{
  "id": "nebius",
  "name": "Nebius (Nebius AI Cloud: GPU Compute, Managed Kubernetes and Soperator, Storage, Virtual Networks + Token Factory Inference and Fine-Tuning + the Applications Marketplace)",
  "subtitle": "Mapped to the 4+1 Layer AI Infrastructure Model",
  "version": "v1.0 - 4+1 v2: Authority Split",
  "date": "September 10, 2026",
  "source": "Nebius AI Cloud documentation at docs.nebius.com (overview, services, regions, quotas; Compute: index, GPU clusters, topology, virtual machines, storage types, pricing, quotas; Managed Service for Kubernetes: index, components, GPU set-up, topology-aware scheduling, storage over CSI, networking and security groups; Slurm and Soperator: index, overview, ephemeral nodes and capacity moves; Object Storage: overview, quickstart, pricing, storage classes, bucket policies, data transfers (overview, launch); Managed Service for PostgreSQL and the RAG tutorial; HIPAA Implementation Guideline; Nebius Echo; Container Registry; IAM: overview, authorization, access tokens, access keys, static keys, federated credentials, roles, federations and SAML SSO; KMS; Audit Logs; Virtual Networks: overview, security groups; security and encryption; Applications: index, types, deploy, standalone quotas and pricing, the NVIDIA Blueprint for virtual screening and its licenses page; MLflow; PostgreSQL; Serverless AI; llms.txt); Nebius Token Factory documentation at docs.tokenfactory.nebius.com (API reference for inference, embeddings, rerank, images, responses, files, datasets, fine-tuning, dedicated endpoints; dedicated endpoints overview, capacity and scaling, control and data plane, lifecycle, billing, custom weights, FAQ; function calling, JSON, rate limits, observability, playground, Data Lab; post-training overview and fine-tuning guide; sandboxes overview; deprecation notices of March (effective April 13), June 22, and August 31, 2026; legal quick guide, HIPAA guideline, sub-processors, terms, privacy; llms.txt); nebius.com pages (AI Cloud, Token Factory, prices, services, newsroom through September 8, 2026, the Meta agreement of March 16, 2026, the Agents Blueprint post of June 10, 2026, the Groq 3 LPX post of August 24, 2026); GitHub license API for nebius/soperator. Peer-reviewed cell by cell through the labs claims ledger (nebius-<layer>-chatgpt, ChatGPT gpt-5.5) and as a whole row by Antigravity (nebius-row-agy); totals and escalated items in reviews/nebius-judgment.md.",
  "status": "complete",
  "summary": {
    "title": "Summary Finding",
    "paragraphs": [
      "Nebius is the European NVIDIA cloud with a model service on top. The map reads it strong at three layers, moderate at three, and gap at two. Layer 0 is strong on GPU virtual machines and InfiniBand GPU clusters from H100 to B300 in six public regions across Finland, France, Israel, the UK, and the US (three private regions serve existing customers), with partition-key isolation and topology labels, virtual networks, and security groups; the capacity is Nebius's own and, by contract, partners' too. Layer 2A is strong on Managed Kubernetes with NVIDIA's operators and topology-aware scheduling, Managed Soperator (its open-source Slurm-on-Kubernetes operator) with ephemeral nodes that move capacity between training and inference, Serverless AI, and quotas, the CoreWeave scheduler pair. Layer 2B is strong on Token Factory: open models behind OpenAI-compatible chat, responses, vision, embeddings, and rerank endpoints, serverless per token or on dedicated endpoints with replica bounds, full or Low-Rank Adaptation (LoRA) fine-tuning and custom speculator training with Data Lab and export to Hugging Face format, and open-source agent tooling as managed applications; custom weights and Sandboxes are beta. Layer 1A is moderate on S3-compatible object storage with bucket policies by key and prefix, virtiofs filesystems, and a tenant-project identity model with Security Assertion Markup Language (SAML) single sign-on and OpenID Connect (OIDC) workload credentials, with audit logs in preview and no catalog. Layer 1B is moderate on embedding and rerank endpoints, Qdrant as a managed app, and Managed PostgreSQL with pgvector. Layer 1C is moderate on Object Storage data transfers (a managed sync between buckets, third-party S3 stores, and Azure Blob) and Data Lab's captive dataset workbench. Layer 3 is a gap under the marketplace ruling: a marketplace of other people's applications, one NVIDIA blueprint under its own license, and Nebius Echo, a console assistant with approval-gated actions, none of them a business application. Layer 2C is a gap: identity for people and workloads, nothing generally available over agents.",
      "The capture is at Nebius's control planes and nowhere at the interfaces. Kubernetes, Slurm, S3, virtiofs, SAML, OIDC, PostgreSQL, and the OpenAI-compatible endpoints are standards; Soperator, Qdrant, Flowise, Open WebUI, JupyterLab, and ComfyUI are open source with export pages, and the same apps self-run on a VM or the enterprise's cluster are the enterprise's own; the models are their owners' open weights and fine-tunes export as the enterprise's artifact; that's why ten of the nineteen components read Delegated or Retained. What is Nebius's and stays Nebius's: the instances, fabrics, networks, and disks; the account model, keys, and audit; the data-transfer engine; node-group provisioning, capacity blocks, Serverless AI, quotas, and the marketplace deployer; dedicated endpoints and the fine-tuning service with Data Lab; Echo. NVIDIA is everywhere underneath (every GPU, the operators, the interconnect, the one blueprint under its own license) and is the dependency the row carries at Layer 0, 2A, and 2B.",
      "The buyer's trade: NVIDIA capacity by the second in Europe, with Kubernetes and Slurm it already knows, open models it can call, tune, and take away, a managed sync between object stores, and a shelf of open-source apps, in exchange for a rented substrate Nebius sometimes rents itself, a model service whose catalogue is visible only by API and whose burst isn't guaranteed, a modality retired in April, and an identity and audit layer still partly in preview. The decision-authority readings follow: vendor / Ceded at Layer 0 (a fabric and a platform are a menu), vendor / Delegated at 1A and 1B on per-object controls, vendor / Ceded at 1C (transfer flags are configuration), vendor / Delegated at 2A on two documented pins (topology labels the enterprise's scheduler places on, Slurm nodes released and repowered by name), model / Delegated at 2B (the loop is the enterprise's), Absent at 2C and Layer 3. What would move cells: a first-party business application (Layer 3), Sandboxes leaving beta with a gateway or registry (2C), custom weights leaving beta (a 2B chip), audit logs leaving preview (1A), a catalog or policy surface over data (1A)."
    ]
  },
  "layers": [
    {
      "id": "layer0",
      "label": "Layer 0",
      "shortName": "Compute",
      "title": "Compute & Network Fabric",
      "purpose": "Raw compute, networking, and acceleration fabric",
      "status": "strong",
      "statusLabel": "An NVIDIA GPU Cloud You Rent by the Second: H100 to B300 Virtual Machines and InfiniBand GPU Clusters With Partition-Key Isolation and Topology Labels in Six Public Regions Across Finland, France, Israel, the UK, and the US; Virtual Networks and Security Groups; No Silicon of Its Own",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "Every Accelerator Is NVIDIA's and the Fabric Is InfiniBand",
          "detail": "GPU platforms are NVIDIA H100, H200, B200, B300, L40S, and RTX PRO 6000; GPU clusters live in named InfiniBand fabrics, one platform per fabric, isolated with partition keys; Managed Kubernetes requires the NVIDIA GPU Operator and, for B200 or InfiniBand, the NVIDIA Network Operator, with GPUDirect RDMA on by default. Nebius says it's 'the first AI cloud to adopt NVIDIA Groq 3 LPX' for Vera Rubin NVL72 in Token Factory (blog, August 24, 2026; no product documentation). The whole substrate is NVIDIA's design on Nebius's floor."
        }
      ],
      "gap": "Nebius sells the GPU cloud itself. Virtual machines with one to eight NVIDIA GPUs (H100, H200, B200, B300, L40S, RTX PRO 6000; regular or preemptible; billed per second, priced per hour) group into GPU clusters on InfiniBand fabrics ('Each GPU cluster is created in one of the physical InfiniBand fabrics'; 3.2 Tbps per eight-GPU node; 'isolates InfiniBand traffic between GPU clusters by using InfiniBand partition keys'), with topology exposed as node labels so the enterprise's scheduler can place jobs close; Virtual Networks (IPv4 only) with subnets, pools, routing tables, and stateful or stateless security groups with priority-ordered rules; network SSD, non-replicated, IO-M3, and local disks; six public regions (eu-north1 Finland, eu-west1 France, me-west1 Israel, us-central1 Kansas City, uk-south1 and uk-south2) plus three private ones (eu-north2 Iceland, eu-west2 France, us-north1 Minnesota) open only to customers already deployed there (named, not scored), with GPU platforms varying by region (B300 NVLink in the UK, France, and Minnesota; H200 NVLink in Finland, France, Kansas City, and Iceland). Capacity comes from Nebius's own data centers and, per its sub-processor list, from third-party GPU clouds (the Token Factory sub-processor list effective August 28, 2026 names RunPod in Iceland, Shadeform, BoostRun, Argentum AI, Data Section in Canada, and Eigen AI, acquired June 16, 2026); a July 15, 2026 'business model to scale AI cloud globally through infrastructure partnerships' formalizes that, funded by a $5.75 billion convertible offering (August 2026), a $775 million secured facility (July 2026), and a five-year supply agreement with Meta announced March 16, 2026: $12 billion of dedicated capacity on one of the first large-scale Vera Rubin deployments, plus up to $15 billion of additional capacity Meta committed to buy across upcoming clusters. The buyer gets NVIDIA capacity by the second, in Europe first.\n\nThe architect's concern is that the substrate is rented from a company that also rents it. The fabric is preselected ('In most cases, you do not need to change the preselected fabric'), topology tiers are 'not guaranteed to match these examples', some capacity sits with sub-processors the contract names, and Nebius owns no silicon; the accelerators, operators, and interconnect are NVIDIA's.\n\nCalibration: CoreWeave reads strong on GPU compute the enterprise rents by the instance plus a fabric; NVIDIA strong on silicon; Cerebras strong on its own wafers; Cloudflare moderate on CPU compute you can size. Nebius is CoreWeave's shape in Europe. Strong.",
      "borrowedJudgment": "Ceded at the instance, on rented standards. The virtual machines, GPU clusters, fabrics, networks, and disks are Nebius's implementation of NVIDIA's reference design; instance types and fabrics are Nebius's catalogue: Ceded, the CoreWeave reading; the InfiniBand and NVMe interfaces are standards, but the enterprise can't take a fabric with it. The runtime call at this layer is Nebius placing a VM on a host in the fabric the enterprise chose (or the preselected one) and preempting preemptible VMs; the enterprise picks region, platform, fabric, and count, a menu, and reverses nothing below it: vendor decides, visible (topology labels, quotas), not overridable, Ceded, the CoreWeave reading.",
      "notes": "Named, not scored: the Meta supply agreement (March 16, 2026; $12 billion dedicated plus up to $15 billion additional over five years), the NVIDIA Groq 3 LPX (the inference accelerator NVIDIA licensed from Groq) adoption for Vera Rubin NVL72 (blog, August 24, 2026; no product documentation and no GA date, so not watch-listed), the third-party capacity sub-processors (contractual, not a customer surface), the private regions (existing customers only). Public evidence that moves the cell: nothing upward from strong; a bare-metal tier would change the authority reading.",
      "components": [
        {
          "component": "GPU Virtual Machines and GPU Clusters (NVIDIA H100, H200, B200, B300, L40S, RTX PRO 6000; Regular and Preemptible; InfiniBand Fabrics With Partition-Key Isolation and Topology Labels; Six Public Regions)",
          "detail": "Instances and clusters the enterprise rents on Nebius's implementation of NVIDIA's design; three private regions serve existing customers and are named, not scored. Ceded, the CoreWeave GPU compute reading.",
          "dapm": "Ceded"
        },
        {
          "component": "Virtual Networks and Security Groups (IPv4 Subnets, Pools, Routing Tables; Stateful or Stateless Priority-Ordered Rules; System Security Groups on Kubernetes Nodes)",
          "detail": "Nebius's network primitives in Nebius's regions. Ceded, the CoreWeave network fabric reading.",
          "dapm": "Ceded"
        },
        {
          "component": "Compute Storage (Network SSD, Non-Replicated, IO-M3, Local SSD; Snapshots; Custom and Imported Images; AES-256 by Default on Network SSD)",
          "detail": "Block devices attached to Nebius VMs in Nebius's formats. Ceded; the object and file stores are the Layer 1A chips.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer1a",
      "label": "Layer 1A",
      "shortName": "Storage",
      "title": "Data Storage & Governance",
      "purpose": "Durable, governed data foundation — the Governance Catalog that Layer 2C queries",
      "status": "moderate",
      "statusLabel": "S3-Compatible Object Storage With Bucket Policies by Key and Prefix, Shared Filesystems Over virtiofs, and a Tenant-Project Identity Model With SAML Single Sign-On, OIDC Workload Credentials, KMS-Backed Encryption, a HIPAA Guideline, and Audit Logs in Preview; No Catalog, No Classification, No Lineage",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Dependency at This Layer",
          "detail": "Object storage, filesystems, identity, and keys run on Nebius's CPUs and storage."
        }
      ],
      "gap": "Nebius's data foundation is a cloud's: buckets, filesystems, identities, and keys. Object Storage 'is compatible with Amazon S3' in every region; Enhanced Throughput is offered everywhere, while the Standard and Intelligent classes skip uk-south1, uk-south2, and the private eu-west2 and us-north1; requests bill per thousand and egress per gibibyte; bucket policies grant an Identity and Access Management (IAM) group access to a full object key or a prefix with a wildcard. A shared filesystem mounts to many VMs in one project 'as a virtiofs device', can expose buckets through it, and is 'encrypted by default; you cannot disable it' (the create command also offers WEKA and VAST filesystem types, partners' engines behind a Nebius menu); Container Registry holds images and Helm charts. Identity is a tenant of projects with default groups (viewers, editors, admins; the auditor role deprecating), custom groups with access permits, service accounts with three credential kinds (access keys for the S3-compatible services, which 'can be issued without an expiration date'; static keys for Container Registry and Observability with optional expiration; access tokens for Nebius interfaces valid twelve hours), console single sign-on over Security Assertion Markup Language (SAML) only with guides for Entra ID, Okta, JumpCloud, and Keycloak, and OpenID Connect (OIDC) federated credentials for workloads impersonating an IAM subject; Key Management Service (KMS) holds symmetric and asymmetric keys behind service-level data keys and infrastructure key-encryption keys; Audit Logs ('The service is in preview') record who did what, dropping events past a thousand per second. A Health Insurance Portability and Accountability Act (HIPAA) Implementation Guideline names Object Storage 'the only service authorized for storing electronic protected health information (ePHI) at rest', lets Compute and Managed Kubernetes process it transiently, and requires an executed business associate agreement (BAA). Token Factory's Data Lab keeps inference logs and datasets in Finland with an organization-level zero-data-retention switch, and the legal guide states 'We do not use your content to train, fine-tune or improve any AI models'. The buyer gets standard cloud storage and identity under a European operator, with a HIPAA line drawn around the bucket.\n\nThe architect's concern is that it's storage, not governance: no catalog, classification, or lineage; policy stops at keys and prefixes; audit logs are in preview; and a filesystem can't cross projects.\n\nCalibration: CoreWeave reads moderate on open default storage plus a captive governance tier; Cloudflare moderate on an S3-compatible store plus edge databases; Hugging Face moderate on an artifact registry; Databricks and Snowflake strong on lakehouses with governance. Nebius is CoreWeave's shape. Moderate.",
      "borrowedJudgment": "Delegated at the object door, Ceded at the account. Buckets and objects behind S3 lift to any S3 store, and a virtiofs filesystem's contents copy out: Delegated, the CoreWeave CAIOS and Cloudflare R2 reading. The tenant and project model, groups, access permits, service accounts, KMS, and audit logs are Nebius's: Ceded, the CoreWeave dedicated-tier reading; SAML and OIDC are standard doors onto it. The runtime call is Nebius enforcing the bucket policies, permits, storage classes, and encryption the enterprise set per bucket, key, prefix, filesystem, and project, with override per object: vendor decides, visible, overridable, Delegated, the CoreWeave and Cloudflare 1A reading.",
      "notes": "Unscored on its badge: Audit Logs ('in preview'), Monitoring and Logging ('in preview'). Named, not scored: the WEKA and VAST filesystem types (partners' engines on Nebius's paper; the owners' rows score the engines). The HIPAA guideline is a scope statement, not a governance surface. Public evidence that moves the cell: a catalog or policy surface over the data; audit logs leaving preview would firm up the governance tier.",
      "components": [
        {
          "component": "Object Storage (Amazon S3 Compatible; Standard, Enhanced Throughput, and Intelligent Classes With Regional Exceptions; Bucket Policies by Object Key and Prefix)",
          "detail": "Buckets and objects behind a multi-vendor interface. Delegated, the CoreWeave CAIOS and Cloudflare R2 reading.",
          "dapm": "Delegated"
        },
        {
          "component": "Shared Filesystems (virtiofs Mounts to Many VMs in a Project; Bucket Attachment; Encrypted by Default) + Container Registry",
          "detail": "File and image contents that copy out through standard tools, on Nebius's mounts. Delegated, the CoreWeave file storage reading; the WEKA and VAST types are named, not scored.",
          "dapm": "Delegated"
        },
        {
          "component": "Identity, Keys, and Audit (Tenants and Projects; Groups and Access Permits; Service Accounts With Access Keys, Static Keys, and Access Tokens; SAML SSO for Entra ID, Okta, JumpCloud, Keycloak; OIDC Federated Credentials for Workloads; KMS With Data and Key-Encryption Keys; Audit Logs in Preview)",
          "detail": "Nebius's account model over Nebius's resources; SAML and OIDC are standard doors onto it. Ceded, the CoreWeave dedicated-tier reading; audit logs are named, not scored.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer1b",
      "label": "Layer 1B",
      "shortName": "Retrieval",
      "title": "Context Management & Retrieval",
      "purpose": "Low-latency retrieval for RAG — vector/hybrid search, context windows",
      "status": "moderate",
      "statusLabel": "Embedding and Rerank Endpoints on Open Models in Token Factory, Qdrant as a Managed Application, and Managed PostgreSQL With pgvector; No Retrieval Engine of Nebius's Own",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "Embeddings Run on Nebius's NVIDIA GPUs",
          "detail": "Token Factory's embedding and rerank models run on the same NVIDIA fleet as everything else; the models are open weights."
        }
      ],
      "gap": "Nebius gives the retrieval layer its parts. Token Factory serves an OpenAI-compatible /v1/embeddings endpoint (the example model is BAAI/bge-en-icl) and a /v1/rerank endpoint ('Reranks documents based on their relevance to a query') per token on the serverless tier; the Applications marketplace deploys Qdrant, the open-source vector database, as a standalone managed application ('Managed infrastructure with zero setup time') in eu-north1 and us-central1 with an export-data page, and points the customer at Qdrant's own API for the rest (hybrid and full-text search included); Managed Service for PostgreSQL ships 'the pg_vector extension' to 'store and index vector embeddings required for retrieval-augmented generation (RAG)-based systems', and the RAG tutorial builds on it; Data Lab runs SQL over inference logs into datasets, which is data preparation rather than retrieval. The buyer gets open embedders, a reranker, a hosted vector store, and a vector-capable Postgres from one account.\n\nThe architect's concern is that there's no engine of Nebius's own: the embedders are open weights, the stores are Qdrant's and PostgreSQL's, and nothing Nebius wrote does retrieval over the enterprise's data as a service.\n\nCalibration: Cloudflare reads moderate on a managed index plus open embedding and rerank models; Mistral moderate on an embeddings API and libraries; Hugging Face moderate on open embedders and an engine; Cohere moderate on frontier embed and rerank; Elastic and MongoDB strong on native engines. Nebius is Cloudflare's shape with partners' indexes. Moderate.",
      "borrowedJudgment": "Delegated on open parts. The embedding and rerank endpoints serve open weights the enterprise could run itself, behind OpenAI-shaped doors: Delegated on the open-weights embeddings ruling (the Cloudflare and Hugging Face reading), not the carve-out, because the weights aren't Nebius's. Qdrant as a managed application is Apache 2.0 software Nebius operates, with an export path, and Managed PostgreSQL with pgvector is standard Postgres whose schema and queries lift to any Postgres: Delegated, the Nutanix managed-Postgres and CoreWeave reading. The runtime call is an endpoint embedding or ranking what the enterprise sent, with per-request model choice: vendor decides, visible, overridable, Delegated, the Elastic reading.",
      "notes": "The Token Factory model catalogue is enumerated only through the API (GET /v1/models); which embedding and rerank models are live isn't in a static page in the source set. Public evidence that moves the cell: a Nebius-operated retrieval or hybrid-search engine of its own; nothing describes one.",
      "components": [
        {
          "component": "Token Factory Embedding and Rerank Endpoints (OpenAI-Compatible /v1/embeddings and /v1/rerank on Open Models; Serverless, per Token)",
          "detail": "Open weights behind standard doors on Nebius's GPUs. Delegated on the open-weights embeddings ruling.",
          "dapm": "Delegated"
        },
        {
          "component": "Qdrant as a Managed Standalone Application (Applications Marketplace; eu-north1 and us-central1; Qdrant's Own API Including Hybrid Search; Export-Data Page)",
          "detail": "An open-source vector database Nebius operates for the enterprise, with a documented export. Delegated, the managed open-engine reading.",
          "dapm": "Delegated"
        },
        {
          "component": "Managed Service for PostgreSQL With pgvector (Vector Storage and Search for RAG; the Documented RAG Tutorial Path)",
          "detail": "Standard PostgreSQL with an open extension, operated by Nebius; schema and queries lift to any Postgres. Delegated, the Nutanix managed-Postgres reading.",
          "dapm": "Delegated"
        }
      ]
    },
    {
      "id": "layer1c",
      "label": "Layer 1C",
      "shortName": "Pipelines",
      "title": "Data Movement & Pipelines",
      "purpose": "Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering",
      "status": "moderate",
      "statusLabel": "Object Storage Data Transfers: Continuous or One-Shot Movement Between Buckets, Third-Party S3 Stores, and Azure Blob With Overwrite and Delete Semantics; Data Lab Prepares Fine-Tuning Datasets by SQL Over Inference Logs and S3 Sources; No ETL, Lineage, or Cache Tiering",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Dependency at This Layer",
          "detail": "Data transfers and Data Lab run on Nebius's CPUs and storage."
        }
      ],
      "gap": "Nebius moves objects and shapes training data. Data transfers 'allow you to move data between buckets' for replication, backup, 'or when you want to migrate from a different region or third-party storage service', with 'both Object Storage in Nebius AI Cloud and S3-compatible third-party services as sources and destinations' (Azure Blob containers too; an external destination only from a Nebius source), run as consecutive iterations that list, compare, and copy (multipart above 100 MB), with documented overwrite and delete rules for destination objects, key prefixes, stop conditions (one iteration, a run of empty ones, or indefinitely), and management from the console, CLI, or Terraform; a transfer can land in a shared filesystem through a filesystem bucket. Data Lab in Token Factory is 'a unified workspace ... for working with inference logs (chat completions) and datasets': auto-collected chat completions (unless zero data retention is on), SQL-filtered datasets, uploads in JSON Lines (JSONL), S3 connections for JSONL and Parquet 'without creating an additional raw-data copy', batch and fine-tuning outputs, all processed 'exclusively in the EU-North1 (Finland) data center'. Soperator's ephemeral nodes move compute, not data (scored at 2A). The buyer gets a managed sync between object stores and a dataset workbench for fine-tuning.\n\nThe architect's concern is that it's movement without a pipeline: no transformation, no change data capture, no lineage, no cost-aware orchestration beyond same-region egress being free, no KV-cache tiering; Data Lab prepares data for Nebius's own trainer and nothing else.\n\nCalibration: Cloudflare reads moderate with Super Slurper and Sippy (bulk and on-read migration into R2) as scored chips beside Queues and Workflows; CoreWeave gap on LOTA, a transport accelerator with no movement product to buy (its cell reads data movement as a throughput property, not a pipeline); Nutanix gap on snapshot replication; Mistral and Cerebras gap; Hugging Face moderate on a hosted runner plus libraries. Nebius has a movement product the enterprise configures and holds Nebius to, and a captive-destination workbench, each a fixed-function slice under rule 4 (Data Lab on the September 11, 2026 ruling that trainer-input preparation reads on the NetApp AIDE line). Moderate (ruled September 15, 2026): a managed, configurable, continuous object sync between clouds is the purpose line's cost-aware movement as a fixed-function slice under rule 4; the CoreWeave gap is a transport accelerator with nothing to configure and the Nutanix gap is disaster recovery, so neither is the same shape.",
      "borrowedJudgment": "Ceded at the transfer, with the data on standard doors. The transfer resource, its iteration engine, and its overwrite and delete semantics are Nebius's, though both ends are S3 and the enterprise could substitute its own sync tooling: Ceded, the Cloudflare Super Slurper reading. Data Lab is a captive workbench for Token Factory's fine-tuning, on Nebius's SQL engine in Finland: Ceded, the AIDE reading. The runtime call is Nebius's transfer service deciding, each iteration, which objects to copy, overwrite, or delete inside the flags and prefixes the enterprise set; those are configuration, not per-object overrides: vendor decides, visible (iteration status), not overridable, Ceded.",
      "notes": "Ruled September 15, 2026: moderate stands on rule 4 and the Cloudflare migration-chip reading; gap had been argued on the CoreWeave movement-not-pipeline line. Data Lab settled September 11, 2026: a captive-destination preparation surface is a fixed-function slice (the Cerebras and NetApp AIDE line) and is scored as a Ceded chip. Named, not scored: the Batch API (referenced in rate limits and the Files API; no standalone page in the Token Factory index as of September 10, 2026). Public evidence that moves the cell: a transformation, connector, or lineage product.",
      "components": [
        {
          "component": "Object Storage Data Transfers (Bucket to Bucket; S3-Compatible Third-Party Stores and Azure Blob as Sources; Iterations With Overwrite, Delete, Prefix, and Stop-Condition Rules; Console, CLI, Terraform; Filesystem Buckets as Destinations)",
          "detail": "Nebius's managed sync engine over standard object stores. Ceded, the Cloudflare Super Slurper and Sippy reading; the objects themselves stay behind S3.",
          "dapm": "Ceded"
        },
        {
          "component": "Data Lab (Token Factory; SQL Over Auto-Collected Inference Logs, JSONL Uploads, and S3 JSONL and Parquet Sources Into Fine-Tuning Datasets; Batch and Fine-Tuning Outputs; Processed in Finland; Token Factory Training as the Only Destination)",
          "detail": "Nebius's workbench on Nebius's engine for Nebius's trainer, with the datasets exportable. Ceded, the NetApp AIDE captive-pipeline reading.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2a",
      "label": "Layer 2A",
      "shortName": "Orchestration",
      "title": "Infrastructure Orchestration",
      "purpose": "GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization",
      "status": "strong",
      "statusLabel": "Managed Kubernetes With GPU Node Groups, Operators, a Cluster Autoscaler, and Topology-Aware Scheduling; Managed Soperator (Open-Source Slurm on Kubernetes) With Ephemeral Nodes That Move Capacity Between Training and Inference; Serverless AI Jobs and Endpoints; Quotas, Preemptible Capacity, and Commitments",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "The Operators Are NVIDIA's",
          "detail": "GPU node groups without Nebius's boot image 'must have NVIDIA GPU Operator installed'; B200 and InfiniBand node groups require the NVIDIA Network Operator; GPUDirect RDMA is on by default. The schedulers (Kubernetes, Slurm, Kueue, Volcano) are open."
        }
      ],
      "gap": "Nebius orchestrates GPUs three ways and lets the enterprise move them. Managed Service for Kubernetes (free control plane, nodes billed as VMs) runs GPU node groups on a platform and preset ('You cannot change the VM platform and preset or the GPU cluster of an existing node group'), installs the NVIDIA operators or ships its own boot image, scales with 'the cluster autoscaler [that] seamlessly adds nodes when there are unschedulable Pods', exposes InfiniBand topology as tier labels for Kueue or Volcano, and attaches security groups per node group. Managed Service for Soperator runs Slurm as Kubernetes pods ('an open-source solution from Nebius', github.com/nebius/soperator, Apache 2.0) with a shared root filesystem, and, from version 3.0 with Nebius enabling it, ephemeral nodes the enterprise powers down with scontrol to 'reuse the same capacity block group for other workloads, such as inference'. Serverless AI provisions VMs for jobs and endpoints since July 28, 2026; Token Factory dedicated endpoints scale between minimum and maximum replicas of a chosen GPU type in a chosen region ('Minimum replicas are reserved and non-preemptible ... Maximum replicas scaling depends on available burst capacity and is not guaranteed'); quotas bound each region and platform, preemptible VMs are cheaper, and commitment discounts are 'only available if you have signed up ... as a company'. The Applications marketplace deploys onto Kubernetes or as standalone managed apps. The buyer gets Kubernetes and Slurm on NVIDIA fabrics with the levers to move capacity between training and inference.\n\nThe architect's concern is where the plane stops: topology tiers whose 'exact physical meaning ... is not guaranteed', a preselected fabric, node groups that can't change platform, dedicated-endpoint burst that isn't reserved, and an ephemeral-node feature Nebius must switch on.\n\nCalibration: CoreWeave reads strong on CKS plus SUNK (Slurm on Kubernetes) plus Mission Control; Nutanix strong on Prism, ADS, and a Kubernetes platform; NetApp, VAST, and Everpure moderate on data-infrastructure control planes; Mistral and Cerebras gap on metering edges. Nebius is CoreWeave's shape on the schedulers (Kubernetes plus Slurm on Kubernetes) without a Mission Control: no documented fleet-health, straggler, or node-lifecycle plane across both, and Soperator 'has not been tested on platforms other than Nebius AI Cloud'. Strong (ruled September 15, 2026): the strong 2A cohort reads on managed Kubernetes and its scheduling (AWS on EKS plus capacity management, GCP on GKE, Azure on AKS plus Arc, Nutanix on Prism, ADS, and NKP) and none of it requires a fleet-operations plane; CoreWeave's Mission Control is the exception, not the criterion.",
      "borrowedJudgment": "Delegated at the schedulers and two documented pins, Ceded at the control plane. Kubernetes and Slurm are open interfaces the enterprise's workloads already speak, Soperator is Apache 2.0, and the topology labels feed the enterprise's own Kueue or Volcano: Delegated, the CoreWeave CKS and SUNK reading; node-group provisioning (platform, preset, fabric, boot image), the capacity-block machinery behind ephemeral nodes, Serverless AI, the autoscaler's bounds, quotas, and the marketplace deployer are Nebius's: Ceded. The runtime call is placement. A fabric per cluster and a platform and preset per node group are menus, and autoscaler minimums, maximums, and quotas are bounds, so none of them is an override under the standing rulings; two controls are: the topology labels the enterprise's own scheduler places pods on (the WEKA node-selector reading), and scontrol power down and up on named Slurm nodes the enterprise chooses to release and repower (a per-node pin). Nebius picks the host inside the fabric and the burst it can honor: vendor decides the defaults, visible (topology labels, quotas, statuses), overridable on those two documented controls, Delegated, the Dataiku and WEKA pin reading. Cross-row: CoreWeave's 2A reads Ceded on the same controls, scored before the override rule.",
      "notes": "Ruled September 15, 2026: strong stands on the cohort calibration (managed Kubernetes plus Slurm on Kubernetes plus capacity moves exceeds the AWS and GCP basis for strong); moderate had been argued on the missing fleet-operations plane and Soperator being untested off Nebius. Cross-row: CoreWeave 2A (Ceded, September 2) against this row's Delegated on the two documented pins; the override-rule column item. Soperator ephemeral nodes require version 3.0, Nebius enabling the feature, and a shared capacity block group on one GPU platform; moving capacity means resizing a Managed Kubernetes node group on the same block. Serverless AI is documented by an overview and pricing page only. Public evidence that moves the cell: nothing upward from strong; a fleet-operations plane would settle the escalation.",
      "components": [
        {
          "component": "Managed Service for Kubernetes (Standard Kubernetes API; NVIDIA GPU and Network Operators; Cluster Autoscaler; Topology-Aware Scheduling Labels for Kueue and Volcano; Container Storage Interface (CSI) Disks and Shared Filesystems)",
          "detail": "Standard Kubernetes with NVIDIA's operators on Nebius's nodes; workloads and manifests lift to any cluster. Delegated, the CoreWeave CKS and Nutanix NKP reading; node-group provisioning is the control-plane chip.",
          "dapm": "Delegated"
        },
        {
          "component": "Managed Service for Soperator (Open-Source Slurm on Kubernetes, Apache 2.0; Shared Root Filesystem; scontrol Power Down and Up on Named Worker Nodes)",
          "detail": "An open operator Nebius manages; Slurm jobs and the operator itself lift to any Kubernetes, untested elsewhere by Nebius's own note. Delegated, the CoreWeave SUNK reading; the capacity-block machinery is the control-plane chip.",
          "dapm": "Delegated"
        },
        {
          "component": "Nebius Control Plane (Node-Group Provisioning by Platform, Preset, GPU Cluster, and Boot Image; Security Groups per Node Group; Capacity Block Groups and Ephemeral-Node Enablement; Serverless AI Jobs and Endpoints; Quotas per Region and Platform; Preemptible Capacity; Commitment Discounts; Dedicated-Endpoint Replica Scaling and Burst; Applications Marketplace Deployer)",
          "detail": "Nebius's provisioning, placement, scaling, and bounds over Nebius's capacity. Ceded, the CoreWeave Mission Control reading.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2b",
      "label": "Layer 2B",
      "shortName": "Runtime",
      "title": "Application Runtime & Execution",
      "purpose": "Model serving, agent execution, inference APIs, distributed inference",
      "status": "strong",
      "statusLabel": "Token Factory: Open Models Behind OpenAI-Compatible Chat, Responses, Embeddings, Vision, and Rerank Endpoints, Serverless per Token or on Dedicated Endpoints With Replica Bounds, Plus Full or LoRA Fine-Tuning and Custom Speculator Training With Data Lab; Custom Weights and Sandboxes in Beta; Agents Through Managed Open-Source Applications",
      "authority": {
        "decides": "model",
        "visible": true,
        "overridable": true,
        "boundary": "model",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "NVIDIA GPUs Under Every Endpoint, and Groq 3 LPX Announced",
          "detail": "Dedicated endpoints are provisioned by NVIDIA GPU type (L40S, H100, H200, B200, B300); serverless runs on the same fleet; Nebius calls itself 'the first AI cloud to adopt NVIDIA Groq 3 LPX' for Vera Rubin NVL72 in Token Factory (undated). Clarifai's core team joined and Nebius 'licenses inference IP' from it (undated)."
        }
      ],
      "gap": "Nebius's runtime is a European-hosted open-model service with the training side attached. Token Factory 'offers an OpenAI-compatible API for inference and fine-tuning': chat completions (streaming), a Responses API (no badge), completions, embeddings, vision through image_url, and rerank (text-to-image models and Low-Rank Adaptation (LoRA) per-token endpoints were retired on April 13, 2026, 'as we streamline supported modalities'); function calling with 'Connect to Model Context Protocol (MCP) servers' among its named uses; JSON schema and JSON object modes where a model carries the JSON mode tag; two flavors per model (base and fast, 'identical model outputs' at different price and latency); a catalogue of third-party open weights enumerated through GET /v1/models (Llama, Qwen, DeepSeek, and 'Kimi K3 is now available', 'Qwen3.8-Max ... with Nebius Token Factory as a Day 0 launch partner'), with serverless deprecation waves on June 22 and August 31, 2026 that 'will be unaffected' on dedicated endpoints. Dedicated endpoints ('a private, provisioned instance' shape) let the enterprise 'control: region, GPU type and count per replica, minimum and maximum replicas' in eu-north1, eu-west1, or us-central1, billed per GPU-hour by the minute with no standard rate limits, with observability (traffic, latency percentiles, autoscaling, errors) and Prometheus and Grafana federation for dedicated endpoints only; custom weights 'is currently in beta and available on request'. Fine-tuning jobs run supervised training (full by default, LoRA optional with rank up to 128) or custom speculator training ('a drafter tuned to your own base model and workload') on listed Hugging Face base models, with Weights and Biases and Hugging Face export integrations on the guide page and MLflow in the API reference, over datasets from Data Lab (reinforcement fine-tuning is a limited professional service by request); rate limits scale dynamically to twenty times a base allocation before an Enterprise plan; zero data retention is an organization switch and the chat endpoint is HIPAA-eligible under a BAA with it on (fine-tuning and batch 'excluded from BAA scope'). The Applications marketplace deploys Flowise (an open-source agent builder), Open WebUI, JupyterLab, and ComfyUI as standalone managed apps with export pages. The buyer gets open models it can call, tune, and export, on European floors, with the agent tooling as hosted open-source apps.\n\nThe architect's concern is what Nebius itself adds above the fleet. No model of its own (a licensed Clarifai inference stack inside), a catalogue visible only by API, a burst that 'is not guaranteed', custom weights in beta, batch documented by reference, a modality just retired, and no generally available agent runtime beyond function calling and someone else's app (Sandboxes, a branching code-execution API for agents with a Contree MCP server, 'are currently in Beta').\n\nCalibration: CoreWeave reads strong on open serving under KServe plus its own inference product and sandboxes; Cloudflare strong on serverless open-model inference plus a gateway plus agents; Hugging Face moderate on open serving under maturity gates; Cerebras strong on its own engine at the frontier; Databricks strong on serving plus training plus agents. Nebius has open serving with replica control, generally available full and LoRA fine-tuning and speculator training with export, and a marketplace of open agent tools: the CoreWeave shape with training on top. Strong.",
      "borrowedJudgment": "Delegated at the interfaces and the weights, Ceded at Nebius's surfaces. Serverless model access through OpenAI-compatible endpoints is the inference-interface reading, and the models are their owners' open weights: Delegated. Fine-tuned weights export to Hugging Face format and are the enterprise's artifact: Retained for the weights, the customer fine-tunes reading. Dedicated endpoints, Data Lab, the fine-tuning service, and the flavor catalogue are Nebius's control surfaces on Nebius's GPUs: Ceded, the Cohere Model Vault and CoreWeave Inference reading. Flowise, Open WebUI, JupyterLab, and ComfyUI are open-source applications Nebius operates with documented exports: Delegated. Tools the enterprise writes are Retained. The decision to call a tool is the model's, executed in the enterprise's own process (Token Factory 'does not execute the functions itself'): model decides, visible, overridable, Delegated, the OpenAI and Anthropic reading.",
      "notes": "Badges: custom weights 'currently in beta and available on request', unscored; Sandboxes 'currently in Beta' (Contree SDK, CLI, and MCP server), unscored; the Responses API carries no badge, and its OpenAPI schema lists MCP, code-interpreter, shell, and web-search tool types with approval-request items that no guide documents as executing, unscored. Retired April 13, 2026: text-to-image models (FLUX) and LoRA per-token serverless endpoints. Named, not scored: Reinforcement Fine-tuning ('upcoming', a limited professional service by request, no GA date), the Batch API (referenced, no standalone page), the Nebius Agents Blueprint (blog, June 10, 2026: a reference architecture with recipes naming LangChain Deep Agents, LangSmith, Pinecone Nexus, Tavily, and Snowglobe), the Clarifai inference IP license and the Groq 3 LPX adoption (August 24, 2026). Data Lab processes in Finland regardless of where inference ran. Public evidence that moves the cell: nothing upward from strong; custom weights or Sandboxes leaving beta would add a chip.",
      "components": [
        {
          "component": "Serverless Model Access via OpenAI-Compatible Endpoints (Chat Completions, Responses, Completions, Vision; Function Calling Including MCP Servers; JSON Modes; Base and Fast Flavors per Model; Dynamic Rate Limits)",
          "detail": "Open-weight models their owners publish, behind multi-vendor interfaces. Delegated, the inference-interface ruling; embeddings and rerank are the 1B chips; image generation was retired April 13, 2026.",
          "dapm": "Delegated"
        },
        {
          "component": "Customer-Created and Managed Tools (Function Calling Executed in the Enterprise's Process)",
          "detail": "Tool logic the enterprise writes and runs. Retained, the customer-tools ruling.",
          "dapm": "Retained"
        },
        {
          "component": "Dedicated Endpoints (Region, GPU Type, and Replica Bounds per Endpoint in eu-north1, eu-west1, and us-central1; Non-Preemptible Minimum Replicas; Burst Not Guaranteed; Per-GPU-Hour Billing; Observability With Prometheus and Grafana Federation; Custom Weights in Beta)",
          "detail": "Nebius's provisioned serving on Nebius's GPUs. Ceded, the Cohere Model Vault and CoreWeave Inference reading; custom weights are named, not scored.",
          "dapm": "Ceded"
        },
        {
          "component": "Fine-Tuning and Custom Speculator Training With Data Lab (Supervised Full or LoRA Jobs on Listed Base Models; Weights and Biases and Hugging Face Export, MLflow per the API Reference; SQL Datasets Over Inference Logs and S3 Sources; Processed in Finland)",
          "detail": "Nebius's training service and workbench; the weights it produces export to Hugging Face format and are the enterprise's. Ceded for the service, with the artifact exit named, the Databricks Mosaic AI Model Training reading.",
          "dapm": "Ceded"
        },
        {
          "component": "Managed Open-Source Applications (Flowise Agent Builder, Open WebUI, JupyterLab, ComfyUI; Standalone With Zero Setup or on Kubernetes; Export-Data Pages)",
          "detail": "Others' open-source applications Nebius operates for the enterprise with documented exports. Delegated, the Nutanix managed-open-engine reading.",
          "dapm": "Delegated"
        }
      ]
    },
    {
      "id": "layer2c",
      "label": "Layer 2C",
      "shortName": "Reasoning",
      "title": "Agentic Infrastructure — The Reasoning Plane",
      "purpose": "Policy-driven placement and resource coordination — the Autonomy Layer",
      "status": "gap",
      "statusLabel": "Tenant, Project, and Service-Account Identity for People and Automation, Audit Logs in Preview; Nothing Over Agents: Nebius Echo Is a Console Assistant, Sandboxes Are Beta, the Agents Blueprint Is a Reference Architecture",
      "authority": {
        "decides": "absent",
        "visible": null,
        "overridable": null,
        "boundary": "vendor",
        "direction": "Absent"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Dependency",
          "detail": "Nothing at this layer is a scored capability."
        }
      ],
      "gap": "Read against the five legs, Nebius has none as a plane over agents. Identity: tenants, projects, groups, access permits, service accounts, and OIDC federated credentials identify people and workloads to the cloud and to Token Factory; no agent principal. Gateway: none; Token Factory's function calling hands tool calls back to the enterprise, and the Responses API's schema lists MCP and hosted-tool types with approval-request items that no guide documents as executing. Registry and orchestration: none generally available. Nebius Echo is documented ('an AI assistant that helps you navigate Nebius documentation, explore and manage project resources', executing state changes 'with explicit approval'), and it's one agent Nebius runs over its own console, scored at Layer 3; the Nebius Agents Blueprint (blog, June 10, 2026) is 'an open reference architecture ... and runnable recipes with cloneable code' over Token Factory, LangChain Deep Agents, LangSmith, Pinecone Nexus, Tavily, and Snowglobe, a design, not a service; Sandboxes, a branching code-execution API for agents with a Contree MCP server, 'are currently in Beta'. Observability: dedicated-endpoint metrics, Monitoring and Logging in preview, and Audit Logs in preview watch the cloud, not agents; Sandboxes' logs and artifacts are beta with the product. The buyer brings the plane.\n\nThe architect's concern is nil at this layer: there's nothing generally available to be captured by.\n\nCalibration: CoreWeave, OpenAI, Anthropic, and Cerebras read gap; Cloudflare moderate on a gateway of its own; WEKA gap on application-scoped legs. Nebius is CoreWeave's shape. Gap, authority Absent; Echo is the one-agent case the Confluent, Hugging Face, and WEKA sheets read as a leg, not a plane.",
      "borrowedJudgment": "Nothing offered as a plane. Absent.",
      "notes": "Named, not scored: Nebius Echo (documented; scored at Layer 3 as a console assistant), the Nebius Agents Blueprint (blog, June 10, 2026; no product documentation and no GA date, so not watch-listed), Sandboxes and Contree MCP (Beta), the Responses API tool schema (undocumented beyond the OpenAPI listing), Audit Logs, Monitoring, and Logging (preview). Public evidence that moves the cell: Sandboxes leaving beta with a gateway or registry over the enterprise's agents, or documentation for the Blueprint as a service.",
      "components": []
    },
    {
      "id": "layer3",
      "label": "Layer 3 (+1)",
      "shortName": "Applications",
      "title": "AI Application Layer — The Value Plane",
      "purpose": "AI-powered business capabilities — business logic, workflow automation",
      "status": "gap",
      "statusLabel": "No Business Application: an Applications Marketplace of Others' Open-Source Apps Deployed as Managed Services, Onto the Enterprise's Kubernetes, or Onto a Root-Access Virtual Machine, One NVIDIA Blueprint Under a Bring-Your-Own License, and Nebius Echo, a Console Assistant",
      "authority": {
        "decides": "absent",
        "visible": null,
        "overridable": null,
        "boundary": "vendor",
        "direction": "Absent"
      },
      "nvidia": [
        {
          "component": "The One Blueprint Is NVIDIA's (Named, Not Scored)",
          "detail": "The documented Kubernetes application is the NVIDIA Blueprint for virtual screening, which 'orchestrates a suite of GPU-accelerated NIM microservices' under a bring-your-own NVIDIA AI Enterprise license; the standalone apps run on Nebius's NVIDIA VMs. Nothing at this layer is a scored capability."
        }
      ],
      "gap": "Nebius's application layer is a marketplace with one assistant of its own. Applications deploy three ways ('Virtual machine: ... root access and custom setup'; 'Standalone: ... infrastructure managed by Nebius AI Cloud ... zero setup time'; 'Kubernetes: ... on Managed Service for Kubernetes clusters'), once per project per option and not every option for every app, with documented per-app pages (connect, export data) for JupyterLab, Open WebUI, ComfyUI, Flowise, and Qdrant, standalone pricing that charges for the compute and storage under an app and nothing for the app, and the NVIDIA Blueprint for virtual screening on Kubernetes, which 'orchestrates a suite of GPU-accelerated NVIDIA Inference Microservices (NIM)' and requires 'a valid and sufficient NVIDIA AI Enterprise License' the enterprise brings; standalone apps run in eu-north1 and us-central1. Nebius Echo, 'an AI assistant that helps you navigate Nebius documentation, explore and manage project resources', lists resources and 'executes actions like creating Nebius resources, or starting and stopping virtual machines (VMs) with explicit approval' from the console. The buyer gets a hosted chat UI, an agent builder, notebooks, an image pipeline, and a drug-discovery blueprint in a few clicks, none of them Nebius's, plus a console assistant that is.\n\nThe architect's concern is that Nebius writes none of the applications and runs a marketplace of open-source projects and one NVIDIA blueprint; Echo is an operations assistant over Nebius's own console, not a business application; the value above the console is the enterprise's or the projects'.\n\nCalibration: under the Layer 3 marketplace ruling (September 11, 2026), a marketplace of other people's applications earns no capability grade, a console assistant over the vendor's own platform doesn't either, and the grade rests on first-party business applications; WEKA, NetApp, Everpure, Cerebras, and Groq read gap; Databricks and Snowflake strong on first-party applications. Nebius has none. Gap, authority Absent.",
      "borrowedJudgment": "Nothing offered as a business application. Absent. The relationship boundary records on DAPM where it exists, and here it doesn't: the marketplace bills the compute and storage under an app to the enterprise's Nebius account and carries no commercial relationship for the applications themselves (open source, or NVIDIA's under NVIDIA's license).",
      "notes": "Ruled September 11, 2026 (the Layer 3 marketplace ruling): the first draft read moderate, escalated, on the Nutanix ISV-catalogue reading; a marketplace of others' applications isn't creditworthy at Layer 3, and Echo is an operations assistant rather than a business application. Named, not scored: the managed standalone apps (JupyterLab, Open WebUI, ComfyUI, Flowise, Qdrant; the Qdrant retrieval facet is scored at 1B and the agent tooling at 2B), the self-run VM and Kubernetes deployment paths, the NVIDIA Blueprint for virtual screening (bring-your-own NVIDIA AI Enterprise license), Nebius Echo (no availability badge on its page). Public evidence that moves the cell: a first-party business application.",
      "components": []
    }
  ]
}