Free manual review · 24-hour delivery

Free Hugging Face model review

Submit a model. Get a risk report in 24 hours.

Send us one public Hugging Face model URL. We’ll document its exact revision, license, repository code, file inventory, artifact hashes, and the risks that deserve a closer look—without asking you to upload model weights.

Free while we validate the workflow. One public model per team. No call required.

weightfence / model-intakePR #184
MODEL INTAKE CHECK

acme/retrieval-model

BLOCK
×
Revision policyrevision_not_pinned
BLOCK
!
Remote codetrust_remote_code = true
REVIEW
Serialization scanNo critical findings
PASS
Approved sourcehuggingface.co/acme
PASS
01Runs in your CI
02Weights stay local
03Pass / review / block
04Audit-ready evidence

A concrete first step

Send a model URL. Receive evidence you can review.

We manually inspect the public repository and return a focused provenance and risk report within 24 hours. You get a useful artifact; we learn how technical teams actually evaluate open models.

  1. 01
    Exact model identity

    Repository, revision, license, files, and artifact hashes.

  2. 02
    Risk signals

    Remote code, serialization formats, provenance gaps, and manual-review items.

  3. 03
    Plain-English decision

    What looks safe, what remains unknown, and what to check before deployment.

See the public Qwen sample report
FREE MODEL REVIEWWITHIN 24 HOURS

Which model are you considering?

Public Hugging Face repositories only for this early manual service.

No model weights are uploaded. We review public repository metadata and files.

No weights uploaded. We use the public repository URL and email the finished report to you.

The missing decision layer

A clean scan is not the same as an approved model.

Built-in hub scanners can flag a dangerous file. They cannot enforce your team’s source, license, revision, and approval rules across every repository.

A model dependency can pass today and change tomorrow when the revision is not pinned. A file can be technically clean but still violate your license policy. A developer can enable remote code without leaving a review trail.

01

SOURCE

Who published it?

Approved registry and organization policy at the point of import.

02

REVISION

What exactly changed?

Commit, files, and hashes tied to the decision your team reviewed.

03

POLICY

Why did it pass?

The exact rule, exception, and evidence behind every merge decision.

One gate. Four decisions.

Everything a model needs before production.

Not a new detection engine. A GitHub-native approval process built around the scanners and policies your team already trusts.

01revision_not_pinned

Pin every revision

Record the exact model, commit, and files your team approved. Block floating revisions before they reach a deployment workflow.

02trust_remote_code

Inspect risky files

Surface unsafe serialization signals, remote-code requirements, embedded secrets, and files that need manual review.

03weightfence.yml

Enforce team policy

Define approved sources, blocked formats, license rules, exceptions, and the severity that stops a merge.

04report.sarif

Keep the evidence

Produce human-readable findings plus JSON and SARIF for CI, code review, and customer security requests.

How it works

From model URL to merge decision.

A repeatable intake path for every open model your team evaluates, fine-tunes, or deploys.

  1. 01

    Map

    Provide up to 10 Hugging Face model references or local model paths.

  2. 02

    Scan

    Run checks locally from the CLI or inside a GitHub Action.

  3. 03

    Decide

    Apply source, revision, license, format, and severity rules.

  4. 04

    Prove

    Attach the decision and evidence before merge or deployment.

Local-first by design

The scanner goes to the model. The model does not come to us.

Deep file scanning runs in your local environment or CI. Model weights are not uploaded to WeightFence.

  • Only approved metadata and findings enter the pilot report.
  • Private repository access is optional.
  • Your team can run checks and share only the output.
YOUR ENVIRONMENT
HF
Model weightsPrivate registry / local
LOCAL SCAN
Approved outputHash · policy · findings
Weights never cross this boundary
A FIT

Built for teams shipping open models.

  • Import Hugging Face models into production environments.
  • Run open weights on your own cloud, VPC, or hardware.
  • Need to explain provenance and approval decisions.
  • Have more model dependencies than one engineer can review.
NOT A FIT

Calling one hosted model API?

WeightFence is not a fit if every model you use is accessed only through a hosted API and no model files enter your environment.

Founding Pilot

Get your first model intake policy installed.

The Founding Pilot is a hands-on engagement for one team and up to 10 model dependencies.

1 day to kickoff5 days to delivery60 days Team early access
FOUNDING PILOT

$299

ONE TIME
  • Inventory for up to 10 model dependencies
  • Pass / review / block risk report
  • Tailored weightfence.yml policy
  • GitHub Action with JSON / SARIF evidence
  • 30-minute findings review
  • 60 days of Team early access
Reserve my pilot — $299

No automatic renewal. Fit guarantee before audit work begins.

Fit guarantee. If the kickoff shows that we cannot define a useful model-intake gate for your workflow, we will refund the full $299. Once you approve the scope and audit work begins, the purchase is non-refundable.

FAQ

Questions before the gate.

Clear scope now means no surprises after kickoff.

Does this replace Hugging Face security scanning?

No. WeightFence uses existing scanner results where they are available and adds the decision layer they do not provide for your team: approved sources, pinned revisions, license rules, exceptions, GitHub enforcement, and evidence tied to a specific workflow.

Do I have to upload model weights?

No. Deep scanning runs locally or in your CI. The hosted layer is designed to receive hashes, model metadata, policy decisions, and reports—not model weights.

Can you review private models?

Yes, without transferring the weights to us. Your team can run the checks inside its environment and share only the resulting report. We confirm the workflow during kickoff.

Which model formats are supported?

The pilot can inventory any Hugging Face repository or local directory. Deep malicious-serialization checks depend on the file format and available scanner support. We confirm supported files before audit work begins; if the important files cannot be checked, the fit guarantee applies.

Is this a penetration test or compliance certification?

No. The pilot is a model intake and policy review. It does not test your entire application, certify compliance, analyze training-data legality, or prove that a model has no behavioral backdoor.

What happens after the included 60 days?

There is no automatic renewal. Founding customers will be invited to continue on the Team plan at $99 per month when it is available.