Implement · Baseten
Can you run it?
Ownership levelSubstantialnone·limited·partial·substantial·fullAnalytical input B ยท 73.6/100
This page is a projection of the one entry record, the Reliability and Data control factors that Implement covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
Which domain expands which factor
- AssessUse & modify + Transparency
- ImplementData control + Reliability
- UseReliability
- SupportTransparency
API integration
Hosted Model APIs support the OpenAI Chat Completions API and a beta Anthropic Messages
API (docs.baseten.co/overview, read directly). Custom deploys use customer-authored
Truss/Docker configs rather than a Baseten-proprietary format, which itself aids portability
of the deployment definition.
Authentication & account setup
Public docs describe API-key-based access, but org/workspace key-scoping granularity was not
detailed in the sources read this pass - confirm the exact setup in the Baseten console.
Region & residency configuration
"Regional environments" route a deployment exclusively to a designated geographic region, but
require Baseten to configure it - the docs say to contact support to confirm availability for
the region you need; there is no published, self-serve region list. Self-Hosted is the
alternative: the workload plane runs in any customer-chosen region/VPC, including the EU.
Rate limits, tiers & quotas
Baseten's pricing page documents GPU/token rates and account tiers (Basic/Pro/Enterprise) in
detail, but a specific rate-limit/quota table was not located in the sources read this pass -
confirm current throughput limits for your account before sizing a production workload.
Portability & exit
Terms & Conditions give a documented exit right: Customer Content may be exported for 30 days
after the Term ends, and Baseten will delete Customer Content on written request. Open-weight
models in the Model Library and customer-authored deploy configs keep the workload itself
portable beyond Baseten.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
3
ReliabilityDoes it stay up and stay secure?
StrongUPGRADED 2026-09-21: a real, committed SLA was independently browser-read (99.9% uptime, 40%-capped service credits, 24h claim window) - a prior draft held this at moderate because no SLA had been located. The public status page shows all systems operational with three brief, same/next-day-resolved incidents in the current window.
How this scores (AOI sub-dimensions)
Reliability4/5whether it stays up, with an SLA and status historyUPGRADED 2026-09-21: an independent Cowork browser session found and directly read a real, committed SLA (baseten.co/service-level-agreement, Sec 2.0) - 99.9% uptime for both Dedicated Inference and Model APIs, with a service-credit remedy (capped at 40% of monthly fees, Sec 4.2) and a 24-hour claim window (Sec 4.3).
Security4/5the controls protecting your traffic and dataCORRECTED 2026-09-21 (description, not score): independently browser-confirmed isolation is logical namespace separation for shared use (access controls, unique customer identifiers, namespace isolation) plus single-tenant dedicated Kubernetes namespaces with Calico/Cilium network policies ("GPUs never shared across users") and self-hosted deployment inside the customer's own VPC - not an explicit "three-tier" model as an earlier draft described it, though the practical effect is similar.
Compliance4/5which independent certifications and attestations it holdsCORRECTED 2026-09-21: SOC 2 Type II is confirmed with a named audit firm (Sensiba San Filippo LLP, clean opinion across Security/Availability/Processing Integrity/Confidentiality/Privacy criteria); HIPAA and GDPR are independently confirmed on the Security Practices and DPA pages.
4
Doesn't extract your dataDo the binding terms keep your data and IP yours?
StrongThe Terms & Conditions and security-practices page (independently browser-read, Sec 11 confirmed on two fetches) state Zero Data Retention by default for Model APIs and Dedicated Inference, a contractual never-train clause, and a MUTUAL confidentiality duty - among the strongest standard-terms data-control postures reviewed, now independently verified rather than resting on a single automated read. Caveat: Async Inference queues inputs for up to 72 hours, and no published EU region exists for the managed service.
How this scores (AOI sub-dimensions)
Data governance4/5retention, training-on-inputs and data ownershipTerms & Conditions and the security-practices/DPA pages together give a strong, binding posture: Zero Data Retention by default for Model APIs and Dedicated Inference, a contractual never-train clause covering Customer Content (including deployed model weights and outputs), customer ownership of Customer Content, and a MUTUAL confidentiality duty (same care as own information, three-year survival).
Residency2/5where your data is processed and storedA "regional environments" feature exists, routing a deployment exclusively to a designated geographic region, but no published list of available regions - including whether an EU region is among them - was found; the docs direct customers to contact support.
What this means for adoptionYou substantially own inference here: an independent Cowork browser session confirmed, on two separate fetches, that Baseten's Terms & Conditions state Zero Data Retention by default, a contractual bar on using your content (including deployed model weights) to train its models, and a genuinely mutual confidentiality duty - a stronger standard-terms posture than most peers, and now independently verified rather than resting on a single automated read. A real, committed 99.9% SLA with service credits was also confirmed. It falls short of full ownership because a prior ISO 27001 claim was retracted (not found anywhere on independent verification), the Vanta Trust Center is fully JS-gated so PCI/FedRAMP/CSA STAR status and the named sub-processor list remain unverified, no published EU region exists for the managed service (EU residency means the enterprise Self-Hosted tier), and Async Inference has a 72-hour retention exception. If you need EU data residency or want certifications independently confirmed, use the Self-Hosted tier or ask for the underlying reports directly.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Terms of serviceread2026-09-20
Baseten Terms & Conditions (read directly): Sec on Customer Content ownership - 'Customer reserves all rights, title, and interest in and to Customer Content,' where Customer Content includes Customer Models (deployed weights) and Model Outputs; a training-prohibition clause bars Baseten from using Customer Content to train, fine-tune, or otherwise develop ML/AI models, limiting its license to providing/maintaining the Services and preventing/addressing technical problems, plus anonymized/de-identified telemetry; mutual confidentiality clause requiring 'the same degree of care it uses for its own (but no less than reasonable care),' surviving three years post-termination, with prior-notice compelled disclosure; a documented exit right - Customer Content exportable for 30 days after Term end, deletable on written request.
Securityread2026-09-20
Baseten security-practices page (read directly): Zero Data Retention for Model APIs and Dedicated Inference ('will not store, retain, or otherwise make a persistent copy of model inputs or outputs'); Async Inference queues inputs up to 72 hours before deletion, outputs never stored; three-tier tenant isolation (shared logical separation; dedicated single-tenant Kubernetes namespaces with Calico/Cilium network policies, 'never shares GPUs across users'; self-hosted in customer VPC); TLS 1.2+ in transit, AES-256 at rest with periodic key rotation; least-privilege access, enforced MFA, quarterly access reviews; periodic third-party penetration testing; KV cache never persisted to disk.
Data Processing Addendumread2026-09-20
Baseten DPA (read directly): 'Baseten shall not log, record, or save Customer Personal Data contained in model inputs or outputs to persistent storage after real-time processing'; Baseten as Processor, Customer as Controller; SCCs incorporated, governing law/jurisdiction Ireland (Clause 17/18); UK Addendum (ICO template B.1.0) for UK transfers; a sub-processor list is maintained with at least fifteen (15) days' prior notice before engaging a new sub-processor.
Vendor announcementread2026-09-20
Baseten blog post confirming SOC 2 Type II certification, audited by Sensiba San Filippo LLP, covering Security/Availability/Processing Integrity/Confidentiality/Privacy criteria with a clean opinion across 70+ sub-criteria; the report itself is gated under NDA.
Documentationread2026-09-20
Baseten regional-environments docs (read directly): routes inference traffic for a deployment 'exclusively to workload planes within a designated geographic region'; requires initial configuration by Baseten - 'Contact support to confirm availability for the region you need.' No published list of specific region names was found.
Documentationread2026-09-20
Baseten Self-Hosted product page (read directly): the full workload plane runs inside the customer's own VPC/cloud, with inference input/output 'never touching Baseten's premises'; marketed toward the Enterprise pricing tier.
Slaread2026-09-20
UPGRADED 2026-09-21: Baseten's public status page (status.baseten.co), independently browser-read: 'All Systems Operational' across 6 components (Dedicated Inference, Model APIs, Training, Model Management API, Web Application, Homepage and Docs); 90-day history, no numeric % shown on the face.
Slaread2026-09-21
Baseten Service Level Agreement (independently browser-read 2026-09-21, verbatim): Sec 2.0 - 'ninety-nine point nine percent (99.9%)' committed uptime, applying to both Dedicated Inference and Model APIs on Baseten-managed infrastructure.
Vendor announcementread2026-09-20
Baseten pricing page (read directly): per-token Model API rates (e.g.
Documentationread2026-09-20
Baseten Model Library page (read directly): current curated catalogue includes DeepSeek V4.1 Flash, GLM-5/5.3/5.3 Fast, Llama 3.3 70B Instruct, Kimi K3, Qwen3.5 35B-A3B + TTS + Reranker/Embedding + Image, Whisper Large V3 variants, Flux.2 [dev], EmbeddingGemma, Nomic Embed Code, BGE Embedding ICL, Inkling.
Documentationread2026-09-20
Baseten platform overview docs (read directly): three pathways - hosted Model APIs supporting the OpenAI Chat Completions API and a beta Anthropic Messages API, deploying an open-source/fine-tuned/custom model on dedicated GPUs, and Training Jobs/Loops.