Support · Nebius (Token Factory)

Will it last?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 60.8/100

This page is a projection of the one entry record, the Transparency factor that Support covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Reliability
  • UseReliability
  • SupportTransparency

Status page & uptime history

A public status page (status.nebius.com, independently browser-confirmed) shows a dedicated "Token Factory" component as Operational, with a 90-day uptime-history view (no numeric % shown on the face). Three brief, resolved incidents in the Sep 9-17 2026 window: partial metrics unavailability in eu-west1, partial Object Storage 5xx errors in us-central1, and SkyPilot cluster-creation errors (503) in eu-north1.

Security disclosure & trust centre

A published Trust Center (nebius.com/trust-center, read directly) documents SOC 2 Type II, ISO 27001/27701, CSA STAR Level 1, and GDPR/CCPA posture. No public bug-bounty programme was found.

Support & community channels

Product/console documentation (docs.tokenfactory.nebius.com and docs.nebius.com) is the primary support surface. Support-tier response commitments were not detailed in the sources read this pass - confirm what comes with your account tier during onboarding.

Model deprecation policy

No published model-deprecation or end-of-life policy was found on Nebius' public docs in the sources read this pass. Because the catalogue is predominantly open-weight, a removed model can generally be sourced from another provider - but confirm Nebius' own migration practice directly if this matters for your workload.

How this scores

The ownership factor this domain covers, drawn from the one entry record.

2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The Terms of Service, DPA, Legal Quick Guide and regions/SLA pages are legible and were independently browser-read - but they contain a CONFIRMED internal discrepancy (marketing says no training on content; the binding Terms say otherwise, opt-out only), and the dedicated-tier per-GPU-hour rate is not publicly disclosed. An earlier draft also overstated the public EU-region count (four, corrected to two) and the existence of a committed inference SLA (corrected to none) - both now fixed, but the overstatement itself is a data point about how carefully marketing-adjacent claims need checking here.

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou do not fully control your data by default here: an independent Cowork browser session confirmed, verbatim, that the binding Token Factory Terms of Service (Sec 7) state your Inputs and Outputs are used to train Nebius' own models unless you actively opt out - a materially different posture from the marketing copy's 'we do not use your content to train any models' claim, and from every other provider in this batch. This is not an artefact of automated research; it holds up under independent verification. Compliance is genuinely strong (SOC 2 Type II by a named auditor - Deloitte - covering HIPAA; ISO 27001 scope confirmed to include Token Factory itself), but EU-region breadth is narrower than an earlier draft claimed (two public self-serve regions, not four) and there is no committed inference SLA at all (a prior claim to the contrary is retracted). Enabling Zero Data Retention in account settings closes the training gap - but you have to know to do it. If you route sensitive data through Nebius Token Factory, enable Zero Data Retention explicitly and confirm which endpoint (shared vs dedicated) actually carries your chosen region's residency guarantee before relying on it.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Terms of serviceread2026-09-20
Nebius Token Factory Terms of Service (read directly), Sec 7: Nebius collects and stores Inputs/Outputs by default and grants itself a licence to 'access, use, host, cache, store, copy, and modify Inputs and Outputs' to provide the Service AND to train its own smaller models used exclusively for 'Speculative Decoding'; opt-out available via onboarding form or emailing tokenfactory-support@nebius.com; separately reserves the right to 'remove, screen, or delete any of Your Inputs and Outputs at any time, for any reason, and without notice.' Sec 10(b)/(c): customer 'holds exclusive ownership of all rights, titles, and interests...
Documentationread2026-09-20
Nebius Legal Quick Guide (read directly): states 'We do not use your content to train, fine-tune or improve any AI models - ours or third parties'' - in tension with the binding Terms of Service Sec 7 (see ev-tos).
Terms of serviceread2026-09-20
Nebius Master Services Agreement (read directly), Sec 7.11: 'Nebius may use information about how the Customer use and interacts with the Services for the purpose of improvement of the Services...
Data Processing Addendumread2026-09-20
Nebius Data Processing Addendum (read directly): imposes a processor-side confidentiality duty specifically over 'Customer Personal Data' ('any person that it authorizes to process Customer Personal Data...
Subprocessorsread2026-09-20
CORRECTED 2026-09-21 (count): Nebius Token Factory sub-processor list, independently browser-read, effective 2026-09-15: approximately 21 named entities enumerated (the page's own summary line said 18; a prior draft said ~24 - an exact recount is recommended) across Nebius Group entities (Nebius Inc.
Securityread2026-09-20
STRENGTHENED 2026-09-21: Nebius Trust Center and the linked SOC 2 blog post, both independently browser-read, verbatim: SOC 2 Type II auditor is NAMED - 'Deloitte, an accredited third-party firm that evaluates the design and operational effectiveness of our measures to protect customer data' - and 'SOC 2 Type II also includes a section that confirms compliance with...
Documentationread2026-09-20
Nebius regions documentation (read directly): public regions eu-north1 (Finland), eu-west1 (France), me-west1 (Israel), uk-south1/uk-south2 (UK), us-central1 (US); private/ negotiated regions eu-north2 (Iceland), eu-south1 (Madrid, Spain), eu-west2 (France), us-north1 (US).
Slaread2026-09-20
CORRECTED 2026-09-21: Nebius master SLA page, independently browser-read, verbatim: 'The list of Services which provides Service Levels and links for Service Levels for specific Service are available at: https://docs.nebius.com/legal/sla-levels' and 'Service Level and amount of Compensation is determined for each Service separately.' No number in the master doc; no mention of inference/Token Factory/AI Studio.
Slaread2026-09-20
UPGRADED 2026-09-21: Nebius public status page (status.nebius.com), independently browser-read: a dedicated 'Token Factory' component shown Operational (no separate 'Inference'/'AI Studio' component); regions covered EU-NORTH1, EU-NORTH2, EU-WEST1, EU-WEST2, UK-SOUTH1, US-CENTRAL1, ME-WEST1; 'Uptime over the past 90 days' shown with no numeric % on the main view.
Documentationread2026-09-20
CORRECTED 2026-09-21: Nebius Token Factory live model catalogue, re-checked independently (tokenfactory.nebius.com/models/catalog): roughly 90 model variants.
Documentationread2026-09-20
Nebius dedicated-endpoint billing-policy docs (read directly): billed per running replica on a pay-as-you-go basis, adjusting dynamically with autoscaling; 'charges may vary depending on your custom contract or work order' - the underlying per-replica/GPU-hour rate itself is not disclosed on this page.
Documentationread2026-09-20
Nebius Token Factory product page (read directly): 'a simple, OpenAI-compatible API' over an open-weight model catalogue, with both shared/public per-token endpoints and dedicated single-tenant endpoints.