> ML_STANDARD // SAFETENSORS-FILE-FORMAT-SPECIFICATION_v1.0
SafeTensors Serialization Format Specification
Hugging Face / Rust Foundation · Open Source Consensus Standard · active
specificationOpen Source Consensus Standardactive
Regulatory & Technical Framework Summary
Zero-copy, memory-mapped neural network weight storage format designed to permanently eliminate arbitrary code execution vulnerabilities present in Python pickle files (.bin, .pt).
Key Compliance Requirements
- Strict header layout: 8-byte unsigned little-endian integer specifying JSON header length
- Pure JSON metadata header disclosing tensor shapes, dtypes, and data byte offsets
- Raw binary data buffer directly memory-mappable via mmap without deserialization code execution
- Deterministic SHA-256 integrity digest validation
Applicable Sectors & Tasks
Affected Sectors:
technologycloud computing
Affected Tasks:
text generationimage classificationmodel registry
TinyCTO provides regulatory summaries and technical engineering alignment for informational purposes only. This content does not constitute formal legal advice or regulatory compliance certification.
