---
title: "Safetensors"
description: "A file format for storing a model's tensors safely, as opposed to Python pickle, whose loading can run arbitrary code and which the Python documentation calls not secure."
canonical: https://aigovernanceengineer.com/glossary/safetensors
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Safetensors

A file format for storing a model's tensors safely, as opposed to Python pickle [1], whose loading can run arbitrary code and which the Python documentation calls not secure [2]. Storing weights as safetensors, and scanning any remaining pickle files for code-executing imports before they reach a registry, closes a common supply-chain route into serving.

- Developed in: [ch. 14, Reproducibility and linked versioning](https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning); [ch. 05, Pattern: Model Artefact Integrity](https://aigovernanceengineer.com/patterns/model-artefact-integrity)
- Chapters: [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 14, Development](https://aigovernanceengineer.com/bok/governing-development)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-safetensors

## Sources

[1] Safetensors ("a new simple format for storing tensors safely (as opposed to pickle)"). Hugging Face documentation. n.d. (accessed 2026-09-25). https://huggingface.co/docs/safetensors/index (verified: primary)
[2] pickle: Python object serialization ("The pickle module is not secure. Only unpickle data you trust."). Python Software Foundation. 2026. https://docs.python.org/3/library/pickle.html (verified: primary)
