# What is CrowdStrike SafeMind?

> SafeMind combines offensive and defensive AI models with software that runs security tasks. Here is how Red Tempest, Blue Solano and the testing loop fit together.

Source: https://fmcybersecurity.com/en/insights/ai-security/what-is-crowdstrike-safemind/
Locale: English
Other locale: https://fmcybersecurity.com/insights/ai-security/hva-er-crowdstrike-safemind/

## Metadata

- Date: 2026-09-17
- Author: kenny-le
- Topic: ai-security
- Format: article
- Partner: crowdstrike

<img src={crowdstrikeLogo.src} alt="CrowdStrike logo" width="320" height="75" style="margin: 0 0 24px; border-radius: 0; max-width: 100%;" />

**In brief:** SafeMind is CrowdStrike's system of specialised AI models and software for running offensive and defensive security work. It pairs agents that find attack paths with agents that develop and test protections. CrowdStrike introduced it on 1 September at Fal.Con 2026. [The SafeMind announcement](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-launches-frontier-models-for-cybersecurity-with-nvidia/)

## Two models with different jobs

**Red Tempest** is the offensive model. It is designed to emulate adversary techniques and explore ways an attack could succeed. **Blue Solano** is the defensive model, intended to identify gaps and develop protections. CrowdStrike explains both roles in its official demonstration, published on 2 September. [SafeMind video and description](https://www.youtube.com/watch?v=mvOiYozVwO0)

## The software that puts the models to work

SafeMind also includes agent harnesses: the software that supplies a model with tools, context, memory and permissions, and coordinates its tasks. This is what connects a model's output to a working security process. [How CrowdStrike describes the harnesses](https://www.crowdstrike.com/en-us/about-us/cyber-superintelligence-lab/)

NVIDIA describes defensive models based on its Nemotron models, adapted using CrowdStrike's security data. That partnership includes the models and computing infrastructure; SafeMind's cybersecurity harnesses and security context come from CrowdStrike. [NVIDIA's explanation of SafeMind](https://blogs.nvidia.com/blog/nvidia-crowdstrike-fal-con-2026/)

## Repeated testing in a representative environment

NVIDIA and CrowdStrike describe an evaluation in an isolated environment modelled on NVIDIA infrastructure. Offensive agents produced attack activity; defensive agents used the resulting telemetry to create and validate detections. Further attacks tested the protections again. This repeated exchange is what the companies call adversarial coevolution.

That is a controlled evaluation, not evidence that SafeMind can prevent every attack in a production network. Its results depend on the environment, tasks and model configuration being tested. [NVIDIA's technical account of the evaluation](https://developer.nvidia.com/blog/building-an-adaptive-agentic-cybersecurity-system-with-nvidia-nemotron/)

## SafeMind alongside Guardian and Agentic IdP

The related products address different parts of AI security. [Falcon Guardian](/en/insights/ai-security/what-is-falcon-guardian/) monitors and controls AI use and agent activity. [Agentic Identity Provider](/en/insights/ai-security/what-is-crowdstrike-agentic-identity-provider/) establishes agent identities for access decisions. SafeMind applies AI to security work itself. Our [Fal.Con Las Vegas roundup](/en/insights/ai-security/crowdstrike-september-2026-falcon-ai-security-news/) puts the three announcements together.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
