Term
Sec-Gemini v1
Sec-Gemini v1 is Googles experimental, Gemini-based AI model for cybersecurity. It combines Gemini reasoning with current threat intelligence from Mandiant, the OSV vulnerability database and Google Threat Intelligence.
Sec-Gemini v1 — explained in more detail
Sec-Gemini v1 is an experimental cybersecurity AI model that Google introduced on April 4, 2025. It builds on the Gemini architecture and pairs its reasoning capabilities with continuously updated security knowledge. The goal is to reduce the asymmetry between attackers and defenders: while attackers only need to find a single vulnerability, defenders must secure against all threats. The model targets core defensive workflows such as incident root cause analysis, threat analysis and vulnerability impact assessment.
The strength of Sec-Gemini v1 lies in its connection to Googles security data sources: Mandiant Threat Intelligence, the open-source vulnerability database OSV, Google Threat Intelligence (GTI) and near real-time cybersecurity knowledge. On the CTI-MCQ threat intelligence benchmark it scores at least 11 percent higher than comparable models, according to Google, and 10.5 percent higher on the CTI-Root Cause Mapping benchmark. Google makes the model freely available to select organizations, institutions, professionals and NGOs for research purposes through an early access application form.
Example / In practice
An analyst can ask Sec-Gemini v1 about a known threat actor such as “Salt Typhoon.” The model correctly identifies the actor and provides a description enriched with Mandiant data. It then analyzes the associated vulnerabilities, drawing information from the OSV database and placing it in the context of the threat actor. This shortens research in incident response and threat intelligence workflows.
Distinction from similar terms
Unlike a general-purpose language model such as the base Gemini, Sec-Gemini v1 is a specialized security model with tightly integrated threat intelligence. It belongs to the broader family of agentic cybersecurity approaches but stands out through its direct integration of Mandiant, GTI and OSV. As an experimental research model, it is not a freely deployable product but is only accessible via an early access program.