Caret-back
Back to Blog
Blog

Astelia Joins OpenAI's Trusted Access for Cyber Program

Astelia Team
2.5
min read
Sep 23, 2026
Astelia Joins OpenAI's Trusted Access for Cyber Program

Astelia has joined OpenAI's Trusted Access for Cyber program, which gives verified defenders its highest tier of model access, built for security work. We're pointing that access at one problem: AI has made working exploits fast and easy to build. Our answer is reachability analysis. It uses a customer's specific network context to prove that about 99% of their backlog isn't reachable, and shows how to close off the 1% that is before an attacker gets there.

What verification actually unlocks

OpenAI built the program for defenders whose work, such as vulnerability research or exploit-requirement analysis, would otherwise run into a model's ordinary safety restrictions. Verification means a company has shown its use case is genuinely defensive, and the top tier unlocks GPT-5.4-Cyber specifically: a fine-tune of GPT-5.4 with a lower refusal boundary for legitimate cybersecurity work, fewer capability restrictions than the general-purpose model, and binary reverse engineering ability strong enough to assess compiled software for exploit potential without seeing its source code.

What makes this worth building around isn't just the capability on day one. OpenAI has said GPT-5.4-Cyber is the starting point for a series of increasingly capable models aimed at defensive use, released as they're ready rather than held back as one static grant. Frontier models can already turn a disclosed CVE into a working exploit in a matter of hours, and that curve isn't flattening. Getting verified access now means we track that capability as it moves, instead of reasoning about exploit conditions with a model that's already a generation behind what an attacker might be using.

The assumption that just expired

Vulnerability management grew up assuming most "critical" findings would never get weaponized, which made a severity score a workable proxy for real risk. That assumption depended on exploit development staying slow and specialized.

Once a CVE can be turned into a working exploit on demand, severity tiers stop separating signal from noise, and the backlog reads as uniformly urgent. Patching faster than a model can write exploit code isn't a strategy that scales.

This is the gap Astelia was built to close. Rather than ranking findings by how dangerous they might be in theory, we show what an attacker can actually reach inside a given environment. Severity describes a vulnerability in the abstract; reachability describes what's actually true of a specific network.

How reachability analysis puts the access to work

Astelia maps real network topology through read-only integrations , then uses agentic AI to work out what each finding would actually take to exploit: the running services, the path, and the preconditions that all have to line up. Matched against topology, that process narrows things down to the roughly 1% of vulnerabilities that are genuinely reachable, with evidence for why everything else can be set aside as noise.

The same analysis also points toward a fix. When a CVE can be weaponized as soon as it becomes public, waiting on a vendor patch is often unrealistic, so Astelia lays out several ways to cut the attacker's path to a reachable flaw: segmentation, configuration changes, or changes to compensating controls. Security and IT can then work from the same evidence and choose whichever option they can actually deploy.

What this means for your program

On-demand exploitation doesn't weaken this approach, because reachability was never a bet on how hard an exploit is to build. Severity scores and patch cycles were, and that's why they're breaking down now. Once exploiting a vulnerability costs an attacker almost nothing, finding and fixing the reachable ones is the only defense that still works.
‍

Request a demo to identify and eliminate the 1% of reachable vulnerabilities in your network.

Share