> For clean Markdown of this page, append .md to its URL. For the complete documentation index, see https://www.superagent.sh/llms.txt.


Use Security-One to make fast, calibrated security decisions across applications, agents, code, and infrastructure.

# Models

Security-One is Superagent's security decision model. It reads security-relevant state, such as a prompt, an agent tool call, a log line, a code change, or an alert, and answers the questions you define with calibrated probabilities instead of free-form text.

Run it as the always-on first pass in a security pipeline. Let it clear routine events, send suspicious events to a stronger model, and escalate consequential or ambiguous events to a person.

```mermaid
flowchart TD
  A[Applications, agents, code, infrastructure] --> B[Security-One]
  B --> C[Allow or monitor]
  B --> D[Stronger model analysis]
  B --> E[Human or incident queue]
```

## A decision model, not a chat model

- Security-One scores the options you supply in one forward pass. It does not generate an answer.
- Every answer is a calibrated probability or probability distribution, so your code owns the threshold and the action.
- The same request returns the same probabilities.
- Ordinary chat-completion prompting does not reproduce the reported results. Use the [SystemOne API](https://www.superagent.sh/docs/models/api) or the [self-hosting recipe](https://www.superagent.sh/docs/models/self-hosting).

## Ways to run it

| Option | Use it when |
| --- | --- |
| [SystemOne API](https://www.superagent.sh/docs/models/api) | You want an HTTPS endpoint with no GPUs to manage |
| [Open weights](https://www.superagent.sh/docs/models/self-hosting) | You need inference inside your own infrastructure |

Both options use the same prompt format, answer labels, and calibration. Thresholds tuned on the hosted API are a starting point for self-hosting; revalidate them on your deployment, because a different GPU, inference engine, or quantization can shift calibration.

## What to use it for

Prompt-injection detection is the best-validated capability in the current release. The same decision interface supports security classification across every layer:

| Layer | Example decisions |
| --- | --- |
| Applications | Abuse signals, suspicious requests, policy violations, incident severity |
| Agents | Prompt injection, untrusted instructions, tool-use risk, data access, privilege escalation |
| Code | Change risk, vulnerability triage, secret exposure, review priority |
| Infrastructure | Log and alert triage, anomalous actions, configuration risk, escalation routing |

Layers other than prompt injection are deployment patterns, not equally validated benchmark claims. Evaluate each workflow on representative traffic and choose your own threshold before you automate actions.

The [examples](https://www.superagent.sh/docs/models/examples) show the full pipeline, including escalation to a stronger model, for prompt-injection screening and pull request checks.

## Keep enforcement outside the model

Security-One produces evidence for a control plane. It is not the control plane. Keep authentication, authorization, sandboxing, rate limits, least privilege, and human review around consequential actions.

## Next steps

- [Browse Security-One examples](https://www.superagent.sh/docs/models/examples)
- [Read the Security-One 27B model card](https://www.superagent.sh/docs/models/security-one)
- [Call the SystemOne API](https://www.superagent.sh/docs/models/api)

---
Source: https://www.superagent.sh/docs/models
Index: https://www.superagent.sh/llms.txt
