On 1 September 2026, CrowdStrike introduced SafeMind at Fal.Con in Las Vegas. The company describes it as a family of purpose-built security models and harnesses from its Cyber Superintelligence Lab. The agentic system will run natively in the Falcon platform. Trusted access for standalone models and harnesses is part of Project QuiltWorks.
NVIDIA is the named AI design partner. CrowdStrike says it builds the models on NVIDIA Nemotron open models, with CoreWeave’s AI Cloud for training and inference. For teams that already shortlist CrowdStrike, this is a product-surface change on Falcon, not a reason to drop ChatGPT, Claude, or Gemini from a general assistant row.
What CrowdStrike says shipped: two models, one loop, Falcon as the home
CrowdStrike’s press release splits SafeMind into an offensive model that finds an attack path, a defensive model that closes it, and harnesses that run both in the same loop. The company says training data comes from Falcon sensor telemetry, CrowdStrike threat intelligence, Falcon Complete MDR event annotations, and fifteen years of incident-response fieldwork.
- Red Tempest: CrowdStrike’s offensive red-team model, described as built for advanced attack scenarios and for emulating AI adversaries.
- Blue Solano: CrowdStrike’s defensive blue-team model, described as built to protect enterprise assets with measures defenders use in production.
- Harnesses: CrowdStrike says they operationalize both models in a closed loop, and that they can also work with other frontier and open-source models.
- Where it runs: native in Falcon. Standalone model and harness access is a QuiltWorks trusted-access path, not a self-serve API the press release prices.
NVIDIA’s Fal.Con post adds model names inside that stack. It says NVIDIA Nemotron 3 Ultra orchestrates the defensive agent harness, and a fine-tuned Nemotron 3 Super powers SafeMind’s rule-generation sub-agent. The same post says CrowdStrike also announced Falcon IQ, which operationalizes Project QuiltWorks through agentic workload automation, and expanded Guardian, CrowdStrike’s AI safety product.
The 29 percent, 6x, and 99 percent figures are CrowdStrike evaluations
CrowdStrike published three comparisons against “leading frontier models and open-source baselines.” Those are company evaluations. They are not an independent audit, and the release does not name the comparison models or publish a reproduction package.
- 29 percent higher detection rate, per CrowdStrike.
- 6 times faster end-to-end remediation, per CrowdStrike.
- 99 percent cost savings on detection and remediation, per CrowdStrike.
NVIDIA’s blog repeats a narrower internal claim: after post-training Nemotron on CrowdStrike data, CrowdStrike’s evaluations showed Blue Solano, based on Nemotron 3 Super, delivered higher accuracy than leading frontier models at 99 percent lower cost. That is the same vendor family of numbers, restated for one model. Keep it labeled.
Why this is not a ChatGPT, Claude, or Gemini replacement
CrowdStrike and NVIDIA are selling a security stack that stays inside Falcon telemetry and CrowdStrike’s harness. George Kurtz, quoted by NVIDIA, said the gap he saw was attackers with frontier AI and defenders without it. Jensen Huang, on the same stage, framed cyber defense as one of the most compute-intensive uses of AI. Those are speeches. They do not make SafeMind a general coding agent.
- If the job is endpoint, identity, and cloud detection on a Falcon estate, score SafeMind and Falcon IQ on that estate.
- If the job is repository work, keep Claude Code, OpenAI Codex, and Google Antigravity on the coding-agent shortlist.
- If the job is a gated cyber model from a frontier lab, use the Daybreak, Mythos, and Fairwind playbook. QuiltWorks is CrowdStrike’s trusted-access path, not a substitute for those lab programs.
- If the job is an open model hub, that is the NVIDIA and Hugging Face agreement, a different NVIDIA story from the same week.
NVIDIA also wrote that AI-enabled attacks rose 89 percent in the past year and that the fastest eCrime breakout time has reached 27 seconds, attributing those figures to CrowdStrike. Treat both as CrowdStrike-stated threat metrics. They explain why the company wants machine-speed response. They do not tell you whether SafeMind will do that on your tenants.
What to ask before you add SafeMind to a Falcon renewal
A Falcon customer can treat this as a platform update. A team that is not on Falcon cannot treat QuiltWorks as a public model API. Ask for paper, then run a proof on systems you already own.
- Ask which SafeMind features land in your Falcon SKU this quarter, and which stay behind QuiltWorks approval.
- Ask whether Red Tempest can run only against assets you authorize, who approves that scope, and how the run is logged.
- Ask how Blue Solano detections become Falcon detections you can export to your SIEM, and who can promote or reject them.
- Ask CrowdStrike to restage the 29 percent, 6x, and 99 percent claims on a dataset you recognize, or to withdraw them from the sales deck.
- Ask whether Falcon IQ’s “more than 50 agents,” as NVIDIA reported, can change production controls without a human gate.
- If you also use a lab model for secure review, keep that work on the agent-security checklist and do not fold it into a Falcon checkbox.
