मुख्य सामग्री पर जाएँ

SaaS AI model supply chain security checklist

SaaS AI system के models, datasets, adapters, packages और providers की सूची बनाएं, बदलाव नियंत्रित करें, inference अलग रखें और rollback तैयार करें।

इस मार्गदर्शिका में

SaaS product की AI model supply chain को कैसे सुरक्षित करें?

AI feature केवल model name पर निर्भर नहीं होता। उसकी supply chain में provider endpoints, model weights, fine-tuning adapters, embedding models, tokenizers, datasets, vector software, inference libraries, plugins और deployment images शामिल हो सकते हैं। इन components और उनके owners की सूची बनाएं, फिर production में इस्तेमाल से पहले हर source और change verify करें। भरोसेमंद cloud host होने से हर uploaded model, adapter या dependency स्वतः भरोसेमंद नहीं हो जाती।

Models और सहायक artifacts की inventory बनाएं

हर production model या API, exact provider और model identifier, उपलब्ध version या release date, region, purpose, data classification, owner और downstream feature दर्ज करें। Embedding तथा reranking models, adapters, quantized copies, tokenizers, prompts, plugins, inference runtimes और source datasets भी शामिल करें। Component hosted है या download किया जाता है, यह भी दर्ज हो ताकि सही trust boundary की समीक्षा हो।

Artifact load करने से पहले provenance और integrity जांचें

Approved source और controlled download path इस्तेमाल करें। Publisher signed release या digest देता हो तो trusted publisher channel से verify करें; उसी untrusted mirror का checksum स्वतंत्र प्रमाण नहीं है। Packages और containers scan करें, model serialization के जोखिम देखें और अज्ञात artifacts को production secrets तथा network access के बिना restricted environment में load करें।

इस बिंदु के स्रोत: LLM03:2025 Supply Chain

Feature के स्तर पर provider और vendor की समीक्षा करें

Provider security, data use और retention, service region, subprocessors, model-change notice, incident handling और exit options का मूल्यांकन करें। पुष्टि करें कि application कौन से provider features इस्तेमाल करती है और contract में क्या शामिल है। Server configuration में approved model तथा endpoint allowlist रखें ताकि user या generated prompt customer data को unreviewed destination पर न भेज सके।

AI supply chain inventory और approval
Model/artifact और versionSource और integrity evidenceData तथा privilege scopeOwner/approvalUpgrade और rollback plan
Hosted text-generation model
Embedding model या adapter
Inference package या plugin

Model और dependency changes को नियंत्रित कैसे करें?

Versions pin करें और upgrades को production change की तरह review करें

जहां स्थिर व्यवहार जरूरी हो, mutable alias से बचें; service ने कौन सा version या provider release चुना, दर्ज करें। Model, tokenizer, adapter, dependency और prompt बदलाव को synthetic data वाले non-production environment में test करें। Security, quality, latency और cost की तुलना करें और rollout से पहले जिम्मेदार owner से approval लें।

Build और deployment credentials सुरक्षित रखें

कौन artifact upload, model registry बदल, endpoint routing update या inference image deploy कर सकता है, सीमित करें। Developer और production identities अलग रखें, जहां संभव हो short-lived credentials लें और approvals log करें। Reviewed source से build और dependency versions lock करें; untrusted pull requests या notebooks को production model credentials न दें।

इस बिंदु के स्रोत: LLM03:2025 Supply ChainOWASP Cheat Sheet: authorizationOWASP Cheat Sheet: logging

Inference workloads अलग रखें और उनकी पहुंच सीमित करें

Self-hosted inference को least-privilege service identity, सीमित network egress, read-only model artifacts और resource limits के साथ चलाएं। जहां संभव हो model loading को application data plane से अलग रखें। सिर्फ पास में deploy होने के कारण model process को database credentials, host access या cloud permissions न मिलें।

AI supply chain issue कैसे पहचानें और उससे recover करें?

Upstream बदलाव और component health monitor करें

संबंधित provider और package security notices लें, model या endpoint बदलाव track करें और नए subprocessors या policy changes review करें। Unexpected output shifts, नई network calls, artifact hash mismatch, dependency alerts और बढ़ी runtime permissions पर नजर रखें। हर notice का production feature पर असर तय करने के लिए owner नियुक्त करें।

Test किया हुआ rollback और replacement path रखें

जहां license और provider terms अनुमति दें, पहले approved artifact या endpoint configuration संभालकर रखें। संदिग्ध model से traffic हटाना, credentials revoke करना, artifact quarantine और last known-good release restore करना test करें। Rollback गलती से known vulnerable package या असुरक्षित data-processing route बहाल न करे, यह भी जांचें।

Evidence रखें और प्रभावित outputs trace करें

Privacy-conscious metadata से model और artifact IDs, deployment version, provider request IDs और feature route log करें। Component compromised हो तो पता करें कि किन tenants और outputs ने उसे इस्तेमाल किया, incident owners को सूचित करें और customer तथा कानूनी commitments का पालन करें। जांच के नाम पर पूरे prompts को default से retain न करें।

SaaS AI supply chain सुरक्षा: अक्सर पूछे जाने वाले सवाल

क्या managed model API इस्तेमाल करने से supply chain risk हट जाता है?

नहीं। Hosting और patching की कुछ जिम्मेदारी provider को जाती है, लेकिन आपका service endpoint selection, provider changes, client libraries, prompts, connectors और data-processing terms पर निर्भर रहता है। Feature का पूरा path review करें।

इस बिंदु के स्रोत: LLM03:2025 Supply ChainYour data and model usage policies by endpoint

क्या SaaS team कोई भी लोकप्रिय open model download कर सकती है?

नहीं। Publisher, exact artifact, license, provenance, serialization format, dependencies, security posture और intended use जांचें। अज्ञात files को production data या credentials तक पहुंचने से पहले अलग environment में test करें।

इस बिंदु के स्रोत: LLM03:2025 Supply Chain

क्या model name किसी version को uniquely पहचानता है?

हमेशा नहीं। Provider aliases इस्तेमाल या hosted models update कर सकते हैं। Provider, endpoint, model identifier और आपके account में उपलब्ध version information दर्ज करें, और बदलाव की सूचना कैसे मिलेगी यह provider से पूछें।

AI dependency में critical issue मिले तो क्या करें?

पहले से अभ्यास किया response अपनाएं: प्रभावित features और tenants पहचानें, component या credential सीमित करें, reviewed replacement चुनें या feature disable करें, फिर traffic बहाल करने से पहले fix test करें। Customer communication असली impact और contract duties के अनुरूप रखें।