Skip to main content
ShadowAI Defense GitHub
← All services

Hugging Face · Conversational AI

Hugging Face Chat

Allow with DLP Enterprise tier: Available DPA: Yes

Network signatures

Domains: huggingface.co, hf.co

API endpoints: api-inference.huggingface.co, api.huggingface.co

SNI patterns: *.huggingface.co, *.hf.co

Client signatures

Risk profile (1–5)

  • Data exfiltration: 3
  • IP loss: 4
  • Output quality (hallucination / legal): 2
  • Integration risk (OAuth, extensions, agentic): 3

Data egress concerns

  • Prompts sent through the Inference API reach various open-source model endpoints with differing privacy guarantees
  • Model fine-tuning datasets uploaded to Hub may contain proprietary or sensitive training data
  • Spaces and repositories may inadvertently expose internal models, datasets, or API keys
  • Conversations through HuggingChat use open-source models but data may be logged for service improvement

Training-use default

HuggingChat conversations may be shared publicly and used for model improvement unless users opt out. Enterprise Hub provides private inference with contractual controls. Self-hosted inference avoids data egress entirely.

Applicable detection rules

References