aicoolies logo
OpenSSF Model Signing logo
OpenSSF Model Signing logo

OpenSSF Model Signing

Cryptographic signing and verification for ML models

open sourceupdated Apr 21, 2026

OpenSSF Model Signing is an open-source project for cryptographically signing and verifying machine learning model files to ensure integrity and provenance. Built on Sigstore PKI, it provides CLI tools and a Python library for signing model artifacts and verifying they haven't been tampered with. Part of the OpenSSF AI/ML Working Group, reaching v1.0 in 2025 for production supply chain security.

OpenSSF Model Signing brings software supply chain security practices to machine learning by enabling cryptographic signing and verification of model files. Just as code signing verifies software hasn't been tampered with, model signing ensures that ML model artifacts — weights, configs, and metadata — are authentic and unmodified from their source. The project uses Sigstore's PKI infrastructure, allowing keyless signing through OIDC identity providers like GitHub, Google, and Microsoft, eliminating the complexity of managing cryptographic keys.

The project reached v1.0 in April 2025, establishing a production-ready toolchain for model integrity verification. The CLI tool and Python library support signing models stored locally, in cloud storage, or on model hubs, generating signatures that can be verified independently by anyone downloading the model. This creates a chain of trust from model publisher to model consumer, addressing the growing concern of model poisoning attacks where malicious actors distribute modified model files through public repositories.

OpenSSF Model Signing is developed under the OpenSSF AI/ML Working Group with contributions from Google, NVIDIA, and other industry leaders. It's fully open-source and designed to integrate into existing ML deployment pipelines, CI/CD systems, and model registries. For organizations consuming pre-trained models from external sources or distributing models to customers, model signing provides the cryptographic assurance of model authenticity that software supply chain security already provides for code.

Pricing

Free and open-source

Platforms

Python library + CLI — any platform

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

ToolHive mascot logo

ToolHive

Run and govern MCP servers across desktop, CLI and Kubernetes

Open-source MCP runtime and governance platform that runs servers in isolated containers, curates registries, enforces access policies, and operates gateways across desktop, CLI, and Kubernetes.

Open Source
Anamorpher parent Trail of Bits mark

Anamorpher

Craft image-scaling prompt-injection payloads to red-team multimodal AI systems

Open-source red-team toolkit from Trail of Bits that generates image-scaling attack payloads — images that look benign at full resolution but reveal a hidden prompt injection after a multimodal system downsamples them.

freeOpen Source
cai

CAI (Cybersecurity AI)

AI agent framework for offensive security and penetration testing

Alias Robotics' agent framework for building AI-driven offensive-security workflows — reconnaissance, exploitation, privilege escalation, and lateral movement — with multi-agent handoffs and human-in-the-loop control. Source-available, but the core is licensed for non-commercial research use only.

freemiumTelemetry
MEDUSA logo

MEDUSA

AI-first security scanner for LLM, agent, MCP, and RAG codebases

MEDUSA is an AGPL-3.0 AI-first security scanner from Pantheon Security that checks AI and machine-learning applications, LLM agents, MCP workflows, RAG pipelines, repository-poisoning risks, secrets, and agent-specific compromise patterns.

Open Source
iFixAi logo

iFixAi

Open-source diagnostic for AI operational misalignment

iFixAi is an Apache-2.0 diagnostic tool for scoring AI agents and models against operational-misalignment risks such as hallucination, manipulation, sabotage, sandbagging, and oversight evasion.

Open Source
Inspect AI parent UK AISI mark

Inspect AI

UK AI Security Institute framework for LLM safety evaluations

Inspect AI is an MIT-licensed framework from the UK AI Security Institute for running large language model evaluations, including tool use, multi-turn dialogue, model-graded scoring, and reusable evaluation tasks.

Open Source

FAQ

What is OpenSSF Model Signing?

OpenSSF Model Signing is an open-source project for cryptographically signing and verifying machine learning model files to ensure integrity and provenance. Built on Sigstore PKI, it provides CLI tools and a Python library for signing model artifacts and verifying they haven't been tampered with. Part of the OpenSSF AI/ML Working Group, reaching v1.0 in 2025 for production supply chain security.

Is OpenSSF Model Signing free?

Yes — OpenSSF Model Signing is open source and free to use. Free and open-source

Is OpenSSF Model Signing open source?

Yes — OpenSSF Model Signing is open source.

What are the best OpenSSF Model Signing alternatives?

The top editor-verified OpenSSF Model Signing alternatives are Protect AI, ModelScan.