Platform / Custom models / Own your model
Own your model: weights, data, evaluation and lineage that stay yours
What owning a custom model actually means, what you do not own, and how portability, control, sovereignty and retirement work in practice.
Owning a model is a stronger claim than paying for access to one. It means you hold the weights or the adapter, the data it learned from, the tests that justified releasing it and the record that ties them together, and that you can take all of it elsewhere. It also has limits: the base model you started from belongs to its maker, and its licence follows your model. This page sets out both sides plainly, with the controls Swfte has built and those it is designed for.
What ownership means
Four things, held together. Missing any one of them weakens the other three.
Your weights or adapter
The trained artifact itself: full weights from a fine-tune, or an adapter trained on top of a base. Stored in the Model Vault with a hash for every file.
Your training data
The selected, sanitised dataset and its datasheet. Without it you cannot retrain, explain the model or respond properly to an erasure request.
Your evaluation sets
The domain, safety and regression cases you built from your own work. They are often more valuable than any single model, because every future model is judged against them.
Your lineage record
Which base, which data, which evaluation results, who approved each promotion and when. The record that lets you answer for the model later.
What you do not own
You do not own the base model. An adapter or a fine-tune is a derivative of weights someone else released, under a licence they chose, and that licence still applies to what you build on it. Some licences are permissive and ask for little more than a notice. Others restrict use above a certain scale, require the model name to be shown, or exclude certain regions or uses. The Llama licence, for example, carries an EU restriction on some multimodal models, set out on the deploy-models hub.
So ownership starts before training, with the choice of base. Read the licence file that ships with the exact checkpoint, record the revision, and have counsel read it for your intended use. As a recommendation, permissive licences such as Apache 2.0 or MIT keep the most options open. If you used another model's outputs as training data, its terms may apply too.
Portability and exit
A model you cannot take with you is a model you rent. Weights stored in the Model Vault can be downloaded, with the hash manifest that proves they are the files you evaluated, and run on any infrastructure that can serve them. Because Connect speaks the OpenAI-compatible API and so do the common serving engines, applications built against the gateway are not written against anything only Swfte provides.
Plan the exit while things are going well. Keep your datasets, evaluation sets and datasheets in storage you control, export the vault's audit log on a schedule, and test once that you can stand the model up elsewhere. The contractual side of exit and export is <contractual exit and export terms - founder to fill>.
Control: who can do what
Ownership without control is a title deed to a house someone else holds the keys to.
Who can deploy
Deploying and undeploying a model to an endpoint are recorded actions in the vault's audit log, so you can see who did each one.
Who can promote
Promotion from development to staging to production is a separate step. Your process decides who approves it and on what evidence.
Kill switch on the brain link
The company brain's outbound link has a local kill switch, journalled, so the organisation can cut the connection from its own side at any time.
Access lists on the data
Content in the brain carries per-object access lists copied from the source, and reads are filtered by them. This part is in progress.
Sovereignty and EU-first hosting
Ownership is easier to defend when the infrastructure is also under your control or under law you understand. The platform's direction is sovereign by default: the company brain is customer-hosted and can run connected, private or air-gapped, and models are served on dedicated, single-tenant infrastructure rather than a shared pool. For European organisations, in-region hosting is the starting point; the regions and facilities on offer are <EU regions and facilities offered - founder to fill>.
Sovereignty has several dimensions, from where data sits to who operates the hardware to which law reaches the operator. The sovereignty page and the guide to deploying in the EU go through them one by one. For a custom model the practical test is simple: could you keep serving it if your relationship with any single provider ended tomorrow?
Lineage, retirement and erasure
Lineage is the chain from data to model to decision. For a custom model it records the base and its revision, the dataset and its datasheet, the evaluation results at each promotion, and who approved. The Model Vault records the base model, versions, stages and an exportable audit log today; the dataset and evaluation records are yours to keep beside it until data export and managed evaluation are built.
Retirement matters as much as release. When a model is replaced, archive it rather than delete it, so the record of what served past decisions survives. Erasure is harder. If a person whose data was used for training later asks to be erased, current methods cannot reliably remove their influence from trained weights. The honest answer is to rebuild the dataset without them, retrain, evaluate and promote the new version, then retire the old one.
What ownership costs, and where compliance fits
Owning a model costs more than calling one. You pay for the people who prepare data and build evaluation suites, for training compute, for dedicated serving that runs whether or not traffic arrives, and for retraining when data changes or is erased. In return you get behaviour you control, data that stays where you put it, and no dependency on a provider's next release. For a narrow, high-volume task that trade is often worth it. For occasional use, a governed general model is usually cheaper.
Swfte provides the technical controls, governance mechanisms and evidence required to deploy AI within an organisation's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration. Swfte does not hold a SOC 2 report, an ISO 27001 certificate or a HIPAA BAA today. A SOC 2 Type I audit is in preparation; the trust page lists what is in place and what is in progress.
What to ask any vendor
Ask these of Swfte as well. A vendor who cannot answer them clearly is renting you a model, whatever the contract calls it.
- 01
Can we download the weights?
In a standard format, with hashes, without asking permission each time.
- 02
Where does the data go?
Which region, which operator, which law, and whether any of it is used to train anything else.
- 03
What is recorded?
Base model, data, evaluation, approvals and every deployment, and whether we can export that record.
- 04
Who can change what is serving?
Who can promote, deploy and roll back, and how each action is logged.
- 05
What happens on erasure?
How a retrain is triggered and how long the old version keeps serving.
- 06
What happens at exit?
What we take, in which formats, and what is deleted on your side afterwards.
A worked example
A public-sector agency adapts a small open-weight base, released under a permissive licence, to classify and route citizen enquiries in each of its official languages. It keeps the dataset, its datasheet and its evaluation sets in its own storage, and uploads the adapted weights to the Model Vault, which records the base model and hashes. Promotion to production needs sign-off from a named service owner, and the audit log is exported to the agency's records system each month.
When a citizen later asks to be erased, the team rebuilds the dataset, retrains and promotes the new version. When a procurement review asks whether the agency could move providers, it downloads the weights and stands them up on its own infrastructure as a test.
Own your model: built, in progress and roadmap
| Capability | Status | Notes |
|---|---|---|
| Weights stored with a sha256 manifest | Built | In the Model Vault, versioned. |
| Base model recorded per model | Built | The parent a fine-tune was built from. |
| Exportable audit log of model actions | Built | Promotions, deployments and other actions. |
| OpenAI-compatible API through Connect | Built | Applications are not written against anything only Swfte provides. |
| Local kill switch on the brain link | Built | Journalled, from the organisation side. |
| Per-object access lists on brain content | In progress | Exists as libraries; endpoints not finished. |
| Dataset export and lineage from the brain | Roadmap | Keep datasets and datasheets yourself today. |
| Consent capture and erasure-triggered retraining | Roadmap | Retraining after erasure is a manual process today. |
Legend
- Built. Exists today and can be used.
- In progress. Being built. Not yet something to rely on.
- Roadmap. Designed for and on the roadmap. Not built. No dates are given.
Where this fits in the loop
Ownership spans the custom model and its outcomes: you keep the model, the record of what it did, and the evidence that decides when it is retrained.
- 01Company brainHolds what the organisation knows, with evidence statuses, history and access rules.
- 02Custom modelAdapted on data chosen from the brain, then evaluated and hardened before it ships.(this page)
- 03Governed agentsUse the model and read the brain, inside a Trust Profile, with approval where it matters.
- 04OutcomesWhat happened: approvals, corrections, results and cost, all on the record.(this page)
The four arrows
- Company brain to Custom model: select, sanitise, adaptRoadmap
Choose training data from the brain, remove what must not reach a model, adapt an open-weight base. The sanitisation gateway is in progress, and the data selection and training steps are on the roadmap.
- Custom model to Governed agents: serve, governBuilt
Serve the model on dedicated infrastructure behind the Connect gateway and bring agents onto it under policy. Model hosting and the gateway are built.
- Governed agents to Outcomes: act, recordBuilt
Agents act within their Trust Profile, with human approval for consequential steps, and every action is recorded.
- Outcomes to Company brain: written back as evidenceRoadmap
Outcomes return to the brain as new evidence with a status, and they decide when the model needs retraining. The write-back is on the roadmap.
Legend
- Built. Exists today and can be used.
- In progress. Being built. Not yet something to rely on.
- Roadmap. Designed for and on the roadmap. Not built. No dates are given.
Frequently asked questions
What do we own when we build a custom model on Swfte?
Your weights or adapter, your training data, your evaluation sets and the lineage record that ties them together. You do not own the base model, whose maker licensed it to you, and its licence still applies to anything derived from it.
Can we take our model to another provider?
Weights stored in the Model Vault can be downloaded with their hash manifest and served anywhere that can run them. Connect uses an OpenAI-compatible API, as do common serving engines. The contractual exit and export terms are not yet published.
Does the base model licence still apply to our fine-tune?
Yes. A fine-tune or adapter is a derivative of the base weights, and the base licence follows it. Read the licence file for the exact checkpoint, record the revision, and have counsel review it. As a recommendation, permissive licences such as Apache 2.0 or MIT keep more options open.
What happens to our model if someone asks to be erased?
Current methods cannot reliably remove one person from trained weights. Rebuild the dataset without their records, retrain, evaluate and promote the new version, then retire the old one. Erasure-triggered retraining is designed for and on the roadmap; today it is a manual process.
Who can deploy or promote our model?
Your organisation decides. Deploying and promoting are separate steps in the Model Vault, and each is written to an audit log you can export. Pair that with a named approver for each stage and an evidence pack for production.
Is a model we own on Swfte automatically compliant?
No product makes a model compliant by itself, and Swfte does not claim it. Swfte provides technical controls, governance mechanisms and evidence that help an organisation meet its own obligations; the posture depends on use case, jurisdiction, deployment and configuration, and on your own legal assessment.
Is owning a model cheaper than using an API?
Not always. Ownership adds data preparation, evaluation, training, dedicated serving and retraining. It tends to pay off for narrow, high-volume tasks where control and data location matter. For occasional use, a governed general model is usually the cheaper choice.
Take own your model further with Swfte
Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.