MALICIOUS MODEL FILE SCANNER

Scan the weights
before they hit disk.

Malicious model-file scanning checks weights for embedded code before you load them. Pickle-based files, including PyTorch checkpoints, can run arbitrary Python the moment they are loaded. Route a Hugging Face Hub or GitHub download through AiDren and it scans pickle, safetensors, GGUF, ONNX, joblib and Keras files, plus extension-versus-content mismatches, before the file reaches disk.

No card required ~5ms proxy overhead One-line setup
HOW IT WORKS

How model-file scanning works
A proxy for downloads, not just chat.

Point a Hugging Face Hub or GitHub download at AiDren. Model files are scanned inline; everything else streams straight through and does not count against your request allowance.

  1. 1

    Route the download

    Fetch from Hugging Face Hub or GitHub — release assets and raw files — through AiDren instead of directly.

  2. 2

    The file is scanned

    Pickle (including ones wrapped inside a torch.save ZIP), safetensors, GGUF, ONNX, joblib, and Keras. AiDren also checks that the file’s extension matches its actual content.

  3. 3

    Verdict, cached

    A clean file passes; a malicious one is blocked per your key’s mode. Verdicts are cached content-free, so the same file is not re-scanned on every pull.

FORMATS & CONTROLS

What it scans, what you control

Real coverage and real per-key control, straight from the API reference.

  • Pickle — including pickles wrapped inside a torch.save ZIP.
  • safetensors
  • GGUF
  • ONNX
  • joblib
  • Keras
  • Extension / content mismatch — a .safetensors that is really a pickle is flagged.
  • Monitor or enforce per key, plus an unconditional blocked-formats list and a narrow allowlist (named ONNX custom ops / Keras custom layers only).
IN THE DASHBOARD

Turn model-file scanning on per key.

app.aidren.co.uk/proxy-keys LIVE
AiDren proxy keys page showing per-key model-file scanning mode, blocked formats, and allowlist controls

A real screen from a live AiDren account.

FAQ

Questions,
answered plainly.

More in the API reference and on the pricing section.

Where do you scan model files from, and which formats?

Hugging Face Hub and GitHub: release assets and raw files. Route the download through AiDren and it's scanned for malicious code before it reaches disk, across pickle (including ones wrapped inside a torch.save ZIP), safetensors, GGUF, ONNX, joblib, and Keras. Non-model files pass straight through.

How many requests do I get?

A "checked request" is one AiDren screens on its way to your model. Starter covers 100,000 a month, Growth 500,000, Scale 2,000,000. It's a fair-use guide, not a hard limit: if you go over, we email you about a 10,000-request top-up (£19) or moving up a tier, we don't cut you off mid-month. The count resets on the 1st. For very high volume, email us for a custom plan. Model-file scans and agent egress reports don't count.

How much latency does AiDren add?

The proxy layer itself adds about 5 ms. On top of that, requests that need screening get one classification call — usually 200–500 ms, which runs before your request reaches OpenAI, Anthropic, or Mistral, so it overlaps nothing. Short, clearly-benign messages skip the classification call entirely. Model-file scans and egress reports add nothing to your chat traffic.

What happens after the trial?

Your 14-day trial needs no card up front and covers 25,000 checked requests. When it ends, upgrade to keep your proxy running — if you don't, AiDren pauses your traffic rather than silently letting it through unprotected.

Is a pickle file safe to load?

Only if you fully trust its source. Python's pickle format can run arbitrary code while a file is loading, and the Python documentation warns against unpickling data from an untrusted source. Prefer safetensors where you can, and scan a file before you load it.

Does scanning guarantee a model file is safe?

No scanner can. AiDren checks for dangerous patterns such as unsafe pickle opcodes, custom ONNX ops and Keras Lambda or custom layers, but a clean verdict lowers risk rather than removing it. Load models from sources you trust and run unfamiliar ones in a sandbox.

Can I block a file format outright?

Yes. Add pickle, joblib, safetensors, gguf, onnx or keras to a key's blocked-formats list and any file of that format is refused before scanning runs, in either enforce or monitor mode.

READY WHEN YOU ARE

Know what is in the file
before you load it.

Get the full stack free for 14 days. No card, no sales call, no SDK rewrite.

Start protecting requests