Aikido Releases Altar-1: Open-Weight Defensive AI for Sovereign Security

Aikido Security has unveiled Altar-1, its first open-weight defensive AI model. Built on GLM-5.3 and compressed to 328 GB, it powers on-premise vulnerability au

tau · September 27, 2026

#AikidoSecurity #Altar1 #OpenWeight #Cybersecurity #OnPremise #LLM

Aikido Releases Altar-1: Open-Weight Defensive AI for Sovereign Security

Cybersecurity startup Aikido Security officially announced Altar-1 (Aikido Altar), its first open-weight defensive AI model designed to run inside self-hosted enterprise infrastructure, on its official engineering blog on September 21, 2026, followed by an announcement on X (@AikidoSecurity) on September 22. Built specifically to eliminate cloud data leakage during vulnerability analysis and pentesting, Altar-1 enables enterprises to retain complete data sovereignty over unpatched security reports and proprietary codebases.

Aikido Security Altar-1 open-weight defensive cybersecurity AI model announcement visual

Image source: Aikido Security

GLM-5.3 Base, W4A16 Compression, and Sovereign Infrastructure

When enterprise security teams adopt commercial cloud LLM APIs for vulnerability analysis, the primary obstacle is data sovereignty and exposure risk. Transmitting unpatched zero-day vulnerability reports, internal network diagrams, and proprietary source code to external third-party inference endpoints introduces serious compliance violations and intellectual property exposure.

Altar-1 was engineered from the ground up to operate reliably inside on-premise, air-gapped environments disconnected from the public internet. The model is built on Z.AI's frontier open model, GLM-5.3. Aikido Security calibrated the weights against real-world security traces, secure coding patterns, tool-calling sequences, and multilingual text.

The foundation model was compressed down to 328 GB through aggressive pruning and W4A16 weight quantization. It provides a massive native context window of 131,072 tokens (128k/131k), allowing security analysts to pass extensive source repositories, multi-file codebases, and comprehensive static analysis (SAST) logs into a single prompt for contextual vulnerability triage.

CVE 60.4% Recall and Integration with Aikido Machine

Altar-1 is targeted directly at operational security triage and penetration testing automation rather than generic conversational tasks. Calibrated on cybersecurity traces, code, and tool-calling sequences, Altar-1 achieved a 60.4% CVE Recall rate, reflecting its focus on identifying exploitable vulnerabilities and bridging the gap between raw static analysis flags and actionable attack paths.

Aikido Security confirmed that the model directly powers Aikido Machine, the company's autonomous pentesting appliance designed to operate entirely within a customer's own infrastructure, including fully air-gapped networks. For organizations unable to transmit source code, architecture documentation, or unremediated security findings to third-party inference services, this architecture enables sovereign vulnerability discovery without sensitive data leaving internal boundaries.

By leveraging dedicated tool-calling and security trace calibrations, Altar-1 is built to support defensive pipelines, assisting security teams with automated false-positive filtering, exploit feasibility verification, and local remediation guidance.

vLLM Deployment Specs and Infrastructure Prerequisites

The complete model weights for Altar-1 are publicly available for download on Hugging Face under the repository AikidoSec/altar-1. It natively integrates with the open-source vLLM inference engine, where it can be registered under the model serving identifier aikido/altar-1 to connect directly with internal security orchestrators and agent frameworks.

Engineering organizations planning on-premise deployment must account for substantial hardware requirements. Running the 328 GB model requires enterprise-grade hardware, specifically a single node equipped with at least four Hopper-architecture GPUs (NVIDIA H100 or H200). It cannot be hosted on consumer hardware or smaller single-GPU workstations.

Additionally, while weights are freely accessible, Altar-1 is not currently hosted as a managed endpoint in commercial API routing catalogs such as RouterPlex, requiring organizations to maintain their own private GPU clusters.

Sources