Skip to content

The 8 Hugging Face security checks Black Cat runs

Black Cat SSPM evaluates 8 security policies against your Hugging Face configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Hugging Face — what access Black Cat needs, and why.

Access control & privilege (3)

Other checks (5)

severity: low SSO Not Observed fix difficulty: medium #

Confirm SSO is configured and in use for the organization

  1. Open Organization Settings > SSO and verify a provider is configured
  2. Require SSO for member sign-in
  3. Re-run the scan; org.sso_login events should appear in the audit log

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Public Org Repository fix difficulty: easy #

Review org repositories that are publicly visible

  1. Open the repository Settings on huggingface.co
  2. Confirm public exposure is intentional; set to Private if it holds proprietary models, datasets, or code
  3. For datasets that must be shared, prefer a gated repository over fully public

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low Public Gated Repository Misconfiguration fix difficulty: easy #

Consider gating sensitive datasets/models that must remain shareable

  1. Open the repository Settings
  2. Enable gated access for models/datasets with usage or licensing constraints

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low Audit Logs Unavailable fix difficulty: easy #

Enable an org plan that provides audit logs

  1. Confirm the organization is on a Team or Enterprise plan
  2. Ensure the connector token has read access to organization settings
  3. Re-run the scan to confirm audit events are retrieved

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high Token Approval Policy Disabled fix difficulty: medium #

Re-enable the access-token approval policy

  1. Open Organization Settings > Tokens and enable "Require administrator approval"
  2. Review any tokens authorized while the policy was disabled
  3. Rotate org tokens if unexpected access occurred

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.3 DORA (SaaS Security) DORA-9.8

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial