G
GetLLMs
ModelAI security

Gemini 3.5 Flash Cyber

Gemini 3.5 Flash Cyber is a security-specialist model built on Gemini 3.5 Flash and fine-tuned to find, validate, and patch vulnerabilities. It is not a public Gemini API model; Google plans a limited CodeMender pilot for governments and trusted partners.

Why it matters

Flash Cyber shows how a smaller specialist model can be invoked repeatedly across a large vulnerability search space, but its dual-use capability also makes availability and deployment controls central to understanding the product.

Source-backed summary

Google DeepMind announced Gemini 3.5 Flash Cyber on July 21, 2026 as a lightweight cybersecurity model used by CodeMender. Google says multiple Flash Cyber agents explore code paths and combine their findings into one report. In Google-reported testing, the system was competitive on CyberGym and found 55 unique confirmed V8 issues versus 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6. Google is limiting the model to governments and trusted partners through a forthcoming CodeMender pilot because of its dual-use risk.

Primary use cases
  • Find and validate vulnerabilities across large codebases through CodeMender.
  • Generate candidate patches and consolidated security reports.
  • Run repeated defensive scans in trusted launch or commit-review pipelines.
  • Research specialist-model orchestration under controlled security access.
What the model does

Gemini 3.5 Flash Cyber is fine-tuned for vulnerability discovery, validation, and patching. CodeMender can invoke the model multiple times over different code paths, then combine the results into one report instead of relying on one expensive model call.

Availability is intentionally restricted

Google has not announced a public Gemini API model ID or public token price for Flash Cyber. Access is planned soon through a limited CodeMender pilot for governments and trusted partners. Publicly available Gemini models can use some CodeMender-derived capabilities through Gemini Enterprise, but that is not direct Flash Cyber access.

How to read the benchmark claims

Google reports competitive CyberGym results and stronger vulnerability discovery than mainline Flash models in internal Big Sleep, Chrome commit-scanning, and V8 evaluations. These are vendor-reported security evaluations with restricted tasks and deployment controls, so they should not be generalized into unrestricted offensive capability or public API availability.

Gemini 3.5 Flash Cyber FAQ

Common questions about Gemini 3.5 Flash Cyber.

Can I use Gemini 3.5 Flash Cyber through the public Gemini API?+

No public Gemini API access has been announced. Google says Flash Cyber will be available soon only to governments and trusted partners through a limited CodeMender pilot.

What is the difference between Flash Cyber and Gemini 3.6 Flash?+

Flash Cyber is a restricted specialist model fine-tuned for defensive vulnerability discovery and patching through CodeMender. Gemini 3.6 Flash is a generally available workhorse for coding, multimodal work, and agentic workflows through the Gemini API and Google products.

Why is Gemini 3.5 Flash Cyber access restricted?+

Google cites the dual-use nature of advanced vulnerability discovery: the same capability that helps defenders can also support misuse. The limited pilot is intended to give trusted defenders access while reducing broader abuse risk.