Safetensors Concepts

A secure file format for storing AI model weights. Unlike .ckpt files, safetensors cannot contain malicious code, making them the recommended format for sharing models.

Safetensors is the modern, secure way to store and share AI model files.

Why Safetensors?

Security

  • Cannot contain executable code
  • Safe to load from any source
  • Sandboxed parsing

Performance

  • Faster loading than .ckpt
  • Memory-mapped loading
  • Lazy loading possible

Compatibility

  • Supported by all major UIs
  • Works with models, LoRAs, VAEs
  • Cross-platform

File Comparison

FormatSecuritySpeedSize
.safetensorsSafeFastSame
.ckptRiskySlowerSame
.ptRiskyMediumSame

The .ckpt Risk

Traditional .ckpt files use Python pickle format:

  • Can contain arbitrary Python code
  • Code runs when file is loaded
  • Malicious models exist
  • Avoid from untrusted sources

Converting Models

Many tools convert .ckpt to .safetensors:

  • Most UIs have built-in conversion
  • CLI tools available
  • Maintains model quality

Best Practices

  1. Always prefer .safetensors downloads
  2. Avoid .ckpt from unknown sources
  3. Download from reputable sites
  4. Check file types before loading
  5. Most new models are .safetensors only