For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/what-is-crowdstrike-safemind.md.
AI Security ↗

What is CrowdStrike SafeMind?

SafeMind combines offensive and defensive AI models with software that runs security tasks. Here is how Red Tempest, Blue Solano and the testing loop fit together.

CrowdStrike logo

In brief: SafeMind is CrowdStrike’s system of specialised AI models and software for running offensive and defensive security work. It pairs agents that find attack paths with agents that develop and test protections. CrowdStrike introduced it on 1 September at Fal.Con 2026. The SafeMind announcement

Two models with different jobs

Red Tempest is the offensive model. It is designed to emulate adversary techniques and explore ways an attack could succeed. Blue Solano is the defensive model, intended to identify gaps and develop protections. CrowdStrike explains both roles in its official demonstration, published on 2 September. SafeMind video and description

CrowdStrike diagram with offensive Red Tempest on the left, defensive Blue Solano on the right, and a shared learning loop between them.
CrowdStrike’s illustration of SafeMind: Red Tempest and Blue Solano work in a repeated attack-and-defence loop. © CrowdStrike. Source: CrowdStrike Cyber Superintelligence Lab. Open SafeMind diagram at full size ↗
CrowdStrike's official SafeMind demonstration, published 2 September 2026. Watch on YouTube ↗

The software that puts the models to work

SafeMind also includes agent harnesses: the software that supplies a model with tools, context, memory and permissions, and coordinates its tasks. This is what connects a model’s output to a working security process. How CrowdStrike describes the harnesses

NVIDIA describes defensive models based on its Nemotron models, adapted using CrowdStrike’s security data. That partnership includes the models and computing infrastructure; SafeMind’s cybersecurity harnesses and security context come from CrowdStrike. NVIDIA’s explanation of SafeMind

Repeated testing in a representative environment

NVIDIA and CrowdStrike describe an evaluation in an isolated environment modelled on NVIDIA infrastructure. Offensive agents produced attack activity; defensive agents used the resulting telemetry to create and validate detections. Further attacks tested the protections again. This repeated exchange is what the companies call adversarial coevolution.

That is a controlled evaluation, not evidence that SafeMind can prevent every attack in a production network. Its results depend on the environment, tasks and model configuration being tested. NVIDIA’s technical account of the evaluation

SafeMind alongside Guardian and Agentic IdP

The related products address different parts of AI security. Falcon Guardian monitors and controls AI use and agent activity. Agentic Identity Provider establishes agent identities for access decisions. SafeMind applies AI to security work itself. Our Fal.Con Las Vegas roundup puts the three announcements together.

← Back to all insights
Questions or inquiry? [email protected] Contact us →