Alpha
Contact
Assess · DeepInfra

Can you own it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 56.8/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Reliability
  • UseReliability
  • SupportTransparency

Data governance - retention, ZDR & training

Correction (2026-09-21): a rewritten Terms of Service (effective 2026-08-17) makes Zero Data Retention contractual and controlling - Sec 7(b): "Provider will not retain, store, or log any Customer Data submitted to or generated by the Services beyond the period strictly necessary to process and return the applicable request... ('Zero Data Retention')", and Sec 5(a) states this "controls over the Privacy Policy and any other Provider policy." The old open-ended debugging carve-out is replaced by bounded exceptions: support diagnostics deleted within 30 days, operational metadata (excludes content), and legal-compliance records. Training remains never by contract, properly scoped: "Provider will not use Customer Data to train, fine-tune, or otherwise improve any model, except as necessary to provide the Services."

The decisive caveat is scope: this covers DeepInfra's own open-model serving only. The same documents state that when you route requests to the closed models it re-sells - Anthropic Claude, Google - DeepInfra transfers your data to those endpoints to fulfil the request, and that vendor's storage and training policy applies (Google stores the output per its Privacy Notice; Anthropic per its Trust Centre). This is the key finding for anyone assuming a single blanket data guarantee: the guarantee is model-dependent, so segregate open-model and closed-model traffic when governance matters.

Data & IP ownership

For DeepInfra's own open-model serving, the ownership story is clean and grounded in the Terms of Service, which state you retain any intellectual property rights over your Submissions. Correction (2026-09-21): the rewritten Terms add Sec 17, a genuine bilateral confidentiality duty (three-year survival) - replacing the prior "will remain private" non-commitment. Combined with zero-retention and no training on submitted data, your inputs, outputs and any derived knowledge stay yours - customer_retains. But ownership is not uniform across the catalogue. The closed models DeepInfra re-sells - Anthropic Claude, Google - are transferred to those vendors and route your data under their storage and training terms rather than DeepInfra's, so whether your data stays proprietary depends on which model you call. The sub-processor list is not disclosed. Segregate open- and closed-model traffic and pin the terms per model.

Compliance & attestations

DeepInfra's data-privacy documentation states SOC 2 and ISO 27001 certification plus GDPR and HIPAA technical/organisational measures. The finer SOC 2 Type 1 (point-in-time, not Type II) designation, the sub-processor list and ISO 27701 status live on the Sprinto-powered trust centre, which is unreachable - documented but unverified. HIPAA is framed as measures, not a BAA. For healthcare or continuous-controls procurement, confirm the SOC 2 Type and the HIPAA posture on the trust centre directly.

Data residency & jurisdiction

DeepInfra operates US-based data centres only - no EU data-residency option was surfaced and region pinning is unconfirmed. For workloads with EU residency requirements this is a hard constraint that no plan upgrade removes. As a US-headquartered company it also carries standing US CLOUD Act exposure.

Security controls

Baseline controls are evidenced by ISO 27001 and SOC 2 certification, and the retrieved data-privacy docs confirm batch data is held encrypted on disk then deleted. The assessment is held to partial because the SOC 2 Type-1-vs-Type-II distinction rests on the unretrieved trust centre and no independent penetration test was surfaced.

Pricing & cost model

Cost is DeepInfra's standout: it is among the cheapest providers on the market. Pricing is mixed - pay-as-you-go per-token (indicatively Llama 3.1 8B ~$0.02/M, Llama 3.3 70B ~$0.35/M, gpt-oss-120B ~$0.08/M blended) plus dedicated GPU by the hour (A100 $0.89, H100 $1.79, H200 $2.19, B200 $2.79). Rates are approximate, so confirm live pricing, but the order of magnitude is the reason to consider DeepInfra.

Reliability posture

No incidents have been reported, but no public uptime SLA or failover documentation was independently verified. Reliability is therefore assessed conservatively: adequate on available evidence, but without an observable status/SLA record to lean on for availability-critical workloads.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you use it freely and leave without lock-in?

Strong

OpenAI-compatible API over ~77-90+ portable open-weight checkpoints on NVIDIA GPUs - the same models run elsewhere or self-hosted, so switching cost for the open catalogue is low.

How this scores (AOI sub-dimensions)
Transparency & lock-in4/5how portable it is and how easily you can leaveOpenAI-compatible API serving portable open-weight models with clear per-token and per-GPU-hour options.
Cost5/5how the pricing model compares and how predictable it isAmong the cheapest providers on the market, with very low per-token rates and competitive by-the-hour dedicated GPUs.
2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The Terms and data-privacy docs are legible and the open catalogue is clear, but re-selling closed models under other vendors' terms adds routing opacity, sub-processors are undisclosed, and the SOC 2 Type designation sits on an unretrieved trust centre.

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou substantially control your data on DeepInfra's own open-model serving, and more so than a prior grounding found: an independently re-verified rewrite of the Terms of Service (2026-08-17) adds a genuine mutual confidentiality clause and makes Zero Data Retention contractual and controlling with a bounded 30-day exception, on top of the already-confirmed no-training and customer-retained IP. Ownership is capped at partial because that control is not uniform - the re-sold closed models (Claude, Google) are transferred to those vendors and carry their data terms rather than DeepInfra's, so route no sensitive data through them - and US-only residency rules it out where EU data sovereignty is required. The ToS's self-serve-vs-enterprise scope and the compliance trust centre remain to be independently re-confirmed.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Documentationread2026-07-25
DeepInfra data-privacy documentation: zero-retention by default, only debugging metadata (request ID, cost, sampling parameters) is logged, batch/bulk data is held encrypted on disk then deleted after a short retention period, it does not train on submitted data, it runs on secure US-based data centres, and it is SOC 2 and ISO 27001 certified.
Privacy Policyread2026-07-25
DeepInfra data-privacy statement: it does not use API data for training except when using Google or Anthropic models, where the receiving company's training policy applies - if you use a Google model, Google stores the output per its Privacy Notice; if you use an Anthropic model, Anthropic stores the output per its Trust Centre.
Terms of serviceread2026-07-25
DeepInfra Terms of Service: 'When you submit data, content, materials, or requests into models through DeepInfra (Submissions), you retain any intellectual property rights over such Submissions, which will remain private'; DeepInfra does not share data with third parties except when using Google or Anthropic models, where it is required to transfer data to those endpoints to fulfil the request.
Securityunverified2026-07-25
Trust centre (Sprinto-powered) is stated to list SOC 2 Type 1 (not Type II) and ISO 27001; the SOC 2 Type designation, sub-processor list and ISO 27701 status were not read verbatim this session - documented but unverified.
Third-party analysisunverified2026-07-25
Among the cheapest providers (third-party pricing research): per-token e.g.
Documentationread2026-07-25
DeepInfra data-privacy documentation states it runs on secure US-based data centres; no EU data-residency option was surfaced.
Third-party analysisunverified2026-07-25
Serves ~77-90+ open models over an OpenAI-compatible API on NVIDIA GPUs plus per-hour GPU instances; also re-sells some closed models (Anthropic Claude, Google).
Terms of serviceread2026-09-21
DeepInfra Terms of Service, rewritten into a full 20-section MSA-style agreement, effective 2026-08-17 (independently browser-read 2026-09-21, after the prior 2026-08-06 grounding).