Hugging Face Compliance Splits Between Hub Controls and Your Inference Traffic
Hugging Face documents SOC 2 Type 2 certification, GDPR compliance, SSO, resource groups, MFA, commit signing and malware, pickle and secrets scanning on the Hub. Those controls govern who touches a repository. A compliance file for an AI system also needs records of inference traffic: which identity called which model endpoint, with what data, under which policy. This article separates the repository controls from the request controls.

Hugging Face's security documentation states that the company "is SOC2 Type 2 certified" and GDPR compliant, and that Enterprise Plan customers can obtain Business Associate Addendums or GDPR data processing agreements. The Hub itself documents User Access Tokens, Two-Factor Authentication, Single Sign-On, Advanced Access Control through resource groups, GPG commit signing, Malware Scanning, Pickle Scanning and Secrets Scanning. Hugging Face compliance work tends to stop at that list, which covers the artifact side of the problem and leaves the traffic side open.
Repository controls answer who can publish or pull a model. An AI control audit also asks what happened at inference time, and that question is answered on your side of the wire.
TL;DR
- Hugging Face documents SOC 2 Type 2 certification, GDPR compliance and a named set of Hub security features including SSO, resource groups and three scanning services.
- Those features govern repository access and artifact integrity, not the content of inference requests your applications make.
- A model supply chain file needs the pinned revision, the scanner result and the approval record for every model in production use.
- Inference evidence needs per-request identity, data classification, destination endpoint and policy decision, captured where the request is made.
The Hub controls cover artifact provenance
The Hugging Face Hub security documentation lists the mechanisms by name. Access tokens and resource groups decide who reaches a private repository. Commit signing with GPG establishes who published a revision. Malware Scanning, Pickle Scanning and Secrets Scanning look for dangerous content in uploaded files, with third-party scanner integrations also documented.
Read as a control set, this is supply-chain assurance. It tells an auditor that the weights your platform team pulled on a given date came from a known publisher and passed scanning. Stated that way, it is a control an auditor can test against a dated pull record.
What it does not describe is the request. Once a model is deployed behind an internal endpoint, the Hub has no further involvement, and no Hub log records that an analyst sent customer records through the model at 4pm.
Pin the revision or the evidence decays
A model reference without a revision is a moving target. The same repository identifier can point at different weights next month, and an audit finding about model behavior then has no fixed artifact to examine.
Record four things for every model in production use. The repository identifier, the exact commit revision deployed, the scanning result at the time of approval and the named approver with a date. Store the record where change management already lives rather than in a spreadsheet maintained by one engineer.
An open-weights deployment without pinned revisions is not a governed AI system, whatever the policy document says. The AI governance framework covers the approval structure this slots into, and Hugging Face security covers the Hub control surface in more depth.
Self-hosted inference does not remove the obligation
Teams often treat self-hosting as a compliance simplification. The data stays inside the network, so the third-party processing question goes away. That removes one obligation and adds several others.
The organization now owns model behavior, access control at the endpoint, logging of requests and classification of the content being submitted. EU AI Act Article 12 requires automatic recording of events over the lifetime of a high-risk system, including the period of use, the input data and identification of the natural persons involved. A self-hosted endpoint with no request records satisfies none of that.
The NIST AI Risk Management Framework handles this under MEASURE and MANAGE, which both expect dated evidence that a control operated rather than a statement that it exists.
The identity problem is sharper with internal endpoints
A hosted commercial API at least carries an API key per application. A self-hosted inference server reached over the internal network often accepts unauthenticated calls from anything that can route to it, because the first deployment was a proof of concept and nobody revisited it.
That configuration produces an endpoint where any workload can submit any content and nothing records the end user behind the call. Fixing it means the calling application attaches the authenticated end-user identity to each request, and an enforcement point on the path records that identity alongside the policy decision.
AI policy enforcement at the HTTP layer describes how that capture works on managed HTTP paths. Local execution through a Python process on a developer laptop produces no HTTP request to inspect, so endpoint controls cover that case instead.
Build the file in two parts
Keep the artifact evidence and the request evidence in separate sections with separate owners. The artifact section holds vendor attestations, the SOC 2 report reference, pinned revisions, scanning results and approvals. The request section holds per-request records, policy versions, coverage tests and exception records.
Reviewers move faster through a file structured that way, and the split makes a missing control obvious. Hugging Face audit logs covers what the platform records, and AI audit trail requirements by regulation covers the fields each regime names.
DeepInspect
DeepInspect is a stateless proxy for authenticated HTTP traffic between enterprise users or agents and LLM endpoints, including self-hosted inference servers running open weights pulled from the Hub. It evaluates application-supplied identity, request classification, approved destination and policy before forwarding, then writes a signed per-decision record outside the calling application's write path.
That supplies the request half of a Hugging Face compliance file while the Hub controls supply the artifact half. DeepInspect does not scan model weights, validate model quality or replace Hugging Face's own attestations, and local process execution stays outside its enforcement boundary. Book a demo today.
Frequently asked questions
- Is Hugging Face SOC 2 certified?
Hugging Face's security documentation states that the company is SOC 2 Type 2 certified and GDPR compliant, and that Business Associate Addendums or GDPR data processing agreements are available through an Enterprise Plan. Request the current report under NDA, check the period it covers and confirm the services in scope match the ones your organization uses.
- Do the Hub scanners make an open model safe to deploy?
They reduce a specific class of risk. Malware Scanning, Pickle Scanning and Secrets Scanning look for dangerous content in uploaded files, which addresses artifact integrity. Model behavior under adversarial input, output handling in your application and authorization on the inference endpoint are separate concerns with separate controls and separate evidence.
- What does an auditor ask about a self-hosted open model?
Which revision is deployed, who approved it, what the scanning result was, who can reach the endpoint, what identity is recorded per request, how input content is classified and how long the records are retained. The first three come from the supply-chain file and the rest come from request-level evidence.
- How are private repository controls evidenced?
Export the resource group configuration, the SSO settings, the token inventory with scopes and the membership list, each with an export date. Pair that with a sample showing that a user outside the group cannot pull the repository, which converts a configuration screenshot into a tested control.