Frontier labs now ship open-weight models — a whole enterprise can self-host frontier capability inside its own network. But self-hosting means the enterprise owns the safety: no lab safety layer applies. CryptoShield gives every open-weight agent the same continuously-proven containment as the rest of your fleet — plus the checks that only open source needs. As the labs scale model power, we scale containment power — in parallel.
A hosted model comes with the provider's guardrails. An open-weight model, downloaded and self-hosted, does not: the enterprise owns patching, monitoring, access control and safety. That is frontier capability with zero built-in governance — and it is exactly the surface CryptoShield was built to contain.
The freedom to self-host also lets an attacker study the model for weaknesses, ship a poisoned fork, hide a backdoor in a fine-tune, or spin up a shadow agent nobody registered — all without a provider in the loop.
A continuously-proven passport on every open-weight agent, provenance attestation on the model itself, and a Blue-Team plane that contains the moment an agent stops being itself. Governance without prohibition.
The OPEN SOURCE plane is the same Blue-Team Command Center your CIO, CISO and Blue-Team already know from AIM Fleet — every live integrity, discovery, drift, blast-radius, memory and legal lens — plus the lenses that only open weights require. One familiar console; the open-source reality handled in the same place.
On top of every AIM Fleet lens, the OPEN SOURCE plane adds the checks specific to models you host yourself:
The whole model is attested against the vendor's published baseline and quantum-sealed — a poisoned fork or a tampered component is caught before it runs.
Every fine-tune is checked for hidden, triggered behaviour — because signing an adapter proves who made it, not that it is safe.
Each agent records the model that powers it and its jurisdiction, flagging origins that trigger enhanced review under MiCA / DORA / HKMA.
High-consequence actions are checked by a genuinely dissimilar second model — a jailbreak that fools one cannot silently pass the other.
Agent instruction files are screened for hidden, injected prompts — so a poisoned config cannot turn your own assistant against you.
Only vetted models, adapters and skills reach a registered agent — the open-model and skill-registry supply chain, gated at the door.
Prove your open-weight model can still say no. You run our versioned probe in your own estate — the model never leaves it — and we make the result non-repudiable: an ML-DSA-87 signed attestation of this weight, this date, this refusal rate and its over-refusal rate, so a model that refuses everything is reported as damaged, not safer. Up to 5 models per estate. Above five you graduate to the Fleet plan.
€374 / month · up to 5 models
Signed attestation per model · drift, breach and over-refusal thresholds · API key by email the moment you pay.
€3,740 / year · 2 months free
Everything in monthly, billed once. Same 5-model estate, same signed proof, same API.
Card checkout by Stripe. The key arrives on the confirmation page and by email; the first attestation takes one API call. Larger estates, air-gapped sites and platform plans: Contact us.