Skip to content
aicoolies logo
OpenSSF Model Signing logo

OpenSSF Model Signing

Cryptographic signing and verification for ML models

OpenSSF Model Signing is an open-source project for cryptographically signing and verifying machine learning model files to ensure integrity and provenance. Built on Sigstore PKI, it provides CLI tools and a Python library for signing model artifacts and verifying they haven't been tampered with. Part of the OpenSSF AI/ML Working Group, reaching v1.0 in 2025 for production supply chain security.

About OpenSSF Model Signing

OpenSSF Model Signing brings software supply chain security practices to machine learning by enabling cryptographic signing and verification of model files. Just as code signing verifies software hasn't been tampered with, model signing ensures that ML model artifacts — weights, configs, and metadata — are authentic and unmodified from their source. The project uses Sigstore's PKI infrastructure, allowing keyless signing through OIDC identity providers like GitHub, Google, and Microsoft, eliminating the complexity of managing cryptographic keys.

The project reached v1.0 in April 2025, establishing a production-ready toolchain for model integrity verification. The CLI tool and Python library support signing models stored locally, in cloud storage, or on model hubs, generating signatures that can be verified independently by anyone downloading the model. This creates a chain of trust from model publisher to model consumer, addressing the growing concern of model poisoning attacks where malicious actors distribute modified model files through public repositories.

OpenSSF Model Signing is developed under the OpenSSF AI/ML Working Group with contributions from Google, NVIDIA, and other industry leaders. It's fully open-source and designed to integrate into existing ML deployment pipelines, CI/CD systems, and model registries. For organizations consuming pre-trained models from external sources or distributing models to customers, model signing provides the cryptographic assurance of model authenticity that software supply chain security already provides for code.

Pricing & Platform Specs

Pricing Summary

100% open-source (Apache-2.0) cryptographic model signing and supply chain security framework by OpenSSF and Sigstore. $0 public-good infrastructure funded by the Linux Foundation (Fulcio keyless CA and Rekor transparency log). Provides cryptographic verification, in-toto build attestations, and SLSA provenance for Safetensors, GGUF, and PyTorch models across Hugging Face Hub and CI/CD pipelines with zero licensing fees.

full pricing breakdown →

Supported Platforms

Python library + CLI — any platform

Explore categories, tags & use cases

AI/ML supply chain security and model risk management

Protect AI is a YC-backed AI security company focused on ML supply chain protection. Its platform includes ModelScan for detecting malicious code in model files, Guardian for model repository security policies, and NB Defense for Jupyter notebook scanning. Advocates for SLSA-style supply chain standards for ML, helping organizations secure the full pipeline from training data to production model deployment.

freemiumOpen Source

Security scanner for AI model files

ModelScan by Protect AI is an open-source tool that scans machine learning model files for malicious or unsafe code before they are loaded into production. Supporting formats like Pickle, HDF5, and SavedModel, it detects hidden code execution, deserialization attacks, and supply chain threats in the AI/ML model artifact pipeline, integrating into CI/CD as a critical security gate.

Open Source

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is OpenSSF Model Signing?

OpenSSF Model Signing is an open-source project for cryptographically signing and verifying machine learning model files to ensure integrity and provenance. Built on Sigstore PKI, it provides CLI tools and a Python library for signing model artifacts and verifying they haven't been tampered with. Part of the OpenSSF AI/ML Working Group, reaching v1.0 in 2025 for production supply chain security.

Is OpenSSF Model Signing free?

Yes — OpenSSF Model Signing is free to use. 100% open-source (Apache-2.0) cryptographic model signing and supply chain security framework by OpenSSF and Sigstore. $0 public-good infrastructure funded by the Linux Foundation (Fulcio keyless CA and Rekor transparency log). Provides cryptographic verification, in-toto build attestations, and SLSA provenance for Safetensors, GGUF, and PyTorch models across Hugging Face Hub and CI/CD pipelines with zero licensing fees.

Is OpenSSF Model Signing open source?

Yes — OpenSSF Model Signing is open source.

Is OpenSSF Model Signing still maintained?

Yes — OpenSSF Model Signing is active. Its listing was last verified on September 6, 2026.

What are the best OpenSSF Model Signing alternatives?

The first editor-selected OpenSSF Model Signing alternatives are Protect AI, ModelScan.