Factory.ai

Company

Partnership

Security

New

Factory joins the Open Secure AI Alliance

July 28, 2026 - 1 minute read -

Share

Factory is joining the Open Secure AI Alliance to build and share open tools for securing software and AI agents, from open-weight secret detection to autonomous security research.

Factory joins the Open Secure AI Alliance

Building security in the open

Factory is joining the Open Secure AI Alliance with NVIDIA and other members to help build and share open tools for securing software and AI agents.

Security improves when defenders can inspect the underlying models, test their behavior, and build on shared research. We contribute to the open security ecosystem across our platform: open-weight secret detection, autonomous security research, and security controls built into Droid. Through the Open Secure AI Alliance, we bring this work into a broader community committed to sharing models, tools, and research in the open.

Droid Shield 2.0

Droid Shield 2.0 uses two fine-tuned models to strengthen deterministic secret scanning.

The Risk model reviews code the scanner did not flag, looking for potential secrets in the surrounding context. The Downgrade model reviews scanner hits after the candidate values have been masked, reducing false positives without exposing the detected secret to the model.

Both models are based on Qwen 3.6 35B A3B and trained on Samsung's public CredData benchmark. We open-sourced the approach, sharing the LoRA adapter weights, tokenizer, configuration, training prompt, and calibration guidance on Hugging Face so other teams can run, inspect, and build on it.

Automated Security Review: our Open Source Commitment

Using Automated Security Review, we build threat models to audit open-source projects and responsibly disclose the vulnerabilities we find.

The Open Source Commitment builds a threat model of the affected code, applies STRIDE and OWASP frameworks, traces data across trust boundaries, and validates candidate findings for reachability and exploitability before reporting them.

These reviews have surfaced public findings including CVE-2026-42876, a template-injection vulnerability in External Secrets Operator. Other findings remain private while maintainers complete their disclosure processes.

We're committed to the open source community, and we look forward to building a safer, more open internet.

start building

Ready to build the software of the future?

Start building

Arrow Right Icon