Submersion AI
Models built for depth
Why we built Submersion
We have been in rooms with security and engineering leaders who planned serious AI budgets. We watched hosted models burn through that money on work that can't leave their environment.
An enterprise with roughly eight figures lined up in AI spend this year has allocated a big chunk of that to token burn on security and engineering workloads that should run in-house.
The models are capable. But they can't fully trust or control the stack they're forced to use. Meanwhile, offense is already moving at machine speed.
That is the gap Submersion AI was built to close. Defenders need the same class of capability attackers are already using, under their control, inside their boundary.
Our team has spent years helping governments and enterprises find holes in their systems and close them before someone else does. That job has a simple rule: if you can find it, assume an attacker can too. The holes you miss still get found. Usually not by you.
AI took away the time that rule used to give you. There used to be a gap between a vulnerability existing and an attacker exploiting it at scale. That gap is smaller now.
Models can already read code, map attack paths, and help reproduce bugs. Anthropic mapped AI-enabled cyber abuse onto MITRE ATT&CK and showed attackers using AI deeper in the kill chain. In July 2026, an autonomous agent ran an end-to-end intrusion against Hugging Face. When Hugging Face tried to analyze the attack with hosted frontier models, safety guardrails blocked the forensics. They finished on an open-weight model inside their own boundary.
The strongest frontier cyber models are held to a small set of trusted partners. Open-weight models have caught up in a lot of the places that matter. They also bring tradeoffs.
One truth that still holds? Enterprises need a cyber model they can run under their control, inside their boundary, and inside the security controls they already operate. Their customers already trusted them with that data. Sending it to a third-party API to log and train on is a different promise, and one those customers did not sign up for.
So we built Submersion. Basin is the first model. We built it from the ground up for offensive security research: finding and helping validate real vulnerabilities so defenders can close them. We build and evaluate our models in-house. We put Basin on public benchmarks, and we put it on real software. It has discovered new CVEs in widely used products, which we validate and disclose under SRTSubmersionAI. Each one is a hole in software people actually run, closed before it becomes someone else's incident. A leaderboard screenshot does not do that.
Other people are taking a shortcut: grab an open-weight frontier model, strip its guardrails, and point it at whatever you want. That makes attackers' lives easier.
Basin is for defenders and the security researchers who support them. It runs where their data already is and works with tools they already use. They keep the agent and the keys. We give them the model.
If you spend your days trying to protect networks, companies, or the country from what is coming next, Basin is for you.