Surf joins the OpenAI Daybreak Cyber Partner Program
OpenAI's frontier cyber models improve how Surf remediates security findings, so security teams can close their backlog instead of adding to it.
Surf AI has joined the OpenAI Daybreak Cyber Partner Program.
The same frontier reasoning that helps a defender resolve a vulnerability helps an attacker find and weaponize it, and attackers now move faster than people can respond. This program puts that reasoning on the defender's side and pairs it with Surf's context, so remediation can keep pace.
The remediation gap
Most security programs don't lack detection. They struggle to turn a confirmed finding into a closed one.
Closing a finding means answering a few questions first. Who owns the asset? What breaks if you change it? What does the change process require? Which policies apply? Those answers sit across identity, cloud, HR, ITSM, and code systems, and gathering them by hand takes people, meetings, and time. Until that work finishes, the finding stays live in production.
Attackers work faster than manual response can keep up. Each new detection adds to a backlog that manual remediation can't clear, so more detection on its own widens the gap instead of closing it.
What the Daybreak Cyber Partner Program is
Frontier cyber reasoning is dual-use. The same model that helps a defender judge whether an exposure can be exploited helps an attacker exploit it. That overlap makes open, unrestricted access to these models risky.
Through the Daybreak Cyber Partner Program, OpenAI gives its frontier cyber models to vetted security providers instead of releasing them openly. Providers run the models inside working security programs, with human oversight and governed integrations rather than raw access.
Surf uses this capability for a specific job. Turning a finding into a safe fix requires reasoning about whether an exposure is exploitable, what a change would touch, and where the problem originates. A scanner verdict doesn't answer those questions.
What this means for security teams
The partnership pairs two things. OpenAI's models supply the reasoning: judging whether an exposure is exploitable, tracing it to its root cause, and shaping the fix. Surf's Context Graph supplies the ground truth: an updated map of the entities, relationships, ownership, and policies across identity, HR, cloud, ITSM, code, and collaboration systems. The model reasons about the fix, and the graph anchors it to who owns the asset, what the change affects, and which policies apply. Together they turn a raw finding into an owned, executable fix.
Security teams get frontier-grade reasoning applied to the most manual part of the job, grounded in the context that keeps it safe.
Speed without losing control
The reasoning runs inside Surf's guardrails. Before Surf acts, it models the downstream impact of a change. It resolves compliance scope and change policy from the environment itself rather than adding them afterward. Every proposed fix carries an owner, a safe path, and an audit trail, and a person approves it before anything changes.
By pairing OpenAI's reasoning with the context that makes a change safe, Surf automates the part of security that has resisted automation the longest. The backlog starts to shrink, and the advantage shifts back to the defender.
Prasad Raman is Head of Technology Partnerships at Surf AI, with a decade of experience building alliance and partnership programs across the security industry.
