Assess · Nebius (Token Factory)

Can you own it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 60.8/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Reliability
  • UseReliability
  • SupportTransparency

Data governance - retention, ZDR & training

This is the entry's central finding, and an independent Cowork browser session (2026-09-21) CONFIRMED it VERBATIM. Nebius' marketing-adjacent Legal Quick Guide states "we do not use your content to train, fine-tune or improve any AI models - ours or third parties'." But the binding Token Factory Terms of Service, Sec 7 (independently re-read) states Nebius collects and processes Input/Output data by default and uses it to train its own smaller "Speculative Decoding" models, unless the customer actively opts out (via an onboarding form or by emailing support). Zero Data Retention is an account-level opt-in, not the default - and the Legal Quick Guide itself warns that enabling it "may impact the level of service provided (e.g., inference speed)." This finding survives independent human-grade verification, not just an automated read - it is real.

Data & IP ownership

Terms of Service Sec 10(b)/(c) (independently re-read): the customer "holds exclusive ownership of all rights, titles, and interests... to Customer's Content," subject to the Sec 7 operational licence described above. Sec 7 separately reserves the right to "remove, screen, or delete any of Your Inputs and Outputs at any time, for any reason, and without notice." Neither the general Master Agreement confidentiality clause (Sec 18) nor Sec 7 names Customer Content as the customer's own Confidential Information; the DPA's processor-confidentiality duty is scoped to Customer Personal Data, not Customer Content generally. Sub-processors are fully disclosed: approximately 21 named entities (corrected from an earlier ~24; exact recount recommended) with a 15-day advance-notice commitment.

Residency & sovereignty

Correction: only two EU regions are public/self-serve - Finland (eu-north1) and France (eu-west1). Spain (eu-south1) and Iceland (eu-north2), plus a second French region (eu-west2), are private - "available only to the users who already have deployments there," not self-serve. An earlier draft claimed four public EU regions; an independent browser read of the regions page corrected this. The DPA documents region pinning for AI Cloud and Token Factory dedicated endpoints, but for shared/public Token Factory endpoints - the self-serve, majority-usage surface - processing location "may vary." A US sub-processor entity (Nebius Inc.) and a us-central1 public region exist alongside the Netherlands-domiciled parent (Nebius Group N.V.), creating plausible CLOUD Act exposure that no primary document addresses explicitly.

Compliance & attestations

Nebius' Trust Center and SOC 2 blog post (independently browser-read, verbatim) document SOC 2 Type II audited by a NAMED firm - Deloitte - covering HIPAA, and an ISO 27001 scope statement that explicitly names "AI Studio" (Token Factory itself, not just the company generally) alongside AI Cloud and TractoAI. A GDPR DPA and CSA STAR Level 1 are also documented. The underlying SOC 2 report still requires an NDA and discloses no public audit dates - compliance remains publisher-grade + named auditor, short of an independently-dated public certificate. FedRAMP is not offered.

Security controls

The Legal Quick Guide references encryption at rest and in transit and need-to-know access management, and dedicated endpoints are marketed as single-tenant/isolated. This language is generic - no cipher specifics, no independently confirmed penetration-testing programme, and no public bug-bounty were found. SOC 2 Type II implies some independently tested operational controls, but that is not the same as a named pen-test disclosure.

Pricing & cost model

Public per-token pricing is verified directly and on re-check for several live public endpoints - DeepSeek-V4-Pro at $1.75/$3.50 per 1M tokens, gpt-oss-120b at $0.15/$0.60, Llama-3.3-70B-Instruct at $0.13/$0.40. Correction: a prior claim that several flagship models (Kimi-K2-Instruct, Llama-3.3-70B-Instruct, GLM-4.5) showed "Public endpoint: Not available" is not supported on re-check - those specific named versions have simply been superseded by newer catalogue entries (ordinary churn), not gated behind a dedicated tier. The dedicated tier's underlying per-replica/GPU-hour rate remains not disclosed, described only as varying "depending on your custom contract or work order," and the full authoritative live price list is auth-gated.

Reliability posture

Correction: there is NO committed inference SLA at all. A prior draft claimed a real contractual SLA existed with only the exact number unconfirmed - this overstated it. The master SLA page (independently re-read) delegates entirely to per-service sub-pages; that index lists exactly seven services (Compute Cloud, Managed Kubernetes, Managed MLflow, Managed PostgreSQL, Object Storage, Standalone Applications, Virtual Private Cloud) and none of them is inference, Token Factory, or AI Studio. The marketed 99.9% figure is confirmed marketing-only. A public status page (independently confirmed) shows a dedicated Token Factory component as Operational, with three brief, resolved incidents in the Sep 9-17 2026 window.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you use it freely and leave without lock-in?

Strong

An OpenAI-compatible API over a predominantly open-weight catalogue keeps served checkpoints portable, and the customer retains ownership of Customer Content subject to Nebius' operational licence. CORRECTED 2026-09-21: a prior claim that many flagship models are dedicated-endpoint-only is not supported - they are publicly served per-token, simply superseded by newer catalogue entries.

How this scores (AOI sub-dimensions)
Transparency & lock-in4/5how portable it is and how easily you can leaveAn OpenAI-compatible API over a predominantly open-weight catalogue keeps served checkpoints portable, and the DPA commits to deleting or returning Customer Personal Data on termination.
Cost3/5how the pricing model compares and how predictable it isCORRECTED 2026-09-21: per-token pricing is confirmed publicly visible for current catalogue models (e.g.
2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The Terms of Service, DPA, Legal Quick Guide and regions/SLA pages are legible and were independently browser-read - but they contain a CONFIRMED internal discrepancy (marketing says no training on content; the binding Terms say otherwise, opt-out only), and the dedicated-tier per-GPU-hour rate is not publicly disclosed. An earlier draft also overstated the public EU-region count (four, corrected to two) and the existence of a committed inference SLA (corrected to none) - both now fixed, but the overstatement itself is a data point about how carefully marketing-adjacent claims need checking here.

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou do not fully control your data by default here: an independent Cowork browser session confirmed, verbatim, that the binding Token Factory Terms of Service (Sec 7) state your Inputs and Outputs are used to train Nebius' own models unless you actively opt out - a materially different posture from the marketing copy's 'we do not use your content to train any models' claim, and from every other provider in this batch. This is not an artefact of automated research; it holds up under independent verification. Compliance is genuinely strong (SOC 2 Type II by a named auditor - Deloitte - covering HIPAA; ISO 27001 scope confirmed to include Token Factory itself), but EU-region breadth is narrower than an earlier draft claimed (two public self-serve regions, not four) and there is no committed inference SLA at all (a prior claim to the contrary is retracted). Enabling Zero Data Retention in account settings closes the training gap - but you have to know to do it. If you route sensitive data through Nebius Token Factory, enable Zero Data Retention explicitly and confirm which endpoint (shared vs dedicated) actually carries your chosen region's residency guarantee before relying on it.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Terms of serviceread2026-09-20
Nebius Token Factory Terms of Service (read directly), Sec 7: Nebius collects and stores Inputs/Outputs by default and grants itself a licence to 'access, use, host, cache, store, copy, and modify Inputs and Outputs' to provide the Service AND to train its own smaller models used exclusively for 'Speculative Decoding'; opt-out available via onboarding form or emailing tokenfactory-support@nebius.com; separately reserves the right to 'remove, screen, or delete any of Your Inputs and Outputs at any time, for any reason, and without notice.' Sec 10(b)/(c): customer 'holds exclusive ownership of all rights, titles, and interests...
Documentationread2026-09-20
Nebius Legal Quick Guide (read directly): states 'We do not use your content to train, fine-tune or improve any AI models - ours or third parties'' - in tension with the binding Terms of Service Sec 7 (see ev-tos).
Terms of serviceread2026-09-20
Nebius Master Services Agreement (read directly), Sec 7.11: 'Nebius may use information about how the Customer use and interacts with the Services for the purpose of improvement of the Services...
Data Processing Addendumread2026-09-20
Nebius Data Processing Addendum (read directly): imposes a processor-side confidentiality duty specifically over 'Customer Personal Data' ('any person that it authorizes to process Customer Personal Data...
Subprocessorsread2026-09-20
CORRECTED 2026-09-21 (count): Nebius Token Factory sub-processor list, independently browser-read, effective 2026-09-15: approximately 21 named entities enumerated (the page's own summary line said 18; a prior draft said ~24 - an exact recount is recommended) across Nebius Group entities (Nebius Inc.
Securityread2026-09-20
STRENGTHENED 2026-09-21: Nebius Trust Center and the linked SOC 2 blog post, both independently browser-read, verbatim: SOC 2 Type II auditor is NAMED - 'Deloitte, an accredited third-party firm that evaluates the design and operational effectiveness of our measures to protect customer data' - and 'SOC 2 Type II also includes a section that confirms compliance with...
Documentationread2026-09-20
Nebius regions documentation (read directly): public regions eu-north1 (Finland), eu-west1 (France), me-west1 (Israel), uk-south1/uk-south2 (UK), us-central1 (US); private/ negotiated regions eu-north2 (Iceland), eu-south1 (Madrid, Spain), eu-west2 (France), us-north1 (US).
Slaread2026-09-20
CORRECTED 2026-09-21: Nebius master SLA page, independently browser-read, verbatim: 'The list of Services which provides Service Levels and links for Service Levels for specific Service are available at: https://docs.nebius.com/legal/sla-levels' and 'Service Level and amount of Compensation is determined for each Service separately.' No number in the master doc; no mention of inference/Token Factory/AI Studio.
Slaread2026-09-20
UPGRADED 2026-09-21: Nebius public status page (status.nebius.com), independently browser-read: a dedicated 'Token Factory' component shown Operational (no separate 'Inference'/'AI Studio' component); regions covered EU-NORTH1, EU-NORTH2, EU-WEST1, EU-WEST2, UK-SOUTH1, US-CENTRAL1, ME-WEST1; 'Uptime over the past 90 days' shown with no numeric % on the main view.
Documentationread2026-09-20
CORRECTED 2026-09-21: Nebius Token Factory live model catalogue, re-checked independently (tokenfactory.nebius.com/models/catalog): roughly 90 model variants.
Documentationread2026-09-20
Nebius dedicated-endpoint billing-policy docs (read directly): billed per running replica on a pay-as-you-go basis, adjusting dynamically with autoscaling; 'charges may vary depending on your custom contract or work order' - the underlying per-replica/GPU-hour rate itself is not disclosed on this page.
Documentationread2026-09-20
Nebius Token Factory product page (read directly): 'a simple, OpenAI-compatible API' over an open-weight model catalogue, with both shared/public per-token endpoints and dedicated single-tenant endpoints.