What is CrowdStrike SafeMind?
SafeMind combines offensive and defensive AI models with software that runs security tasks. Here is how Red Tempest, Blue Solano and the testing loop fit together.
In brief: SafeMind is CrowdStrike’s system of specialised AI models and software for running offensive and defensive security work. It pairs agents that find attack paths with agents that develop and test protections. CrowdStrike introduced it on 1 September at Fal.Con 2026. The SafeMind announcement
Two models with different jobs
Red Tempest is the offensive model. It is designed to emulate adversary techniques and explore ways an attack could succeed. Blue Solano is the defensive model, intended to identify gaps and develop protections. CrowdStrike explains both roles in its official demonstration, published on 2 September. SafeMind video and description
The software that puts the models to work
SafeMind also includes agent harnesses: the software that supplies a model with tools, context, memory and permissions, and coordinates its tasks. This is what connects a model’s output to a working security process. How CrowdStrike describes the harnesses
NVIDIA describes defensive models based on its Nemotron models, adapted using CrowdStrike’s security data. That partnership includes the models and computing infrastructure; SafeMind’s cybersecurity harnesses and security context come from CrowdStrike. NVIDIA’s explanation of SafeMind
Repeated testing in a representative environment
NVIDIA and CrowdStrike describe an evaluation in an isolated environment modelled on NVIDIA infrastructure. Offensive agents produced attack activity; defensive agents used the resulting telemetry to create and validate detections. Further attacks tested the protections again. This repeated exchange is what the companies call adversarial coevolution.
That is a controlled evaluation, not evidence that SafeMind can prevent every attack in a production network. Its results depend on the environment, tasks and model configuration being tested. NVIDIA’s technical account of the evaluation
SafeMind alongside Guardian and Agentic IdP
The related products address different parts of AI security. Falcon Guardian monitors and controls AI use and agent activity. Agentic Identity Provider establishes agent identities for access decisions. SafeMind applies AI to security work itself. Our Fal.Con Las Vegas roundup puts the three announcements together.