On Tuesday, Google announced Gemini 3.8 Flash Cyber, a model that its own Cloud Vulnerability Research team used to find a critical, foundational vulnerability in under two hours. Research that Google says normally takes months. The Chrome Security team reported it produced 2.6 times more correct patches to real Chrome vulnerabilities than the best commercial models, which are much larger.
Then I went to use it. You cannot. There is no public API, no published price, no signup page. Access runs through a program Google calls Fairwind, and it is limited to roughly 650 organizations worldwide: government authorities, critical infrastructure operators, and named partners like CrowdStrike, Datadog, and Palo Alto Networks. If you are an independent developer, a startup, or a mid-sized team, your path in is undefined.
Full disclosure before anything else: I am not a security professional. I am a backend engineer who maintains a few small services and my own AI agent infrastructure, and I do not have Fairwind access either. But while reading the launch post, one line stood out. Google's own Chrome Security team got that 2.6x result, and the byteiota write-up of the launch notes the standard public Flash model was part of that security workflow. The public model is available to anyone, at $0.75 per million input tokens through the end of 2026.













