BLACKFROST / ANSWERS
Blackfrost builds cybersecurity AI for defenders: exact model-weight releases, custom model engineering, and separately scoped scalable hosting. De-Risked describes reduced or removed refusal behavior in a specific model release; it is not a safety guarantee or permission to misuse the model.
BLACKFROST
Blackfrost is a cybersecurity AI company for defenders. We sell licensed access to exact model-weight releases, engineer custom open-weight models through fine-tuning and post-training, and separately design scalable private hosting. We also maintain open-source tools and publish free model releases.
Blackfrost is built for defensive security teams, security product builders, authorized researchers, and technical organizations that need a model they can evaluate and operate inside explicit data, access, infrastructure, and human-approval boundaries.
Cybersecurity is the company’s primary focus. Blackfrost specializes in model behavior and controlled agentic capability for defensive work such as incident investigation, detection engineering, threat and artifact analysis, secure-code review, vulnerability triage, and security automation. A custom scope determines what any commissioned model is actually built to do.
Blackfrost is the public brand of Blackfrost Softwares Corp, a founder-led company based in Las Vegas, Nevada. Terrell A. Lancaster founded the company and leads its model, security, and cloud architecture work.
DE-RISKED + THE VOID
De-Risked is Blackfrost’s release label for reduced or removed refusal behavior. The intended result is better completion on authorized cybersecurity and technical tasks, but the effect is model-, prompt-, and workload-specific. Buyers must evaluate the exact release in their own environment.
No. De-Risked is not a claim that a model is safe by default, free of harmful outputs, legally unrestricted, certified, or authorized to act. Capability does not grant authority. Identity, tool permissions, network boundaries, logging, containment, approval gates, and human oversight remain deployment responsibilities.
The Void is Blackfrost’s method for custom-model tuning and post-training, not a standalone product. Its teacher-generated training signal comes from permitted De-Risked frontier teachers with deliberately reduced or, when the authorized mission requires it, removed refusal behavior. The engagement still defines the task, data rights, protected boundaries, evaluation protocol, and deployment controls.
No. Blackfrost does not use those phrases as blanket product promises. De-Risked describes one behavior characteristic—the refusal profile—without claiming that every answer is correct, safe, useful, or appropriate. Operational guardrails belong in the complete deployment system and must match the organization’s authority and risk model.
No. Technical capability is not permission. Security testing requires explicit authorization that covers the relevant target, scope, techniques, data, time period, responsible parties, and stop conditions. A model must operate within the same legal, contractual, identity, and infrastructure controls as the people and systems using it.
MODEL STORE
The current Model Store lists 11 exact editions across GLM-5.3, Qwen3.8 2.4T A95B, Kimi K3, and GLM-5.2. Listed formats include BF16, FP8, NVFP4, MXFP4, and GGUF. Each product page names the base model, architecture, precision, footprint, intended fit, deployment boundary, upstream license, SKU, repository, and verified revision.
A purchase grants the Hugging Face account entered at checkout licensed access to the exact gated repository named on the product page. The included package is limited to the listed weights and repository artifacts, such as configuration, tokenizer files when present, metadata, documentation, package profile, and verified release identity.
A model purchase does not include Shadow CLI, Context Cooler, an inference API, compute, storage, cloud service, hosting, installation, integration, custom tuning, evaluation tooling, workload validation, ongoing operations, an SLA, or future catalog releases unless a product page expressly says otherwise.
No. It is a one-time commercial license to possess, run, and use the delivered package under the Blackfrost license, the product page, the accepted order, and applicable upstream terms. Copyright, trademarks, repository ownership, upstream rights, and unrestricted redistribution rights are not transferred.
Unless a product page or upstream license says otherwise, the Blackfrost license permits internal and commercial inference, hosted outputs that do not expose the weights, and internal fine-tuned, quantized, or pruned derivatives. Redistribution, sublicensing, credential sharing, and transfer to unlicensed parties remain restricted.
No catalog purchase guarantees a benchmark result, output quality, safety characteristic, runtime compatibility, hardware fit, or fitness for a specific purpose. Model outputs are probabilistic. Buyers must validate the exact artifact, workload, capacity, and controls before production use.
CUSTOM MODELS + HOSTING
Blackfrost can select an open-weight foundation, construct a permitted data path, fine-tune or post-train behavior, optimize the artifact, and evaluate the candidate against an agreed task protocol. A scope may include supervised fine-tuning, preference optimization, distillation, Directional Weight Modification, quantization, and runtime-aware packaging.
Examples include incident investigation, evidence synthesis, timeline construction, detection engineering, ATT&CK-informed analysis, threat and malware artifact analysis, indicator enrichment, secure-code review, vulnerability triage, structured reporting, and controlled security agents. These are possible custom scopes, not claims about every catalog model.
Deliverables can include weights or adapters, tokenizer and configuration, a model card, release manifest, provenance summary, baseline-versus-candidate evaluation, releasable test materials, and serving guidance. Only artifacts and evidence named in the signed statement of work are included.
Directional Weight Modification is controlled behavioral tuning toward a defined operating band while retaining or protecting named capability floors. It is one possible method inside a custom engagement, selected only when it fits the task, model, and acceptance criteria.
Yes, as a separate engineering engagement. Blackfrost can scope capacity and topology, runtime and artifact fit, APIs, deployment automation, scaling and queueing, observability, security boundaries, load validation, rollback, runbooks, and operational handoff around the selected weights and actual workload.
A hosting engagement can target a customer cloud account, a private-cloud or on-premises environment, or a Blackfrost-operated service under a separate agreement. Hardware, network, identity, data movement, telemetry, operating ownership, and support obligations are defined in the scope.
No. Model weights, custom model engineering, and scalable hosting are distinct offers. Custom engineering and hosting can be commissioned together, but deliverables, operating roles, ongoing support, and service-level commitments apply only when explicitly contracted.
OPEN SOURCE + COMMUNITY
Shadow CLI is Blackfrost’s separate MIT-licensed, local-first, provider-neutral agentic CLI for macOS, Linux, and Windows. It uses the model providers, workspace, permissions, and tools the operator chooses. Shadow is open source; it is neither bundled with nor required to use purchased model weights.
Context Cooler is a separate MIT-licensed Blackfrost open-source MCP server. It keeps bulky execution and search output outside the model context, then returns the useful result. Its source, installation, and support boundary live in its own public repository.
Yes. The current Community library includes Lumix-4B, Lumix-35B, and GLM-5.3 Flash De-Risked. Each Hugging Face model card—not the directory—is authoritative for the release files, lineage, license, hardware guidance, intended use, and known limitations.
The Community hub contains Blackfrost open-source projects, free models, independent defender-project recommendations, contribution paths, and clearly labeled commercial relationships. Current independent recommendations include Sigma, Apache Caldera, and Velociraptor.
A recommendation is an unpaid editorial selection. A partner must have an active, named relationship and public evidence. An advertisement is paid placement and is labeled at the listing. Payment never creates partner status, an undisclosed endorsement, or access to private visitor data. No public partners or active advertisements are currently listed.
BUYING + SUPPORT
Payment is completed through Stripe Checkout. After Stripe confirms payment through a signature-verified event and required compliance checks pass, Blackfrost grants the Hugging Face username entered at checkout access to the exact gated repository. A browser success page alone does not prove payment or trigger delivery.
A digital model order ordinarily becomes final after correct repository access is granted. A correction or refund may apply for duplicate charges, non-delivery after reasonable troubleshooting, corrupt or materially unusable files, the wrong SKU or format, material misdescription, or rights required by applicable law.
For a catalog release, compare the exact architecture, precision, footprint, intended fit, runtime boundary, upstream license, and verified repository revision. For custom work, start with the authorized workflow, evidence standard, target hardware, data rights, failure modes, and deployment boundary rather than a preferred training technique.
Use the contact brief for model compatibility, custom engineering, scalable hosting, Community submissions, partnerships, or advertisement inquiries. For purchase and general support, email support@blackfrostai.com. Security researchers can use the reporting instructions on the Security page.
STILL NEED A SPECIFIC ANSWER?