Scan the weights
before they hit disk.
Malicious model-file scanning checks weights for embedded code before you load them. Pickle-based files, including PyTorch checkpoints, can run arbitrary Python the moment they are loaded. Route a Hugging Face Hub or GitHub download through AiDren and it scans pickle, safetensors, GGUF, ONNX, joblib and Keras files, plus extension-versus-content mismatches, before the file reaches disk.
How model-file scanning works
A proxy for downloads, not just chat.
Point a Hugging Face Hub or GitHub download at AiDren. Model files are scanned inline; everything else streams straight through and does not count against your request allowance.
-
1
Route the download
Fetch from Hugging Face Hub or GitHub — release assets and raw files — through AiDren instead of directly.
-
2
The file is scanned
Pickle (including ones wrapped inside a
torch.saveZIP), safetensors, GGUF, ONNX, joblib, and Keras. AiDren also checks that the file’s extension matches its actual content. -
3
Verdict, cached
A clean file passes; a malicious one is blocked per your key’s mode. Verdicts are cached content-free, so the same file is not re-scanned on every pull.
What it scans, what you control
Real coverage and real per-key control, straight from the API reference.
- Pickle — including pickles wrapped inside a
torch.saveZIP. - safetensors
- GGUF
- ONNX
- joblib
- Keras
- Extension / content mismatch — a
.safetensorsthat is really a pickle is flagged. - Monitor or enforce per key, plus an unconditional blocked-formats list and a narrow allowlist (named ONNX custom ops / Keras custom layers only).
Related: OSS / third-party agent security · Agent egress monitoring · AiDren vs Protect AI · How AiDren compares →
Turn model-file scanning on per key.
A real screen from a live AiDren account.
Where do you scan model files from, and which formats?
Hugging Face Hub and GitHub: release assets and raw files. Route the download through AiDren and it's scanned for malicious code before it reaches disk, across pickle (including ones wrapped inside a torch.save ZIP), safetensors, GGUF, ONNX, joblib, and Keras. Non-model files pass straight through.
How many requests do I get?
A "checked request" is one AiDren screens on its way to your model. Starter covers 100,000 a month, Growth 500,000, Scale 2,000,000. It's a fair-use guide, not a hard limit: if you go over, we email you about a 10,000-request top-up (£19) or moving up a tier, we don't cut you off mid-month. The count resets on the 1st. For very high volume, email us for a custom plan. Model-file scans and agent egress reports don't count.
How much latency does AiDren add?
The proxy layer itself adds about 5 ms. On top of that, requests that need screening get one classification call — usually 200–500 ms, which runs before your request reaches OpenAI, Anthropic, or Mistral, so it overlaps nothing. Short, clearly-benign messages skip the classification call entirely. Model-file scans and egress reports add nothing to your chat traffic.
What happens after the trial?
Your 14-day trial needs no card up front and covers 25,000 checked requests. When it ends, upgrade to keep your proxy running — if you don't, AiDren pauses your traffic rather than silently letting it through unprotected.
Is a pickle file safe to load?
Only if you fully trust its source. Python's pickle format can run arbitrary code while a file is loading, and the Python documentation warns against unpickling data from an untrusted source. Prefer safetensors where you can, and scan a file before you load it.
Does scanning guarantee a model file is safe?
No scanner can. AiDren checks for dangerous patterns such as unsafe pickle opcodes, custom ONNX ops and Keras Lambda or custom layers, but a clean verdict lowers risk rather than removing it. Load models from sources you trust and run unfamiliar ones in a sandbox.
Can I block a file format outright?
Yes. Add pickle, joblib, safetensors, gguf, onnx or keras to a key's blocked-formats list and any file of that format is refused before scanning runs, in either enforce or monitor mode.
Know what is in the file
before you load it.
Get the full stack free for 14 days. No card, no sales call, no SDK rewrite.
Start protecting requests