swiss-ai /Apertus-70B-2509
Verdict
HeldA policy file outside the licence carries a clause that restricts use.
What would change it: evidence from the licensor, or a human ruling. A hold is not a failure.
A verdict covers licence, provenance and files. Quality and fit on your own tasks are measured by Compare.
What was checked
-
Licence Held
Apache-2.0, from a licence file (T1).
-
Provenance Not verified
The licensor's own repository.
-
Files Not verified
Safetensors. The weights digest was not verified, so they are not claimed as byte-checked.
-
Export screening Not yet assessed
No export claim is made.
Verify this verdict
Download attestation.json and check it against the published key:
python scripts/verify-verdict.py
Full record
- Revision
379311a08b6e691f 7b5cfbc1 c408e8fc 0c172981 - Date assessed
- 2026-09-25 BACKFILL
- Upstream released
- 2026-04-21T09:39:41Z, the commit date of the assessed revision, recorded 2026-09-25. A reconstruction: this verdict was assessed before upstream release tracking began, so it is excluded from the median.
- Release to verdict
- Verdict latency: 3758 hours from the upstream release to 00:00 UTC on the assessment date. The record is dated, not timed, so the true figure may be up to 24 hours higher.
- Provenance label
- the weights digest was not verified for this verdict, so the weights are not claimed as byte-checked
- Licence, declared and concluded
- Declared: Apache-2.0 (as a licence-file). Concluded: Apache-2.0.
- Evidence tier
- T1 a licence file in the model repository. Sufficient for Class A.
- Deviation from canonical text
- Deviation found: the added-clause screen found clauses outside the licence file, in the declared sibling policy files. They are quoted under the verdict.
- Added-clause screen
- Run over ../policy-files/apertus-70b-2509-usage-policy.md; 3 clauses found, quoted under the verdict.
- Provenance chain
- Source: huggingface.co/swiss-ai/Apertus-70B-2509. Official licensor repository: yes.
- Base lineage
- Not a derivative recorded in the admission record, so no base licence obligations arise.
- Base-licence obligations
- None recorded: this is not a derivative, or the base's conditions were not engaged.
- Contradiction triage
- None recorded.
- Files and integrity
- safetensors; the weights digest was not verified for this verdict, so the weights are not claimed as byte-checked.
- Export screen
- Export screening: not yet assessed. No export claim is made. The record carries status: not_assessed, basis: null, assessed_by: null, assessed_date: null, reference: null.
- Declared training data
- not recorded in the admission record.
- What was checked
- Canonical text pinned and digest-verified, identifier taken from the licensor's own repository metadata, added-clause screen run over sibling policy files, provenance chain recorded. The licensor's own licence file is not compared byte for byte on this evidence path.
- Signed attestation
- attestation.json: a DSSE envelope over an in-toto Statement v1, whose subject is the weights file digests and whose predicate is this record's provenance artefact. Signed with the key published at /verdicts/keys/, which states the fingerprint, the date the key came into use and how to verify the signature. Key custody: a local key on one operator host, not an HSM.
- Gate findings
added-clause: added clause in ../policy-files/apertus-70b-2509-usage-policy.md: an indemnity clause: the policy requires the user to indemnify or hold harmless a third party, which neither Apache 2.0 nor MIT imposes: "By using the Apertus LLM you agree to indemnify, defend, and hold harmless ETH Zurich and EPFL against any third-party claims arising from your use of Apertus LLM."added-clause: added clause in ../policy-files/apertus-70b-2509-usage-policy.md: a use restriction: the policy prohibits or restricts uses beyond the canonical licence: "The training data and the Apertus LLM may contain or generate information that directly or indirectly refers to an identifiable individual (Personal Data)."added-clause: added clause in ../policy-files/apertus-70b-2509-usage-policy.md: a binding term: the policy makes the user agree to, warrant or consent to something the licence does not: "By using the Apertus LLM you agree to indemnify, defend, and hold harmless ETH Zurich and EPFL against any third-party claims arising from your use of Apertus LLM." The gate's own words, with one term normalised; the signed attestation carries them exactly.
Running models like this in your own estate? Heliast runs the same gate inside your environment, on your policy.
Book a discovery session