Implement · DeepInfra
Can you run it?
Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 56.8/100
This page is a projection of the one entry record, the Reliability and Data control factors that Implement covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
Which domain expands which factor
- AssessUse & modify + Transparency
- ImplementData control + Reliability
- UseReliability
- SupportTransparency
API integration
DeepInfra exposes an OpenAI-compatible API over NVIDIA GPUs, plus per-hour dedicated
GPU instances for reserved capacity. An existing OpenAI client integrates by changing the
base URL and API key, giving access to the ~77-90+ served models through familiar
chat/completions shapes - integration is largely a configuration change rather than a rewrite.
Region & ZDR configuration
Zero-retention is the default posture, so no toggle is required for the core no-store
behaviour on DeepInfra's own open-model serving. Region control, by contrast, is effectively
absent: there is no EU region to select (US-only data centres) and region pinning is
unconfirmed. If EU residency is a requirement, DeepInfra does not meet it.
Portability & exit
For the open-weight catalogue the exit path is clean: the OpenAI-compatible endpoint
over portable checkpoints means the same models run on other providers or self-hosted, so
switching cost is dominated by re-pointing the base URL and re-validating outputs. The
exception is the re-sold closed models (Anthropic Claude, Google) - those are not
portable and carry different data terms, so any workload that leans on them does not inherit
the open-model portability.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
3
ReliabilityDoes it stay up and stay secure?
ModerateSOC 2 and ISO 27001 certification give baseline controls, but the Type designation is unverified and no public uptime SLA, status page or independent pen-test was found.
How this scores (AOI sub-dimensions)
Reliability2/5whether it stays up, with an SLA and status historyNo incidents surfaced, but no public uptime SLA, status page or failover documentation was independently verified.
Security3/5the controls protecting your traffic and dataISO 27001 and SOC 2 certification indicate baseline controls, and the retrieved data-privacy documentation confirms batch data is held encrypted on disk then deleted.
Compliance2/5which independent certifications and attestations it holdsSOC 2 (Type 1 only, not Type II) and ISO 27001 appear as claims on the Sprinto-powered trust centre, which is unreachable - self-attested, not independently verified.
4
Doesn't extract your dataDo the binding terms keep your data and IP yours?
ModerateCORRECTED 2026-09-21: for DeepInfra's own open-model serving, the rewritten ToS (independently browser-read) now adds a genuine mutual confidentiality duty (Sec 17) and makes Zero Data Retention contractual and controlling with a bounded exception (Sec 7(b)), on top of the already-confirmed no-training and customer-retained IP. It falls short of strong because closed models (Claude, Google) re-sold through it are transferred to those vendors under their storage/training terms, sub-processors are undisclosed, residency is US-only with CLOUD Act exposure, and the ToS's self-serve-vs-enterprise scope is not fully confirmed.
How this scores (AOI sub-dimensions)
Data governance4/5retention, training-on-inputs and data ownershipCORRECTED 2026-09-21: a rewritten ToS (effective 2026-08-17, independently browser-read) resolves the two findings that previously held this at 3.
Residency1/5where your data is processed and storedThe retrieved data-privacy documentation states DeepInfra runs on secure US-based data centres; no EU data-residency option was surfaced and region pinning is unconfirmed, so it sits near the single-region floor.
What this means for adoptionYou substantially control your data on DeepInfra's own open-model serving, and more so than a prior grounding found: an independently re-verified rewrite of the Terms of Service (2026-08-17) adds a genuine mutual confidentiality clause and makes Zero Data Retention contractual and controlling with a bounded 30-day exception, on top of the already-confirmed no-training and customer-retained IP. Ownership is capped at partial because that control is not uniform - the re-sold closed models (Claude, Google) are transferred to those vendors and carry their data terms rather than DeepInfra's, so route no sensitive data through them - and US-only residency rules it out where EU data sovereignty is required. The ToS's self-serve-vs-enterprise scope and the compliance trust centre remain to be independently re-confirmed.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Documentationread2026-07-25
DeepInfra data-privacy documentation: zero-retention by default, only debugging metadata (request ID, cost, sampling parameters) is logged, batch/bulk data is held encrypted on disk then deleted after a short retention period, it does not train on submitted data, it runs on secure US-based data centres, and it is SOC 2 and ISO 27001 certified.
Privacy Policyread2026-07-25
DeepInfra data-privacy statement: it does not use API data for training except when using Google or Anthropic models, where the receiving company's training policy applies - if you use a Google model, Google stores the output per its Privacy Notice; if you use an Anthropic model, Anthropic stores the output per its Trust Centre.
Terms of serviceread2026-07-25
DeepInfra Terms of Service: 'When you submit data, content, materials, or requests into models through DeepInfra (Submissions), you retain any intellectual property rights over such Submissions, which will remain private'; DeepInfra does not share data with third parties except when using Google or Anthropic models, where it is required to transfer data to those endpoints to fulfil the request.
Securityunverified2026-07-25
Trust centre (Sprinto-powered) is stated to list SOC 2 Type 1 (not Type II) and ISO 27001; the SOC 2 Type designation, sub-processor list and ISO 27701 status were not read verbatim this session - documented but unverified.
Third-party analysisunverified2026-07-25
Among the cheapest providers (third-party pricing research): per-token e.g.
Documentationread2026-07-25
DeepInfra data-privacy documentation states it runs on secure US-based data centres; no EU data-residency option was surfaced.
Third-party analysisunverified2026-07-25
Serves ~77-90+ open models over an OpenAI-compatible API on NVIDIA GPUs plus per-hour GPU instances; also re-sells some closed models (Anthropic Claude, Google).
Terms of serviceread2026-09-21
DeepInfra Terms of Service, rewritten into a full 20-section MSA-style agreement, effective 2026-08-17 (independently browser-read 2026-09-21, after the prior 2026-08-06 grounding).