Implement · Nebius (Token Factory)
Can you run it?
Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 60.8/100
This page is a projection of the one entry record, the Reliability and Data control factors that Implement covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
Which domain expands which factor
- AssessUse & modify + Transparency
- ImplementData control + Reliability
- UseReliability
- SupportTransparency
API integration
Nebius Token Factory exposes "a simple, OpenAI-compatible API" usable with standard OpenAI
client libraries (product page and docs, read directly).
Authentication & account setup
Public docs confirm API-key-based access via the OpenAI-compatible client libraries, but
org/project key-scoping granularity was not detailed in the sources read this pass - confirm the
exact setup in the Nebius console.
Region & ZDR configuration
Region selection is documented for AI Cloud and dedicated Token Factory endpoints
(docs.nebius.com/overview/regions, independently re-read): two public self-serve EU regions
(Finland, France), plus US, Israel, and UK. Correction: Spain and Iceland are private,
existing-deployment-only regions, not self-serve - a prior draft counted them as public. Zero
Data Retention is enabled per-account in settings, not by default, with a documented latency
trade-off. Shared/public endpoints do not carry the same region-pinning guarantee as dedicated
endpoints - confirm which applies to your workload before relying on a residency claim.
Rate limits, tiers & quotas
Public docs describe dedicated-endpoint autoscaling and pay-as-you-go-by-replica billing, but a
serverless rate-limit/quota table was not located in the sources read this pass - confirm current
throughput limits for your account before sizing a production workload.
Portability & exit
The DPA commits to deleting or returning Customer Personal Data on termination, at the
customer's choice. An OpenAI-compatible API over a predominantly open-weight catalogue keeps
served checkpoints portable. Correction: a prior claim that many flagship models are
dedicated-endpoint-only is not supported - they are publicly served per-token, simply superseded
by newer catalogue entries.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
3
ReliabilityDoes it stay up and stay secure?
ModerateCORRECTED 2026-09-21 (downward): a prior claim of a real contractual SLA with service credits is RETRACTED - an independent browser session found no committed inference SLA exists at all; the master SLA page delegates to seven per-service sub-pages, none of which is inference. What remains: a public status page with a dedicated Token Factory component, shown operational, with a documented but informal incident record.
How this scores (AOI sub-dimensions)
Reliability3/5whether it stays up, with an SLA and status historyCORRECTED 2026-09-21: an independent Cowork browser session found NO committed inference SLA at all - a prior draft claimed a real contractual SLA existed, which overstated it.
Security3/5the controls protecting your traffic and dataEncryption at rest and in transit and need-to-know access management are referenced in the Legal Quick Guide (read directly), dedicated endpoints are marketed as single-tenant/isolated, and SOC 2 Type II implies independently tested operational controls.
Compliance4/5which independent certifications and attestations it holdsSTRENGTHENED 2026-09-21: independently confirmed verbatim - SOC 2 Type II is audited by a NAMED firm, "Deloitte", covering HIPAA; the ISO 27001 scope statement explicitly names "AI Cloud, AI Studio and TractoAI" (AI Studio = Token Factory, confirming this product is actually in scope, not just the company generally).
4
Doesn't extract your dataDo the binding terms keep your data and IP yours?
WeakThe binding Terms of Service Sec 7 (independently browser-confirmed verbatim) state Input/Output data is used by default to train Nebius' own models unless the customer opts out - directly contradicting the marketing claim of no training on content, and this finding survives independent human-grade verification - and separately reserve a right to delete customer Inputs/Outputs at any time without notice. Zero Data Retention exists only as an account-level opt-in, not a default.
How this scores (AOI sub-dimensions)
Data governance2/5retention, training-on-inputs and data ownershipThe binding Token Factory Terms of Service Sec 7 states Input/Output data is used by default to train Nebius' own "Speculative Decoding" models, contradicting the Legal Quick Guide's marketing claim that content is not used to train any models; an opt-out exists (onboarding form or email) and Zero Data Retention is available as an account-level opt-in, and sub-processors are fully disclosed (24 named entities) - real positives that keep this off the floor.
Residency3/5where your data is processed and storedCORRECTED 2026-09-21: an independent browser read of docs.nebius.com/overview/regions found only TWO public self-serve EU regions - Finland (eu-north1) and France (eu-west1) - not four as an earlier draft claimed; Spain (eu-south1) and Iceland (eu-north2) are private/existing-deployment-only.
What this means for adoptionYou do not fully control your data by default here: an independent Cowork browser session confirmed, verbatim, that the binding Token Factory Terms of Service (Sec 7) state your Inputs and Outputs are used to train Nebius' own models unless you actively opt out - a materially different posture from the marketing copy's 'we do not use your content to train any models' claim, and from every other provider in this batch. This is not an artefact of automated research; it holds up under independent verification. Compliance is genuinely strong (SOC 2 Type II by a named auditor - Deloitte - covering HIPAA; ISO 27001 scope confirmed to include Token Factory itself), but EU-region breadth is narrower than an earlier draft claimed (two public self-serve regions, not four) and there is no committed inference SLA at all (a prior claim to the contrary is retracted). Enabling Zero Data Retention in account settings closes the training gap - but you have to know to do it. If you route sensitive data through Nebius Token Factory, enable Zero Data Retention explicitly and confirm which endpoint (shared vs dedicated) actually carries your chosen region's residency guarantee before relying on it.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Terms of serviceread2026-09-20
Nebius Token Factory Terms of Service (read directly), Sec 7: Nebius collects and stores Inputs/Outputs by default and grants itself a licence to 'access, use, host, cache, store, copy, and modify Inputs and Outputs' to provide the Service AND to train its own smaller models used exclusively for 'Speculative Decoding'; opt-out available via onboarding form or emailing tokenfactory-support@nebius.com; separately reserves the right to 'remove, screen, or delete any of Your Inputs and Outputs at any time, for any reason, and without notice.' Sec 10(b)/(c): customer 'holds exclusive ownership of all rights, titles, and interests...
Documentationread2026-09-20
Nebius Legal Quick Guide (read directly): states 'We do not use your content to train, fine-tune or improve any AI models - ours or third parties'' - in tension with the binding Terms of Service Sec 7 (see ev-tos).
Terms of serviceread2026-09-20
Nebius Master Services Agreement (read directly), Sec 7.11: 'Nebius may use information about how the Customer use and interacts with the Services for the purpose of improvement of the Services...
Data Processing Addendumread2026-09-20
Nebius Data Processing Addendum (read directly): imposes a processor-side confidentiality duty specifically over 'Customer Personal Data' ('any person that it authorizes to process Customer Personal Data...
Subprocessorsread2026-09-20
CORRECTED 2026-09-21 (count): Nebius Token Factory sub-processor list, independently browser-read, effective 2026-09-15: approximately 21 named entities enumerated (the page's own summary line said 18; a prior draft said ~24 - an exact recount is recommended) across Nebius Group entities (Nebius Inc.
Securityread2026-09-20
STRENGTHENED 2026-09-21: Nebius Trust Center and the linked SOC 2 blog post, both independently browser-read, verbatim: SOC 2 Type II auditor is NAMED - 'Deloitte, an accredited third-party firm that evaluates the design and operational effectiveness of our measures to protect customer data' - and 'SOC 2 Type II also includes a section that confirms compliance with...
Documentationread2026-09-20
Nebius regions documentation (read directly): public regions eu-north1 (Finland), eu-west1 (France), me-west1 (Israel), uk-south1/uk-south2 (UK), us-central1 (US); private/ negotiated regions eu-north2 (Iceland), eu-south1 (Madrid, Spain), eu-west2 (France), us-north1 (US).
Slaread2026-09-20
CORRECTED 2026-09-21: Nebius master SLA page, independently browser-read, verbatim: 'The list of Services which provides Service Levels and links for Service Levels for specific Service are available at: https://docs.nebius.com/legal/sla-levels' and 'Service Level and amount of Compensation is determined for each Service separately.' No number in the master doc; no mention of inference/Token Factory/AI Studio.
Slaread2026-09-20
UPGRADED 2026-09-21: Nebius public status page (status.nebius.com), independently browser-read: a dedicated 'Token Factory' component shown Operational (no separate 'Inference'/'AI Studio' component); regions covered EU-NORTH1, EU-NORTH2, EU-WEST1, EU-WEST2, UK-SOUTH1, US-CENTRAL1, ME-WEST1; 'Uptime over the past 90 days' shown with no numeric % on the main view.
Documentationread2026-09-20
CORRECTED 2026-09-21: Nebius Token Factory live model catalogue, re-checked independently (tokenfactory.nebius.com/models/catalog): roughly 90 model variants.
Documentationread2026-09-20
Nebius dedicated-endpoint billing-policy docs (read directly): billed per running replica on a pay-as-you-go basis, adjusting dynamically with autoscaling; 'charges may vary depending on your custom contract or work order' - the underlying per-replica/GPU-hour rate itself is not disclosed on this page.
Documentationread2026-09-20
Nebius Token Factory product page (read directly): 'a simple, OpenAI-compatible API' over an open-weight model catalogue, with both shared/public per-token endpoints and dedicated single-tenant endpoints.