Model Radar

AI supply-chain due diligence · Hugging Face Hub

Would you put this model
in production?

Paste any Hugging Face model ID. Get a transparent Trust Score, a security and licensing risk report, a serving-cost estimate, and an enterprise-readiness checklist — in about two seconds.

🔒 Pickle & remote-code detection
⚖️ Commercial-use verdict
💰 GPU cost estimator
🕵️ 100% client-side
Press / to search · Try: meta-llama/Llama-3.1-8B-Instruct openai/whisper-large-v3 stabilityai/stable-diffusion-xl-base-1.0 google/gemma-2-9b-it sentence-transformers/all-MiniLM-L6-v2
PRO PREVIEW These are the paid features, unlocked and free while in preview. Everything below runs in your browser against public repos.

🛡️ Policy as code — define your rules once, enforce them everywhere

Set the bar your organisation requires. Every scan is evaluated against it live, and the same policy file drives the CI gate.

CI gate output

🏢 Org-wide scan — every model your teams pull, checked against your policy

This is what a scheduled nightly scan reports. Pick an organisation and see how its models fare against the policy above.

Try: mistralaistabilityaigooglemeta-llamaQwen

Run a scan to produce a pass/fail inventory and export an AI-BOM.

📊 Radar Board — trending models, ranked by Trust Score instead of hype

Scanning the trending list…

Pricing

Free for one person. Paid when it has to hold for a whole team.

Free
$0/forever

For the engineer reviewing one model.

  • Unlimited public model scans
  • Full transparent scoring
  • Risk register & cost estimate
  • Comparison & Radar Board
  • Markdown / JSON export
  • No account, no install
You are using this now
Most teams start here
Team
$199/month

For the platform lead who needs it enforced.

  • Everything in Free
  • Continuous monitoring, 25 tracked models
  • CI/CD gate via API
  • Policy as code, shared across the team
  • Change alerts on license & weights
  • AI-BOM export
  • Private & gated repos via scoped token
Enterprise
from $1,500/month

For the governance lead who needs evidence.

  • Everything in Team
  • Unlimited tracked models
  • SSO & org inventory
  • Historical drift & evidence retention
  • Custom policy packs
  • SLA & self-hosted option

Preview pricing, honestly labelled. Team and Enterprise are not purchasable yet — there is no payment processing connected and nothing has been sold. The buttons open a two-minute form so the features people actually need get built first.

🧮 Methodology

Rubric v1.0 · published 7 August 2026 · unchanged since publication. Every change to a weight or a criterion gets a new version number and a dated entry in the commit history, so any score can be traced back to the exact rubric that produced it.

The Trust Score is a 0–100 heuristic computed from public repository metadata returned by the Hugging Face Hub API. Nothing is hidden: every scan lists the exact criteria that passed and failed, and the points each one carried.

PillarMaxSignals
Security & serialization25safetensors availability, pickle-format weights (.bin/.pt/.ckpt), custom executable Python in-repo, repo integrity and config presence
Provenance & licensing20license declared, commercial-use class, base model declared, linked paper, gating status
Documentation20model-card depth, intended use, limitations, bias & risks, training data, runnable example
Maintenance15time since last commit, repo maturity, tokenizer/preprocessor completeness
Adoption12downloads, likes, dependent Spaces
Evaluation8model-index results, declared training/eval datasets

Limits. This is a triage tool. It tells you where to look — it is not a legal opinion, a penetration test, or a substitute for reading the license. A high score means the repository is well-formed and well-documented, not that the model is safe, accurate, or fit for your use case. Always verify licensing terms with the rights holder before commercial deployment.

Costs. Serving estimates use indicative on-demand list prices for common GPU instances and a standard inference memory overhead factor. Real cost depends on batch size, context length, quantisation, utilisation and your negotiated rates. Treat the numbers as an order-of-magnitude sanity check.