Here is the honest situation. Here is the honest situation. Most teams pull an open-source model from a public registry, read a model card, download the weights, and load them, without a single step that verifies the model is what it claims to be. The card is self-reported by whoever uploaded it and certifies nothing. The repository name can be one character off a real publisher, or a taken-over account pushing a malicious update under a trusted name. The weight file is whatever the server returned, with no pinned hash to prove it is the one you reviewed. And depending on the format, loading it can execute code, because pickle-based files run arbitrary code on deserialization and malicious ones have been found on public registries. A model presented as an independent creation can be a fine-tune whose base model's license forbids your use and whose documented vulnerability it still carries. Doing this well does not mean buying more tooling. It means verifying deliberately: read the card as claims, trace lineage and inherited license and vulnerabilities, pin a hash and fingerprint the weights, verify the namespace, prefer safetensors, check signatures and attestations with Sigstore, in-toto and SLSA, keep a model bill of materials, and gate every model through a vetting workflow. Where teams fall short is predictable: a trusted download that was never verified, an unstated derivative lineage, a stale or absent hash, an unchecked signature, and a model that reached production because a deadline was tight and no one looked.
This Kit removes the guesswork. It is AI model provenance and supply chain verification written as adopt-ready controls you personalize in a weekend, with the evidence a security team, a procurement review or an assessor examines.
What you get, the moment you buy
Grounded in software and AI supply chain security practice applied to real model pipelines, including model lineage and card verification, cryptographic hashing and weight-level fingerprinting, registry and namespace trust, safetensors and serialization safety, Sigstore, in-toto and SLSA signing and attestation, the model bill of materials, and a gated vetting workflow. Editable Word and Excel files. This is a practitioner method, not a substitute for your own security review of a specific model.
What one control looks like
This is the opening control, where the assessment begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A model you cannot evidence as verified in lineage, integrity, source, format, signing and license is a finding waiting to land. This tells you what a reviewer or an assessor examines and where teams fall short, for every control.
- The provenance specifics built in. Model card claim verification, pinned hashing and weight fingerprinting, namespace and typosquatting trust, pickle versus safetensors, Sigstore, in-toto and SLSA, the model bill of materials, and derivative license and vulnerability inheritance are written into the controls, not left generic.
- Built on real practice, not one person's opinion, grounded in how software and AI supply chains are actually made to verify, sign, attest and govern the artifacts they pull.
- It compounds. This work shares its shape with software supply chain security, dependency governance and secure AI development, so it feeds your wider security and platform practice.
Who buys this
Security engineers and procurement reviewers responsible for vetting open-source AI models for production who own the model approval decision and have to prove a model is what it claims before it ships. Whether this is your first pass at verifying a model supply chain or a hardening pass on models already in use, you save weeks and walk in with your lineage, integrity, registry trust, signing, derivative risk and vetting workflow controls structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover the whole model supply chain? Yes. Model lineage and provenance evidence, weight-level fingerprinting and integrity, registry and repository trust, cryptographic signing and attestation, derivative and fine-tune supply chain risk, and the model vetting workflow and governance each have their own controls with their own evidence.
Is this tied to one registry or tool? No. The controls are principle-level, model card verification, hashing and fingerprinting, namespace trust, serialization safety, signing and attestation, the model bill of materials, and the vetting workflow, so they apply whatever registries, formats and tooling you use, alongside your team rather than replacing it.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com