Product1 distinct publisher3 min readPublished
CrowdStrike's SafeMind pairs an offensive model, Red Tempest, with a defensive one, Blue Solano, and puts both inside Falcon. The budget question that follows is who authorises the attack side and reviews what it does.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Start with the scheduling problem. Red Tempest is built to emulate AI-driven adversaries and run advanced attack scenarios against an environment [2], so somebody picks the environment, picks the window, and holds the stop button. That person is rarely the one who approved the line item.
Blue Solano is the other half, applying the containment measures CrowdStrike responders use on live incidents [2]. The harnesses can pit the two models against each other in a closed loop so each improves, and they also drive frontier and open-source models from other providers [3]. Inside a closed loop, containment actions are training signal. Inside a live estate, they are tickets landing on people who never read the press release.
The provenance matters. Both models sit on Nvidia's open Nemotron family and were trained on Falcon sensor telemetry, threat intelligence, the annotations Falcon Complete analysts attach to confirmed detections, and fifteen years of incident response fieldwork [5]. The lab behind them runs on telemetry from sensors deployed in customer environments, reporting from endpoints, identity systems, cloud workloads, data stores and Falcon Next-Gen SIEM at trillions of events a day [8]. Customer data trains both the defender and the attacker.
Then there are the numbers. CrowdStrike says SafeMind posted a 29% higher detection rate, remediated six times faster end to end, and cut detection and remediation costs by 99%, measured against leading frontier models and open-source baselines [9]. The release named none of those baselines and described no methodology [10]. Take the two figures together and the claim is roughly 129 times more detections per dollar: 1.29 times the detection rate at one hundredth of the cost [1]. That is a benchmark artefact, not something you can put in a spreadsheet next to a headcount.
Jensen Huang, whose company is the AI design partner on the work, said cyber defense will rank among the most compute-intensive applications of AI [12], and CoreWeave supplied the cloud capacity for both training and inference [6]. Inference is the part you pay for every cycle. Set that beside a 99% cost reduction and the buyer is being asked to believe two things at once.
There is also a lock-in question. Bartley Richardson, who runs the new Cyber Superintelligence Lab, said CrowdStrike is the only company that owns the entire stack, from sensor to harness to model [14]. But the harnesses drive other vendors' models too [3]. If that holds, the durable dependency is the harness and the telemetry feeding it, not Red Tempest specifically.
This is a forcing function for Monday. Put your intended use in one of four boxes, on two axes: production estate or replica, and findings land in a queue with a named owner or findings land in a report. Replica plus report is an exercise, and it tells you about the model rather than your controls. Replica plus queue is where most teams should start, because the failure mode is a wasted quarter rather than a wasted weekend. Production plus queue is the version worth real money, and it needs an authorisation path and a rollback before the first run. Production plus report is the cell that generates risk and closes nothing.
Whichever box you pick, the number to track is not scenarios executed, which is what any dashboard will happily show you. Track the share of findings that produced a shipped control change, and the days between the finding and that change. Dave Vellante, the SiliconANGLE analyst quoted in the launch coverage, compared the approach to an AI security version of Netflix's Chaos Monkey [13]. Chaos Monkey was useful because engineers fixed what it broke, and someone owned the fixing.
Ranked by verification strength, evidence, and original report placement.
CrowdStrike Holdings Inc. launched SafeMind, a family of AI models and agent harnesses created with Nvidia Corp. and built for security work rather than general use, announced at its Fal.Con conference in Las Vegas.
SafeMind launches with two models: Red Tempest, the offensive one, built to emulate AI-driven adversaries and run advanced attack scenarios against an environment; and Blue Solano, which plays defense by applying the containment measures CrowdStrike responders use on live incidents.
The harnesses run both models in a closed loop that pits one against the other so each improves, and they also drive frontier and open-source models from other providers.
SafeMind will operate natively in the CrowdStrike Falcon platform, with standalone access to the models and harnesses handled through the Project QuiltWorks program the company started in April.
CrowdStrike built the models on Nvidia's open Nemotron family and trained them on Falcon sensor telemetry, threat intelligence, the event annotations Falcon Complete analysts attach to confirmed detections, and fifteen years of incident response fieldwork.
CoreWeave Inc. supplied cloud capacity for training and inference.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
CrowdStrike lets Snowflake customers buy Falcon out of capacity they already committed1 distinct publisher
invest
A twenty-point jump in September hike odds reprices the AI trade the earnings just validated1 distinct publisher
product
CrowdStrike cleared its own ARR guide by 17% while revenue beat by 2%1 distinct publisher
invest
Nvidia's Perplexity talks move its money one layer further from its own chips1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One issuer account, no outside check
Everything here — the model pair, the Nemotron base, the training corpus, the telemetry scale, the performance figures — comes from CrowdStrike's announcement as relayed by SiliconANGLE, with corroborating quotes from the two companies that were paid to help build it. Product facts of this kind are reasonably safe in the issuer's hands; capability and cost claims are not, and nobody outside the partnership has touched them. The score is held up mainly by SiliconANGLE stating plainly what the release left out.
Announced, not yet used by anyone
As of this reporting SafeMind exists as a launch with two delivery paths — inside Falcon, or standalone via Project QuiltWorks — and nothing more: no customers, no design partners, no pilot volumes. The trillions of events a day belong to the existing Falcon sensor fleet that trained the models, not to anything SafeMind is doing in production. The Google Cloud additions are the closest thing to real distribution, and they are integration points announced the same week.
Superlatives outrunning the arithmetic
A 29% detection uplift and a 99% cost cut multiply out to roughly 129 times more detections per dollar — an extraordinary result attached to competitors nobody named and a test nobody described. Add a research group called the Cyber Superintelligence Lab and an executive claim to be the only company owning sensor, harness and model, and the language is running well ahead of what can be checked on launch day. The gap is not maximal because the underlying product description is concrete and internally consistent, and the reporting flags the methodology hole itself.
Every voice quoted is inside the deal
Kurtz is selling the platform, Richardson runs the lab that built the models, Huang sells the compute that cyber defense will supposedly consume in bulk, Intrator rents it out, and the outside analyst framing the whole thing as a purpose-built frontier model for defenders is SiliconANGLE's own co-founder. Two more Fal.Con partner announcements ride along in the same story. That is not disqualifying — vendor conferences work this way — but there is no participant here whose interests point the other direction.
Solid on what was announced, thin on what it does
We can be fairly sure of the facts of the announcement — the two models, the Nemotron lineage, the closed-loop harness, the lab and its leadership, the Google Cloud extension — because the issuer is the authority on its own product and the reporting is specific. Confidence drops sharply the moment the story moves to effectiveness, competitive uniqueness or cost, where a single outlet is relaying unaudited numbers. Read this as a reliable record of a launch and an open question about performance.