This is our first public SaaS release.
There will be rough edges.
If something breaks, tell us through the in-product messaging feature. We'll fix it as quickly as we can.
Try it at https://t.co/9xZpI31E3t
Docs: https://t.co/TFnnpYx5YZ
Today, Cracken goes self-serve.
You can now sign up and run proactive cyber on your own organization.
No demo.
No PoC gate.
No sales call.
Almost nothing in enterprise cyber can be bought this way.
π
Pricing starts at $189/month.
The subscription includes credits, with top-ups available when you need more.
For most users, that's roughly enough for 1β3 full web application assessments per month.
Annual pricing is coming soon.
Everything is evaluated safely.
All targets are inert sinkholes or reserved test addresses - nothing touches real infrastructure.
v0.1 includes:
β’ The benchmark
β’ Results across 9 models
β’ Scores from 2 independent judges
GitHub β https://t.co/Q0h9UzQ93X
Write-up β https://t.co/7HHklyAjWT
PRs welcome.
Before you put an LLM inside a red-teaming agent, answer two questions:
1. Will it refuse the task?
2. If it doesn't refuse, will the answer actually work?
Today we're open-sourcing RedLineBench - another Cracken release this week. π§΅
One interesting outcome is what we call a Silent Refusal.
The model appears to answer the task - but hidden guardrails make the output incomplete or unusable.
Without measuring capability separately from refusal, it's easy to miss.
BlackSea is open source.
Live on GitHub β https://t.co/me5xlMbemr
Paper β https://t.co/zSVB4N1hP1
Technical write-up β https://t.co/wKcbBpkMv1
Press release β https://t.co/SbC4C4FNRs
More announcements coming this week. Stay tuned.
97.8% of autonomous pentest agents powered by frontier models took our bait.
Days after an AI agent breached Hugging Face, we're open-sourcing BlackSea - an active honeypot built for attacks like this.
The first of several Cracken announcements this week.
π§΅
In the Hugging Face incident, a BlackSea lure placed in the agent's path could have exposed and interrupted the operation before it reached the production database.
The goal is simple: catch autonomous attackers before they reach real assets.
We're proud to be sponsoring this event with 5 of the most interesting security companies today! Register today and meet us in Las Vegas on August 3rd. #BlackHat2026
The future of enterprise security is being built today.
Join us during #BlackHat2026 for our largest cybersecurity founder showcase yetβbringing together CISOs, security executives, and the founders building what's next.
Meet the teams behind @harnessio, @relyanceai, @KiplingSecure, Tego AI, Cracken and CrystalOS.
Attendance is limited to invited security leaders.
Request your spot: https://t.co/oH4olAgaqW
Cracken builds AI-native offensive security tooling.
We published this because our customers needed it to work in production: https://t.co/JxofyVTws3
Weaponize Defense. Release the Cracken.
The assumption: removing refusal directions in LLMs is a global intervention.
You get everything unlocked - or nothing.
We just proved that assumption wrong.
Domain-specific abliteration. Trillion-parameter model. First time demonstrated at scale. π§΅
For security practitioners: exploit chains, payload logic, privilege escalation paths - generated without the model interrupting itself mid-sequence.
For AI safety researchers: domain-bounded capability release is achievable without global safety regression. The tradeoff isn't inherent - it's architectural.