Frontier labs now ship open-weight models — a whole enterprise can self-host frontier capability inside its own network. But self-hosting means the enterprise owns the safety: no lab safety layer applies. CryptoShield gives every open-weight agent the same continuously-proven containment as the rest of your fleet — plus the checks that only open source needs. As the labs scale model power, we scale containment power — in parallel.
A hosted model comes with the provider's guardrails. An open-weight model, downloaded and self-hosted, does not: the enterprise owns patching, monitoring, access control and safety. That is frontier capability with zero built-in governance — and it is exactly the surface CryptoShield was built to contain.
The freedom to self-host also lets an attacker study the model for weaknesses, ship a poisoned fork, hide a backdoor in a fine-tune, or spin up a shadow agent nobody registered — all without a provider in the loop.
A continuously-proven passport on every open-weight agent, provenance attestation on the model itself, and a Blue-Team plane that contains the moment an agent stops being itself. Governance without prohibition.
The OPEN SOURCE plane is the same Blue-Team Command Center your CIO, CISO and Blue-Team already know from AIM Fleet — every live integrity, discovery, drift, blast-radius, memory and legal lens — plus the lenses that only open weights require. One familiar console; the open-source reality handled in the same place.
On top of every AIM Fleet lens, the OPEN SOURCE plane adds the checks specific to models you host yourself:
The whole model is attested against the vendor's published baseline and quantum-sealed — a poisoned fork or a tampered component is caught before it runs.
Every fine-tune is checked for hidden, triggered behaviour — because signing an adapter proves who made it, not that it is safe.
Each agent records the model that powers it and its jurisdiction, flagging origins that trigger enhanced review under MiCA / DORA / HKMA.
High-consequence actions are checked by a genuinely dissimilar second model — a jailbreak that fools one cannot silently pass the other.
Agent instruction files are screened for hidden, injected prompts — so a poisoned config cannot turn your own assistant against you.
Only vetted models, adapters and skills reach a registered agent — the open-model and skill-registry supply chain, gated at the door.