Skip to main content

> ML_STANDARD // SAFETENSORS-FILE-FORMAT-SPECIFICATION_v1.0

SafeTensors Serialization Format Specification

Hugging Face / Rust Foundation · Open Source Consensus Standard · active

specificationOpen Source Consensus Standardactive

Regulatory & Technical Framework Summary

Zero-copy, memory-mapped neural network weight storage format designed to permanently eliminate arbitrary code execution vulnerabilities present in Python pickle files (.bin, .pt).

Key Compliance Requirements

  • Strict header layout: 8-byte unsigned little-endian integer specifying JSON header length
  • Pure JSON metadata header disclosing tensor shapes, dtypes, and data byte offsets
  • Raw binary data buffer directly memory-mappable via mmap without deserialization code execution
  • Deterministic SHA-256 integrity digest validation

Applicable Sectors & Tasks

Affected Sectors:
technologycloud computing
Affected Tasks:
text generationimage classificationmodel registry

TinyCTO provides regulatory summaries and technical engineering alignment for informational purposes only. This content does not constitute formal legal advice or regulatory compliance certification.