Nemotron 3.5 Content Safety is a content moderation model developed by NVIDIA, built by fine-tuning Google's Gemma-3-4B-it base model. It is best at multimodal content safety moderation, evaluating both text and optional image inputs for safety violations, and can optionally apply user-defined custom safety policies.
Input
Output
Context
131K
Max Output
8K
Parameters
4.3B
Input Modalities
Output Modalities
Loading capabilities…
Estimates based on INT8 quantization at up to 32K context. A count above one assumes tensor parallelism across the cards. Actual requirements vary by framework and configuration.
The creator's other models in the catalog, with their context, size and license where published.
Put this model beside its alternatives on the same evidence, or go back to the full catalog.
Answered from the entry's own fields: context, license, modalities, evidence, serving and the memory to self-host.
Nemotron 3.5 Content Safety advertises a context window of 131,072 tokens, with a maximum output of 8,192 tokens in a single response. The figure is the creator's published maximum; a given host may serve less, and the gateway routes on what each host actually serves.
Yes. Nemotron 3.5 Content Safety is an open-weight model released under the Other license, so the weights can be downloaded and self-hosted within that license's terms.
Nemotron 3.5 Content Safety accepts Text and Image and produces Text. The capabilities card on this page lists which API features each deployment honours, such as function calling and structured output, with the source each was checked against.
No published benchmark result for Nemotron 3.5 Content Safety is in the catalog yet, so the model is shown as unmeasured. It is not ranked or estimated; the router treats it as unknown for every task until a suite measures it.
Not on the managed pool today; Nemotron 3.5 Content Safety is listed for reference and comparison. Connect your own provider key or endpoint that serves it and the gateway runs it on your account, with routing decisions recorded the same way.
About 4.6 GB at INT8 for the weights and a default context, from the catalog's 4.3B parameter count; FP16 needs roughly twice that, and long contexts or many concurrent requests add KV cache on top. The GPU section on this page lists cards that hold it, and the capacity planner sizes it for your context length and traffic.
Fields collected from public registries, host APIs and benchmark publishers, each tagged with its source.
Last updated: Aug 28, 2026
One gateway in front of every model, with your policies applied and every decision on record. Start with $5 of credit and 5,000 routing decisions a month, no card required.