Please do not upload any confidential information. You may upload images, which we and our service providers will use for the sole purpose of providing you with this demo experience. Your use is logged for security purposes and anonymous session data may be used to improve NVIDIA products and services, including network performance metrics, AI-generated outputs, and audio transcriptions. The logged session data for improvement purposes is not linked to your identity or any persistent identifier. For more information about our data processing practices, see our Privacy Policy(opens in new tab). By uploading the file, you consent to our collection, recording, and use of such information and the NVIDIA API Trial Terms of Service(opens in new tab).
NVIDIA Nemotron 3.5 Content Safety is a compact 4B-parameter multimodal guardrail model from NVIDIA, fine-tuned from Google Gemma-3-4B. It moderates both inputs to and responses from LLMs and VLMs, accepting text and image input and returning text output: a safe/unsafe classification for the user prompt and the response, safety category labels, and an optional reasoning trace. It covers 12 languages with a context window of up to 128K tokens.
It is suited for prompt and response moderation, content classification, safety pipelines, and enterprise AI guardrails with policy enforcement, and includes a togglable reasoning mode. It is part of the NVIDIA Nemotron family of open models for agentic AI.
Modalities
In / Out Price
$0.20 / $0.20per 1M
Context
131K
Released
Jun 4, 2026
This model is hosted by one provider. OpenRouter forwards every request to it directly — no routing decisions to make.
The average price customers actually pay for this model, next to the prices providers post. Caching and discounts mean the price actually paid is often well below the listed one.
Throughput is how fast the model writes (tokens per second — higher is better). Latency is total round-trip time (lower is better). TTFT is time-to-first-token — how long before you see anything appear (lower is better).
Uptime is the percentage of the past 3 days that at least one provider was responding to requests. Availability is the percentage of time that inference was successfully served. OpenRouter continuously monitors and uses the next-best provider when one returns an error.
Public apps that send the most traffic to this model. Good signal for what real production workloads look like — and a hint at which use cases this model is best suited for.
Token volume and request traffic to this model over time.
Drop-in code to call this model. OpenRouter's API is OpenAI-compatible — most SDKs work by just swapping the base URL. The only thing that changes between models is the model slug below.
| $0.20 | $0.20 | 0.11s | 113 tps |
Throughput
113tok/s
P50, best across providers
Latency
0.11s
P50, best provider
97.32%
97.13%
When an error occurs in an upstream provider, we can recover by routing to another healthy provider, if your request filters allow it. You can access per-provider uptime data programmatically through the Endpoints API. Learn more about our load balancing and customization options.
NVIDIA Nemotron 3.5 Content Safety is a compact 4B-parameter multimodal guardrail model from NVIDIA, fine-tuned from Google Gemma-3-4B. It moderates both inputs to and responses from LLMs and VLMs, accepting text and image input and returning text output: a safe/unsafe classification for the user prompt and the response, safety category labels, and an optional reasoning trace.
Nemotron 3.5 Content Safety costs $0.20/M input tokens and $0.20/M output tokens.
Nemotron 3.5 Content Safety has a 131,072 token context window.
The Nemotron 3.5 Content Safety endpoint shown on this page does not accept tools, so function calling is unavailable there. It supports response_format for JSON output, without JSON-schema enforcement.
Nemotron 3.5 Content Safety accepts text and images as input and returns text.
Nemotron 3.5 Lightning, Nemotron 3 Ultra, Nemotron 3 Nano Omni (free) and 2 more are other text models from Nvidia.
Nemotron 3.5 Content Safety was released on June 4, 2026.