Nemotron 3.5 Content Safety
NVIDIA Nemotron 3.5 Content Safety is a compact 4B-parameter multimodal guardrail model from NVIDIA, fine-tuned from Google Gemma-3-4B. It moderates both inputs to and responses from LLMs and VLMs, accepting...
Updated 12 h ago · first seen 11 Sept 2026
model_01M294WVXCH17ZR022YTQHBCGC
Overview
Identity
Identity block not returned by the API for this entity.
Openness
Openness not classified yet — no sourced evidence to place this model in the ontology.
Key facts
- Release date
Source:OpenRouter public model & pricing listingT2observed 12 h agomedium
- Openrouter id
Source:OpenRouter public model & pricing listingT2observed 12 h agomedium
Architecture
- Hugging Face repo
Source:OpenRouter public model & pricing listingT2observed 12 h agomedium
Capabilities
Modalities
- Modalities
- imagetext
- Input
- imagetext
- Output
- text
Capabilities
Tool calling
No
OpenRouter public model & pricing listing · T2
Structured output
Yes
OpenRouter public model & pricing listing · T2
Reasoning
Yes
OpenRouter public model & pricing listing · T2
Vision
Yes
OpenRouter public model & pricing listing · T2
Audio
Unavailable
Fine-tuning available
Unavailable
- Context window
Source:OpenRouter public model & pricing listingT2observed 12 h agomedium
- Max output
Source:OpenRouter public model & pricing listingT2observed 12 h agomedium
Providers & Pricing2
All offers in the price terminal →USD per 1M tokens as published by each provider (USD). Rows are append-only: every change is kept in the history below.
Price history
Output price · USD / 1M tokens 1 provider
- NVIDIA NIM / build.nvidia.com
- NVIDIA NIM / build.nvidia.com$0.20 → $011 Sept 2026
- NVIDIA NIM / build.nvidia.comfirst observed $0.2011 Sept 2026
Input price · USD / 1M tokens 1 provider
- NVIDIA NIM / build.nvidia.com
- NVIDIA NIM / build.nvidia.com$0.20 → $011 Sept 2026
- NVIDIA NIM / build.nvidia.comfirst observed $0.2011 Sept 2026
Timeline3
Full timeline →New model: Nemotron 3.5 Content Safety (NVIDIA)
openrouterNVIDIA NIM / build.nvidia.com lists Nemotron 3.5 Content Safety at $0 in / $0 out per 1M tokens
openrouterNVIDIA NIM / build.nvidia.com lists Nemotron 3.5 Content Safety at $0.2 in / $0.2 out per 1M tokens
openrouter
Change history14
Viewing AI Atlas as of 12 Sept 2026 — attributes exactly as the atlas knew them on that day; later corrections are not shown.
Back to today →Attributes as of 12 Sept 2026 17 claims in force
- Release date
- 4 Jun 2026
- Openness
- open-weights
- Context window
- 131.1K tokens
- Max output
- 118K tokens
- Modalities
- image, text
- Input modalities
- image, text
- Output modalities
- text
- Hugging Face repo
- nvidia/Nemotron-3.5-Content-Safety
- Openrouter id
- nvidia/nemotron-3.5-content-safety
- Openrouter listed at
- 4 Jun 2026
- Reasoning
- Yes
- Structured output
- Yes
- Supported parameters
- frequency_penalty, include_reasoning, logit_bias, max_tokens, min_p, presence_penalty, reasoning, repetition_penalty, response_format, seed, stop, temperature, top_k, top_p
- Tool calling
- No
- Vision
- Yes
- Weights available
- Yes
Release daterelease_date1
Context windowcontext_length1
Max outputmax_output_tokens1
Modalitiesmodalities1
Input modalitiesmodalities_input1
Output modalitiesmodalities_output1
Hugging Face repohf_repo1
Descriptiondescription1
Openrouter idopenrouter_id1
Reasoningreasoning1
Structured outputstructured_output1
Supported parameterssupported_parameters1
Tool callingtool_calling1
Visionvision1
Claims are temporal and append-only: a new observation closes the previous claim (valid_to) instead of overwriting it. Conflicting claims from different sources are kept side by side and flagged — never averaged. Methodology →
Provenance
Attributed facts
14
Source tiers
T214
Freshest observation
12 h ago
Conflicts
None
Source documents 1
Tier 1 = official/primary, 2 = quality secondary, 3 = community, 4 = unverified. Every snapshot is archived; see all sources and the methodology.
Data quality (50/100) measures how well AI Atlas knows this entity — completeness, primary-source ratio, freshness, conflicts — never how good the model is. Methodology →