Models
Use Security-One to make fast, calibrated security decisions across applications, agents, code, and infrastructure.
Security-One is Superagent's security decision model. It reads security-relevant state, such as a prompt, an agent tool call, a log line, a code change, or an alert, and answers the questions you define with calibrated probabilities instead of free-form text.
Run it as the always-on first pass in a security pipeline. Let it clear routine events, send suspicious events to a stronger model, and escalate consequential or ambiguous events to a person.
flowchart TD A[Applications, agents, code, infrastructure] --> B[Security-One] B --> C[Allow or monitor] B --> D[Stronger model analysis] B --> E[Human or incident queue]
A decision model, not a chat model
- Security-One scores the options you supply in one forward pass. It does not generate an answer.
- Every answer is a calibrated probability or probability distribution, so your code owns the threshold and the action.
- The same request returns the same probabilities.
- Ordinary chat-completion prompting does not reproduce the reported results. Use the SystemOne API or the self-hosting recipe.
Ways to run it
| Option | Use it when |
|---|---|
| SystemOne API | You want an HTTPS endpoint with no GPUs to manage |
| Open weights | You need inference inside your own infrastructure |
Both options use the same prompt format, answer labels, and calibration. Thresholds tuned on the hosted API are a starting point for self-hosting; revalidate them on your deployment, because a different GPU, inference engine, or quantization can shift calibration.
What to use it for
Prompt-injection detection is the best-validated capability in the current release. The same decision interface supports security classification across every layer:
| Layer | Example decisions |
|---|---|
| Applications | Abuse signals, suspicious requests, policy violations, incident severity |
| Agents | Prompt injection, untrusted instructions, tool-use risk, data access, privilege escalation |
| Code | Change risk, vulnerability triage, secret exposure, review priority |
| Infrastructure | Log and alert triage, anomalous actions, configuration risk, escalation routing |
Layers other than prompt injection are deployment patterns, not equally validated benchmark claims. Evaluate each workflow on representative traffic and choose your own threshold before you automate actions.
The examples show the full pipeline, including escalation to a stronger model, for prompt-injection screening and pull request checks.
Keep enforcement outside the model
Security-One produces evidence for a control plane. It is not the control plane. Keep authentication, authorization, sandboxing, rate limits, least privilege, and human review around consequential actions.