Which model are you considering?
Public Hugging Face repositories only for this early manual service.
No weights uploaded. We use the public repository URL and email the finished report to you.
Free Hugging Face model review
Send us one public Hugging Face model URL. We’ll document its exact revision, license, repository code, file inventory, artifact hashes, and the risks that deserve a closer look—without asking you to upload model weights.
Free while we validate the workflow. One public model per team. No call required.
A concrete first step
We manually inspect the public repository and return a focused provenance and risk report within 24 hours. You get a useful artifact; we learn how technical teams actually evaluate open models.
Repository, revision, license, files, and artifact hashes.
Remote code, serialization formats, provenance gaps, and manual-review items.
What looks safe, what remains unknown, and what to check before deployment.
Public Hugging Face repositories only for this early manual service.
No weights uploaded. We use the public repository URL and email the finished report to you.
The missing decision layer
Built-in hub scanners can flag a dangerous file. They cannot enforce your team’s source, license, revision, and approval rules across every repository.
A model dependency can pass today and change tomorrow when the revision is not pinned. A file can be technically clean but still violate your license policy. A developer can enable remote code without leaving a review trail.
SOURCE
Approved registry and organization policy at the point of import.
REVISION
Commit, files, and hashes tied to the decision your team reviewed.
POLICY
The exact rule, exception, and evidence behind every merge decision.
One gate. Four decisions.
Not a new detection engine. A GitHub-native approval process built around the scanners and policies your team already trusts.
Record the exact model, commit, and files your team approved. Block floating revisions before they reach a deployment workflow.
Surface unsafe serialization signals, remote-code requirements, embedded secrets, and files that need manual review.
Define approved sources, blocked formats, license rules, exceptions, and the severity that stops a merge.
Produce human-readable findings plus JSON and SARIF for CI, code review, and customer security requests.
How it works
A repeatable intake path for every open model your team evaluates, fine-tunes, or deploys.
Provide up to 10 Hugging Face model references or local model paths.
Run checks locally from the CLI or inside a GitHub Action.
Apply source, revision, license, format, and severity rules.
Attach the decision and evidence before merge or deployment.
Local-first by design
Deep file scanning runs in your local environment or CI. Model weights are not uploaded to WeightFence.
WeightFence is not a fit if every model you use is accessed only through a hosted API and no model files enter your environment.
Founding Pilot
The Founding Pilot is a hands-on engagement for one team and up to 10 model dependencies.
weightfence.yml policyNo automatic renewal. Fit guarantee before audit work begins.
Fit guarantee. If the kickoff shows that we cannot define a useful model-intake gate for your workflow, we will refund the full $299. Once you approve the scope and audit work begins, the purchase is non-refundable.
FAQ
Clear scope now means no surprises after kickoff.
No. WeightFence uses existing scanner results where they are available and adds the decision layer they do not provide for your team: approved sources, pinned revisions, license rules, exceptions, GitHub enforcement, and evidence tied to a specific workflow.
No. Deep scanning runs locally or in your CI. The hosted layer is designed to receive hashes, model metadata, policy decisions, and reports—not model weights.
Yes, without transferring the weights to us. Your team can run the checks inside its environment and share only the resulting report. We confirm the workflow during kickoff.
The pilot can inventory any Hugging Face repository or local directory. Deep malicious-serialization checks depend on the file format and available scanner support. We confirm supported files before audit work begins; if the important files cannot be checked, the fit guarantee applies.
No. The pilot is a model intake and policy review. It does not test your entire application, certify compliance, analyze training-data legality, or prove that a model has no behavioral backdoor.
There is no automatic renewal. Founding customers will be invited to continue on the Team plan at $99 per month when it is available.
Early access
Get the first public release and the model intake policy template when they are available.