Frontier models can find vulns. Regulated buyers still cannot send code to someone else’s API. Aikido just published the weights for that gap.
On September 21 Aikido introduced Altar / Altar-1, billed as its first open-weight security model — built to bring frontier-grade defensive security into infrastructure you control (Aikido blog by Selim Decamps & Tiburce Gridello). Altar powers Aikido Machine, the company’s autonomous pentesting appliance that runs inside customer infrastructure, including air-gapped environments. The product argument is residency: keep source, architecture notes, and unremediated findings on-prem while still running agentic AppSec.
Compression math is the underwrite core — and it is company-sourced. Base: Z.AI GLM-5.3 MoE. Full BF16 ~1,506.7 GB → AWQ INT4 ~488.2 GB → Altar pruned W4A16 328.0 GB (78.2% vs BF16; 32.8% vs AWQ). Altar retains 168 of 256 routed experts (removed 88 / 34.4%). Router still picks 8 per token. Pruning used Cerebras REAP; calibrated on pentest harness traces plus multilingual text; no customer data in calibration (company). Serve target: 4× H200 with vLLM. Weights: AikidoSec/altar-1 on Hugging Face.
Internal CVE rediscovery harness (company): 32 known vulns across 30 repos. Altar ~60.4% avg recall; quantized GLM-5.3 AWQ ~61.5%; full GLM-5.3 ~65.6%. Altar covered 23 of 32 at least once; kept 23 of the parent’s 25 covered vulns (~92% coverage at ~33% less storage vs the AWQ parent). Aikido also says Altar found a critical in a client production pentest after fleet deploy — label that as Aikido-reported, not independently verified here.
Valuation: CNA (Sep 21) says Aikido reached a $1B valuation in January 2026 (per CNA). Revenue and later marks: Undisclosed. CyberMerge prints what primary coverage states.
License nuance: open-weight on a GLM-5.3 lineage. Secondary coverage notes a high-revenue MaaS review clause from Z.AI — treat that as a license-condition nuance, not “fully unrestricted OSS.” Downloadable weights ≠ public-domain cyber kit.
Competitive lanes already exist. Cisco Foundation AI ships Foundation-Sec-8B / Instruct / Foundation-Sec-8B-Reasoning — open-weight Llama 3.1 8B lineage; Reasoning public around Jan 28, 2026 — a small reasoning model for threat modeling, investigation, and vuln analysis. Different thesis: portable 8B, not a 328 GB MoE prune. WhiteRabbitNeo (Kindo-backed open project) publishes uncensored Llama/Qwen cyber models on Hugging Face for offensive + defensive work — red-team lane. CrowdStrike and peers mostly wrap partner open models (e.g. NVIDIA Nemotron inside Charlotte AI AgentWorks) inside cloud platforms — they consume open weights; they do not ship a branded downloadable cyber model for you to self-host alone.
POV: Three open-weight cyber lanes — Cisco (small general security reasoning), WhiteRabbitNeo (uncensored adversary-style), Aikido (frontier MoE compressed for sovereign agentic AppSec). Altar is a distribution and trust wedge for regulated buyers blocked by SaaS AI — not a mid-market laptop story (4× H200). Dual-use risk rises when capable offensive reasoning is downloadable. Underwrite: residency + harness → reproducible findings — or weights theater?
Underwrite sheet — sourced only: Altar / Altar-1 open-weight security model (Aikido Sep 21); powers Aikido Machine incl. air-gap (company); GLM-5.3 MoE → BF16 1,506.7 GB → AWQ 488.2 GB → Altar W4A16 328.0 GB; 168/256 experts; REAP; no customer data in calibration (company); serve 4× H200 + vLLM; HF AikidoSec/altar-1; internal CVE harness 60.4% recall vs 65.6% full parent; 23/32 coverage; critical in client prod = Aikido-reported; $1B Jan 2026 valuation (CNA Sep 21); revenue Undisclosed; Cisco Foundation-Sec-8B-Reasoning and WhiteRabbitNeo are peer open-weight lanes, different bets. Sovereign AppSec inference — or weights for the RFP?
