AI Security

Aikido ships Altar. Open-weight security AI that runs inside the fence.

Sep 21 release. Pruned GLM-5.3 MoE → 328 GB for on-prem / air-gapped pentest. Solves residency, not “can AI find vulns.” Cisco Foundation-Sec and WhiteRabbitNeo already play open-weight — different lanes.

Sep 22, 2026 · 5 min read

Frontier models can find vulns. Regulated buyers still cannot send code to someone else’s API. Aikido just published the weights for that gap.

On September 21 Aikido introduced Altar / Altar-1, billed as its first open-weight security model — built to bring frontier-grade defensive security into infrastructure you control (Aikido blog by Selim Decamps & Tiburce Gridello). Altar powers Aikido Machine, the company’s autonomous pentesting appliance that runs inside customer infrastructure, including air-gapped environments. The product argument is residency: keep source, architecture notes, and unremediated findings on-prem while still running agentic AppSec.

Compression math is the underwrite core — and it is company-sourced. Base: Z.AI GLM-5.3 MoE. Full BF16 ~1,506.7 GB → AWQ INT4 ~488.2 GB → Altar pruned W4A16 328.0 GB (78.2% vs BF16; 32.8% vs AWQ). Altar retains 168 of 256 routed experts (removed 88 / 34.4%). Router still picks 8 per token. Pruning used Cerebras REAP; calibrated on pentest harness traces plus multilingual text; no customer data in calibration (company). Serve target: 4× H200 with vLLM. Weights: AikidoSec/altar-1 on Hugging Face.

Internal CVE rediscovery harness (company): 32 known vulns across 30 repos. Altar ~60.4% avg recall; quantized GLM-5.3 AWQ ~61.5%; full GLM-5.3 ~65.6%. Altar covered 23 of 32 at least once; kept 23 of the parent’s 25 covered vulns (~92% coverage at ~33% less storage vs the AWQ parent). Aikido also says Altar found a critical in a client production pentest after fleet deploy — label that as Aikido-reported, not independently verified here.

Valuation: CNA (Sep 21) says Aikido reached a $1B valuation in January 2026 (per CNA). Revenue and later marks: Undisclosed. CyberMerge prints what primary coverage states.

License nuance: open-weight on a GLM-5.3 lineage. Secondary coverage notes a high-revenue MaaS review clause from Z.AI — treat that as a license-condition nuance, not “fully unrestricted OSS.” Downloadable weights ≠ public-domain cyber kit.

Competitive lanes already exist. Cisco Foundation AI ships Foundation-Sec-8B / Instruct / Foundation-Sec-8B-Reasoning — open-weight Llama 3.1 8B lineage; Reasoning public around Jan 28, 2026 — a small reasoning model for threat modeling, investigation, and vuln analysis. Different thesis: portable 8B, not a 328 GB MoE prune. WhiteRabbitNeo (Kindo-backed open project) publishes uncensored Llama/Qwen cyber models on Hugging Face for offensive + defensive work — red-team lane. CrowdStrike and peers mostly wrap partner open models (e.g. NVIDIA Nemotron inside Charlotte AI AgentWorks) inside cloud platforms — they consume open weights; they do not ship a branded downloadable cyber model for you to self-host alone.

POV: Three open-weight cyber lanes — Cisco (small general security reasoning), WhiteRabbitNeo (uncensored adversary-style), Aikido (frontier MoE compressed for sovereign agentic AppSec). Altar is a distribution and trust wedge for regulated buyers blocked by SaaS AI — not a mid-market laptop story (4× H200). Dual-use risk rises when capable offensive reasoning is downloadable. Underwrite: residency + harness → reproducible findings — or weights theater?

Underwrite sheet — sourced only: Altar / Altar-1 open-weight security model (Aikido Sep 21); powers Aikido Machine incl. air-gap (company); GLM-5.3 MoE → BF16 1,506.7 GB → AWQ 488.2 GB → Altar W4A16 328.0 GB; 168/256 experts; REAP; no customer data in calibration (company); serve 4× H200 + vLLM; HF AikidoSec/altar-1; internal CVE harness 60.4% recall vs 65.6% full parent; 23/32 coverage; critical in client prod = Aikido-reported; $1B Jan 2026 valuation (CNA Sep 21); revenue Undisclosed; Cisco Foundation-Sec-8B-Reasoning and WhiteRabbitNeo are peer open-weight lanes, different bets. Sovereign AppSec inference — or weights for the RFP?

Sources