Paste any Hugging Face model ID. Get a transparent Trust Score, a security and licensing risk report, a serving-cost estimate, and an enterprise-readiness checklist — in about two seconds.
Set the bar your organisation requires. Every scan is evaluated against it live, and the same policy file drives the CI gate.
This is what a scheduled nightly scan reports. Pick an organisation and see how its models fare against the policy above.
Run a scan to produce a pass/fail inventory and export an AI-BOM.
For the engineer reviewing one model.
For the platform lead who needs it enforced.
For the governance lead who needs evidence.
Preview pricing, honestly labelled. Team and Enterprise are not purchasable yet — there is no payment processing connected and nothing has been sold. The buttons open a two-minute form so the features people actually need get built first.
Rubric v1.0 · published 7 August 2026 · unchanged since publication. Every change to a weight or a criterion gets a new version number and a dated entry in the commit history, so any score can be traced back to the exact rubric that produced it.
The Trust Score is a 0–100 heuristic computed from public repository metadata returned by the Hugging Face Hub API. Nothing is hidden: every scan lists the exact criteria that passed and failed, and the points each one carried.
| Pillar | Max | Signals |
|---|---|---|
| Security & serialization | 25 | safetensors availability, pickle-format weights (.bin/.pt/.ckpt), custom executable Python in-repo, repo integrity and config presence |
| Provenance & licensing | 20 | license declared, commercial-use class, base model declared, linked paper, gating status |
| Documentation | 20 | model-card depth, intended use, limitations, bias & risks, training data, runnable example |
| Maintenance | 15 | time since last commit, repo maturity, tokenizer/preprocessor completeness |
| Adoption | 12 | downloads, likes, dependent Spaces |
| Evaluation | 8 | model-index results, declared training/eval datasets |
Limits. This is a triage tool. It tells you where to look — it is not a legal
opinion, a penetration test, or a substitute for reading the license. A high score
means the repository is well-formed and well-documented, not that the model is safe,
accurate, or fit for your use case. Always verify licensing terms with the rights
holder before commercial deployment.
Costs. Serving estimates use indicative on-demand list prices for common GPU
instances and a standard inference memory overhead factor. Real cost depends on
batch size, context length, quantisation, utilisation and your negotiated rates.
Treat the numbers as an order-of-magnitude sanity check.