model APIs, service credits capped at 40% of monthly
fees, and a 24-hour claim window. The public status page (status.baseten.co,
independently confirmed) shows all systems operational, with three brief incidents in the current
90-day window (Sep 9, 14, 20 2026), all resolved same-day or next-day.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
1
Use and modify freelyCan you use it freely and leave without lock-in?
StrongOpenAI/Anthropic-compatible APIs over a predominantly open-weight Model Library keep workloads portable, and the Terms & Conditions confirm the customer retains all IP in Customer Content including deployed model weights and outputs - the three-tier deployment ladder (shared/dedicated/self-hosted) gives real control over where and how the workload runs.
How this scores (AOI sub-dimensions)
Transparency & lock-in4/5how portable it is and how easily you can leaveAn OpenAI-compatible API (plus a beta Anthropic-compatible API) over a predominantly open-weight catalogue keeps workloads portable, and the Terms & Conditions give a documented 30-day post-termination export window plus an on-request deletion right.
Cost4/5how the pricing model compares and how predictable it isDetailed, public per-token rates for Model APIs and per-GPU-minute rates across a wide range of GPU classes (T4 through B200) are both published directly on Baseten's pricing page, with clear tier definitions (Basic/Pro/Enterprise).
2
TransparencyAre the binding terms published, legible and independently checkable?
ModerateThe Terms & Conditions and DPA are legible and were independently browser-read (Sec 11 mutual confidentiality confirmed on two separate fetches) - but a prior ISO 27001 claim was RETRACTED (not found anywhere, not even as a self-attestation) and the Vanta Trust Center that would carry PCI/FedRAMP/CSA STAR status is fully JS-gated and unreadable, so the sub-processor list's actual named contents also remain unverified.
How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou substantially own inference here: an independent Cowork browser session confirmed, on two separate fetches, that Baseten's Terms & Conditions state Zero Data Retention by default, a contractual bar on using your content (including deployed model weights) to train its models, and a genuinely mutual confidentiality duty - a stronger standard-terms posture than most peers, and now independently verified rather than resting on a single automated read. A real, committed 99.9% SLA with service credits was also confirmed. It falls short of full ownership because a prior ISO 27001 claim was retracted (not found anywhere on independent verification), the Vanta Trust Center is fully JS-gated so PCI/FedRAMP/CSA STAR status and the named sub-processor list remain unverified, no published EU region exists for the managed service (EU residency means the enterprise Self-Hosted tier), and Async Inference has a 72-hour retention exception. If you need EU data residency or want certifications independently confirmed, use the Self-Hosted tier or ask for the underlying reports directly.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Terms of serviceread2026-09-20
Baseten Terms & Conditions (read directly): Sec on Customer Content ownership - 'Customer reserves all rights, title, and interest in and to Customer Content,' where Customer Content includes Customer Models (deployed weights) and Model Outputs; a training-prohibition clause bars Baseten from using Customer Content to train, fine-tune, or otherwise develop ML/AI models, limiting its license to providing/maintaining the Services and preventing/addressing technical problems, plus anonymized/de-identified telemetry; mutual confidentiality clause requiring 'the same degree of care it uses for its own (but no less than reasonable care),' surviving three years post-termination, with prior-notice compelled disclosure; a documented exit right - Customer Content exportable for 30 days after Term end, deletable on written request.
Securityread2026-09-20
Baseten security-practices page (read directly): Zero Data Retention for Model APIs and Dedicated Inference ('will not store, retain, or otherwise make a persistent copy of model inputs or outputs'); Async Inference queues inputs up to 72 hours before deletion, outputs never stored; three-tier tenant isolation (shared logical separation; dedicated single-tenant Kubernetes namespaces with Calico/Cilium network policies, 'never shares GPUs across users'; self-hosted in customer VPC); TLS 1.2+ in transit, AES-256 at rest with periodic key rotation; least-privilege access, enforced MFA, quarterly access reviews; periodic third-party penetration testing; KV cache never persisted to disk.
Data Processing Addendumread2026-09-20
Baseten DPA (read directly): 'Baseten shall not log, record, or save Customer Personal Data contained in model inputs or outputs to persistent storage after real-time processing'; Baseten as Processor, Customer as Controller; SCCs incorporated, governing law/jurisdiction Ireland (Clause 17/18); UK Addendum (ICO template B.1.0) for UK transfers; a sub-processor list is maintained with at least fifteen (15) days' prior notice before engaging a new sub-processor.
Vendor announcementread2026-09-20
Baseten blog post confirming SOC 2 Type II certification, audited by Sensiba San Filippo LLP, covering Security/Availability/Processing Integrity/Confidentiality/Privacy criteria with a clean opinion across 70+ sub-criteria; the report itself is gated under NDA.
Documentationread2026-09-20
Baseten regional-environments docs (read directly): routes inference traffic for a deployment 'exclusively to workload planes within a designated geographic region'; requires initial configuration by Baseten - 'Contact support to confirm availability for the region you need.' No published list of specific region names was found.
Documentationread2026-09-20
Baseten Self-Hosted product page (read directly): the full workload plane runs inside the customer's own VPC/cloud, with inference input/output 'never touching Baseten's premises'; marketed toward the Enterprise pricing tier.
Slaread2026-09-20
UPGRADED 2026-09-21: Baseten's public status page (status.baseten.co), independently browser-read: 'All Systems Operational' across 6 components (Dedicated Inference, Model APIs, Training, Model Management API, Web Application, Homepage and Docs); 90-day history, no numeric % shown on the face.
Slaread2026-09-21
Baseten Service Level Agreement (independently browser-read 2026-09-21, verbatim): Sec 2.0 - 'ninety-nine point nine percent (99.9%)' committed uptime, applying to both Dedicated Inference and Model APIs on Baseten-managed infrastructure.
Vendor announcementread2026-09-20
Baseten pricing page (read directly): per-token Model API rates (e.g.
Documentationread2026-09-20
Baseten Model Library page (read directly): current curated catalogue includes DeepSeek V4.1 Flash, GLM-5/5.3/5.3 Fast, Llama 3.3 70B Instruct, Kimi K3, Qwen3.5 35B-A3B + TTS + Reranker/Embedding + Image, Whisper Large V3 variants, Flux.2 [dev], EmbeddingGemma, Nomic Embed Code, BGE Embedding ICL, Inkling.
Documentationread2026-09-20
Baseten platform overview docs (read directly): three pathways - hosted Model APIs supporting the OpenAI Chat Completions API and a beta Anthropic Messages API, deploying an open-source/fine-tuned/custom model on dedicated GPUs, and Training Jobs/Loops.