CUSTOM CYBERSECURITY MODEL ENGINEERING
Custom cybersecurity models, built around the mission.
Blackfrost fine-tunes and post-trains smaller open-weight models for defined defensive workflows and controlled agentic systems. Each engagement starts with the task, authority boundary, target environment, and evidence required for acceptance.
Mission-specific post-trainingArtifact-level evaluationCustomer-controlled deployment
TWO DISTINCT ENGAGEMENTS
Change the model—or build the system that runs it.
Custom Models changes behavior and produces the artifacts and evidence named in the scope. Scalable Hosting turns selected weights into a serving system. The two can be commissioned together, but neither is bundled with a Model Store purchase.
01 / CUSTOM MODELSEngineer behavior for a defined defensive workflow.
We select an open-weight foundation, construct the permitted data path, fine-tune or post-train the candidate, optimize the artifact where required, and evaluate it against the agreed task—not a generic benchmark alone.
The path can include supervised fine-tuning, preference optimization, distillation, quantization, and runtime-aware packaging. Directional Weight Modification means controlled behavioral tuning toward a defined operating band with retained or protected floors. Method follows the requirement.
Prepare a custom-model brief →02 / SCALABLE HOSTINGBuild a private serving system around selected weights.
We translate the artifact, traffic shape, hardware, security boundary, and operating responsibility into a scoped runtime, API, deployment, scaling, observability, and handoff plan.
Hosting is a separate engineering engagement. Ongoing operations, support coverage, and service-level commitments apply only when they are explicitly contracted.
Explore the hosting service → WORK DEFENDERS CAN NAME
Start with the security job, not the training technique.
These are examples of custom engagement scopes—not claims about every catalog release. Final tasks, evidence sources, authority, and acceptance criteria are agreed before engineering begins.01Incident investigation
Shape evidence synthesis, timeline construction, hypothesis tracking, and source-aware reporting around the telemetry your defenders actually use.
02Detection engineering
Train structured reasoning around detection logic, ATT&CK-informed analysis, test cases, false-positive assumptions, and analyst review.
03Threat and artifact analysis
Adapt behavior for authorized malware review, indicator enrichment, threat research, secure-code review, and vulnerability triage.
04Controlled security agents
Improve planning, tool selection, state tracking, structured action, recovery, and human-approval behavior within a named authority boundary.
THE VOID / CUSTOM-MODEL METHOD
Post-training inside the engagement—not a standalone product.
The Void uses training signal from permitted De-Risked frontier teachers with deliberately reduced or, where the authorized mission requires it, removed refusal behavior. The goal is better completion on legitimate cybersecurity work. De-Risked describes the data objective; it does not mean risk-free, grant authority, or replace access controls.- 01
Define
Name the authorized tasks, data rights, target environment, failure modes, and evidence required for acceptance.
- 02
Construct
Build permitted training and evaluation data around the mission, including the intended refusal profile and protected boundaries.
- 03
Post-train
Select the foundation and apply the agreed fine-tuning, preference, distillation, weight-space, or optimization method.
- 04
Evaluate
Test the exact candidate against the named protocol, compare it with the baseline, and document limits and tradeoffs.
POTENTIAL DELIVERABLES · AS NAMED IN SCOPE
Versioned artifacts and evidence—not a mystery handoff.
- Weights or adapter, tokenizer, and configuration
- Model card, release manifest, and provenance summary
- Baseline-versus-candidate evaluation report, including scoped adversarial testing where agreed
- Releasable test materials and serving guidance
Deliverables follow the signed statement of work. Production hosting, application integration, ongoing monitoring, operations, and SLAs are separate unless they are explicitly included.
SCALABLE HOSTING / SEPARATE ENGAGEMENT
When the weights need to become a service.
Hosting begins with a named artifact and a real workload profile. Architecture follows capacity, access, data handling, availability, and operating constraints—not a one-size-fits-all stack.- Capacity + topology
- Model footprint, traffic shape, context, resilience, hardware, storage, and network requirements.
- Runtime + API
- Precision, parallelism, batching, cache behavior, service interface, health checks, and release automation.
- Security + observability
- Identity, network, secrets, data handling, audit, request flow, saturation, and failure visibility.
- Validation + handoff
- Agreed load cases, tested configuration, known limits, rollback, runbooks, and operating ownership.
START WITH THE DEFENSIVE WORKFLOW
Define the mission. We'll scope the engineering.
Tell us what the model must do, what it may access, where it must run, and what evidence will count. We will separate the model work, hosting work, and optional integration clearly.Prepare an engineering brief →