Hero title card for the article 'CrowdStrike SafeMind Debuts at Fal.Con'. Badge reading 'LAUNCHED SEP 1, 2026', subtitle 'The first agentic system for defenders — offensive and defensive models in one closed loop, built with NVIDIA on Nemotron', chips reading 'Red Tempest + Blue Solano', 'Ships in Falcon', 'Standalone via Project QuiltWorks', and a footer quote 'Attackers had frontier AI. Defenders didn't.' The OrcaRouter logo is composited in the bottom-right corner.
Guides & Insights

CrowdStrike SafeMind Debuts at Fal.Con: The NVIDIA-Backed Agentic Defense Stack, Built on Nemotron

Author

Gideon Frost

Date Published

Latest models · 20View all models
Benchmarks: Artificial Analysis · updated daily
Back to all posts

When CrowdStrike SafeMind shipped at Fal.Con 2026 in Las Vegas, George Kurtz spent the keynote's sharpest moment on the gap behind it: the attackers had frontier AI, and the defenders didn't. SafeMind is CrowdStrike's attempt to close that gap — a family of purpose-built security models and agentic harnesses built with NVIDIA on the open NVIDIA Nemotron base, announced September 1, 2026, and now operating natively inside the CrowdStrike Falcon platform. The number doing the rounds from the keynote is that the fastest eCrime breakout time has fallen to 27 seconds, and AI-enabled attacks rose 89% in the past year — the environment SafeMind is answering, not the model's own score.

The framing CrowdStrike wants you to hold is that SafeMind is not another chatbot with a threat-intel plug-in. It is a closed loop: an offensive model that finds the attack path, a defensive model that closes it, and harnesses that operate both against the same telemetry. NVIDIA is the AI design partner, providing the open Nemotron foundation models and full-stack accelerated compute; CoreWeave's AI Cloud handles training and inference. Because Nemotron is open, CrowdStrike says it post-trained on its own threat data without sending that data to an outside model provider.

A generated infographic titled 'The SafeMind coevolution loop'. A circular flow diagram with four stages: 'Red Tempest finds the attack path' → 'Blue Solano closes it' → 'Falcon telemetry records the result' → 'Both models retrain and improve'. A center badge reads 'Continuous coevolution — offense and defense until the attack is unsuccessful'. A footer reads 'Red Tempest (offensive) · Blue Solano (defensive) · Built on NVIDIA Nemotron'. The OrcaRouter logo is composited in the bottom-right corner.

Two models, one loop

SafeMind launches with two model releases. Red Tempest is the offensive half — a red-team model built for advanced attack scenarios, emulating AI-driven adversaries. Blue Solano is the defensive half — built to protect enterprise assets by deploying the battle-tested measures defenders use in real incidents. In NVIDIA's description of the internal testing, the red-team harness runs Recon, Assault, and Compromise sub-agents that execute attack paths, while the blue-team harness watches through Falcon sensors, generates detection candidates, validates them, and promotes the validated ones into actionable detections.

The technical base matters because it is open. NVIDIA's Nemotron 3 Ultra orchestrates the defensive agent harness; a fine-tuned Nemotron 3 Super powers SafeMind's rule-generation sub-agent. CrowdStrike's contribution is the layer nobody else has: training data drawn from Falcon sensor telemetry — which CrowdStrike calls the world's largest pure-play cyber dataset — plus its threat intelligence, Falcon Complete MDR event annotations, and fifteen years of incident-response fieldwork.

The claims — and the honesty label

Against "leading frontier models and open-source baselines," CrowdStrike reports SafeMind delivers a 29% higher detection rate, 6x faster end-to-end remediation, and 99% cost savings on detection and remediation. NVIDIA separately says its internal evaluations showed the Blue Solano model, based on Nemotron 3 Super, reaching higher accuracy than leading frontier models at 99% lower cost. Every one of those numbers is vendor-reported. SafeMind has no public weights, no self-serve API, and — as of this writing — no appearance on any independent benchmark leaderboard, so there is no third-party run to check the claims against yet. The honest read: strong internal results, no external verification, priced inside the Falcon platform rather than disclosed per token.

Who can actually use it

There are two doors into SafeMind, and neither is an API key. The first is the Falcon platform itself, where SafeMind operates natively as part of the security cloud — for existing CrowdStrike customers, that is the productized path. The second is Project QuiltWorks, the program that will provide trusted access to the standalone models and harnesses for independent use, operationalized through Falcon IQ, which CrowdStrike describes as agentic workload automation running inside Charlotte AI AgentWorks with 50+ agents. What is not happening today is a public endpoint, and CrowdStrike has not published pricing for standalone access.

That leaves a concrete decision for a security team that wants this capability class now, without waiting out a trusted-access program. The general-purpose frontier models that carry the security workloads are already callable through a single API at provider list price, passed through with zero markup — which is the entire point of a routing layer like OrcaRouter. Claude Opus 5 and GPT-5.6 Sol are live at $5.00 and $4.00 per million input tokens, and Gemini 3.5 Flash at $1.50, with automatic failover between providers so a triage pipeline does not stall on a single vendor's outage. None of that replaces SafeMind's Falcon-native loop — but for detection and triage generation on code you can actually send it today, it is the difference between working with the model class now and waiting.

A screenshot of the CrowdStrike press release page titled 'CrowdStrike Launches Frontier Models for Cybersecurity, Created with NVIDIA', captured September 2, 2026, showing the announcement headline, the Fal.Con 2026 and Las Vegas dateline, and the opening paragraphs describing SafeMind as a family of purpose-built security models and harnesses.

What to watch

• The first independent benchmark run. The 29% / 6x / 99% figures are the whole sales story, and they are unverified. A third-party CyberGym-style evaluation would settle the question of how a defense specialist trained on real telemetry compares to the frontier cyber models now being benchmarked publicly.

• Project QuiltWorks access terms. Who qualifies, what surface the standalone models get, and what pricing looks like will determine whether SafeMind stays a Falcon feature or becomes a genuine third-party option.

• The coevolution loop's real output. The continuous offense-versus-defense retraining is the most novel claim in the launch; watch for published detection candidates or vulnerability findings that were produced by the loop rather than by human researchers.

• How CrowdStrike's partners react. SafeMind arrives in a market where OpenAI, Google, Microsoft, and Anthropic all ship gated cyber models — and where CrowdStrike itself is a named early partner in OpenAI's Daybreak program. Whether that partnership survives a rival product family is a real question for 2027.

The launch is genuinely new — a productized agentic defense stack, built on open Nemotron, inside the largest endpoint security install base in the industry. What remains to be proven is the part that matters most: whether the loop actually produces better detection at the claimed cost, and whether the industry will get to verify it independently. Until then, the practical route to the model class is the open frontier models you can call today, and the route to SafeMind itself runs through Falcon.

A screenshot of the Artificial Analysis Intelligence Index leaderboard (captured September 2, 2026) showing Claude Fable 5.1 (max with fallback) at index 66 and Claude Fable 5.1 (high with fallback) at index 65 at the top, followed by Claude Opus 5 (max) and Claude Opus 5 (xhigh) at index 63, each with a 1M-token context window and cost-per-task figures. CrowdStrike SafeMind does not appear — it is not on any public leaderboard.
© 2026 OrcaRouter

For Providers

Run an inference platform? Get your models on OrcaRouter.

providers@orcarouter.ai

Join our community

Discordsupport@orcarouter.aiXGitHubYouTube