Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google announced Sec-Gemini v1 on April 4, 2025, as an experimental AI model for cybersecurity work. The company said it could help security practitioners investigate incidents, analyze threats, and understand the impact of vulnerabilities by combining Gemini capabilities with near-real-time cybersecurity knowledge and tools. At launch, access was offered selectively for research—not as a public consumer service.

What is Sec-Gemini v1?

Google described Sec-Gemini v1 as an experimental model intended to advance cybersecurity AI. Its design paired Gemini’s capabilities with near-real-time cybersecurity knowledge and tooling, so its answers could draw on sources including Google Threat Intelligence (GTI) and OSV, a vulnerability database. The announcement was published by Google’s Security Blog on April 4, 2025, and was authored by Elie Burzstein and Marianna Tishchenko of the Sec-Gemini team. Google’s announcement

Which security tasks did Google say it could support?

Google presented Sec-Gemini as an aid for security practitioners’ investigations and analysis, not as a consumer security product. Its named workflows were:

  • Incident root cause analysis: helping analysts investigate what led to a security incident.
  • Threat analysis: bringing threat-intelligence context to an investigation.
  • Vulnerability impact understanding: helping determine how a vulnerability relates to a threat or environment.

In Google’s Salt Typhoon example, Mandiant threat intelligence provided context about the threat actor, while OSV supplied vulnerability details. Google said bringing those sources together could help analysts understand a vulnerability’s risk and threat profile more quickly. That example illustrates the intended workflow; it does not establish that the model independently verified a threat or made operational decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What performance did Google report?

Google said Sec-Gemini v1 outperformed other models by at least 11% on the CTI-MCQ threat-intelligence benchmark and by at least 10.5% on the CTI-Root Cause Mapping benchmark. These are figures reported by Google in its April 4, 2025 announcement, not independently verified results. The reviewed sources do not establish independent replication or provide enough methodological detail to judge how comparable the benchmark results are to real-world security work.

Who could use Sec-Gemini v1?

At announcement, Google said it would make Sec-Gemini v1 freely available to selected organizations, institutions, professionals, and NGOs for research. Interested parties were directed to an early-access request form. “Freely available” therefore meant selective research access, not unrestricted access for the public. Google’s announcement does not establish the model’s present-day availability.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How Sec-Gemini fits with Google’s later security AI work

Google announced other AI security projects after Sec-Gemini v1. They address different workflows and have their own access terms; their announcements do not show that Sec-Gemini v1 became a generally available product.

Project or announcement What Google described Access or status described
Big Sleep and Timesketch AI features (July 15, 2025) Google said Big Sleep had found multiple real-world vulnerabilities and described new agentic capabilities for Timesketch powered by Sec-Gemini. It also outlined FACADE, an AI-based insider-threat detection effort. Google’s update described project developments; it did not establish general availability for Sec-Gemini v1. Google’s July 2025 update
CodeMender and SAIF 2.0 (October 6, 2025) Google announced CodeMender for automatically finding and fixing code vulnerabilities, a dedicated AI Vulnerability Reward Program, and SAIF 2.0 guidance on agent risks. Google highlighted human controllers, limited agent powers, and observable actions and planning as security principles. A distinct security initiative; the announcement does not identify CodeMender as Sec-Gemini v1. Google’s October 2025 update
Fairwind (September 2, 2026) Google described a limited-access offering combining Gemini 3.8 Flash Cyber with CodeMender, aimed at governments, critical infrastructure, and core technology platforms. Limited access for governments and trusted partners, under operational standards Google said restrict use to internal cybersecurity, incident response, or penetration-testing teams and include safeguards such as multifactor authentication. Google also said any Google Cloud customer could use CodeMender with publicly available models hosted on Gemini Enterprise Agent Platform alongside AI Threat Defense. These are Fairwind and CodeMender terms, not Sec-Gemini v1 terms. Google’s Fairwind announcement

The projects reflect a broader set of cybersecurity applications—from threat intelligence and forensic investigation to vulnerability discovery and code repair. Their capabilities, integrations, and eligibility differ, so availability for one project should not be taken as access to another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.