What is Gemini 3.5 Flash Cyber? Google's gated security model

Gemini 3.5 Flash Cyber is Google's gated security model for finding and fixing vulnerabilities. Here's what it does and why you probably can't use it yet.

Ashley Innocent

Ashley Innocent

22 July 2026

What is Gemini 3.5 Flash Cyber? Google's gated security model

Apidog for Enterprise

On-Premises Deploy

SSO & RBAC

SOC 2 Compliant

Explore Apidog Enterprise

Gemini 3.5 Flash Cyber is a security-focused version of Google’s Flash model, tuned to find and fix software vulnerabilities. It shipped on July 21, 2026, alongside two other Flash-tier models. Here’s the part most write-ups bury: you probably can’t use it yet. It’s a limited-access pilot, open to governments and trusted partners only. There’s no public API and no public pricing.

So treat this as an explainer, not a setup guide. If you came looking for an API key and a code sample for Cyber, that doesn’t exist right now. What does exist is a clear picture of what the model does, why Google is holding it back, and what you can actually build with today.

button

What is Gemini 3.5 Flash Cyber?

Gemini 3.5 Flash Cyber is a security-vulnerability specialist. It’s part of Google’s CodeMender effort, which is aimed at finding and fixing vulnerabilities in code. The general Flash model is a broad coding and reasoning workhorse. Cyber is tuned for one job: spotting security flaws in code and proposing patches for them.

Google announced it in the same Gemini models post that covered the wider Flash refresh. You can read about the general Flash tier on the DeepMind Flash model page. Cyber sits next to those models as the security-tuned member of the family.

Two things to keep straight. CodeMender is the program; Gemini 3.5 Flash Cyber is the model that came out of it. And the name really is “3.5 Flash Cyber,” not 3.6. More on that version mismatch below.

The catch: you probably can’t use it yet

Here’s the honest status, up front. Gemini 3.5 Flash Cyber is a limited-access pilot. Google has made it available to governments and trusted partners only. It is not publicly available.

In practical terms:

If you find a “tutorial” with Cyber API code, a model string, and a neat price table, treat it as invented. Google hasn’t shipped any of those for public use. This is the single most important fact about the model, so it’s worth stating plainly: as a general developer, you cannot access Gemini 3.5 Flash Cyber today.

Why Google gated it

The reasoning is dual-use. A model that’s good at finding vulnerabilities is, by definition, good at finding vulnerabilities. That skill patches a flaw when a defender uses it. The same skill locates a flaw to attack when an attacker uses it. Ship a strong vulnerability finder to everyone with a credit card, and you hand that second use to anyone who wants it.

So Google is starting narrow. A limited release to governments and trusted partners lets the model do defensive work, hardening real systems, while Google watches how it behaves and who’s using it. That’s a normal pattern for security-sensitive tooling: prove it out with vetted partners first, widen access later if the risk picture allows.

It also means the timeline is Google’s to set. There’s no committed public launch date, and there may never be a fully open release in the shape you’d expect from a normal model. Plan around the model you can use, not the one you can’t.

Where it fits in the Flash family

The July 21 refresh shipped three Flash-tier models, and the versioning is genuinely confusing. Here’s the map:

Notice the numbers. The workhorse jumped to 3.6, but Flash-Lite and Cyber both stayed at 3.5. That’s not a typo on Google’s part; the three models are on different version tracks. If you’re comparing the two public options, Gemini 3.6 Flash vs 3.5 Flash walks through what actually changed. Cyber is the odd one out: it’s the only member of the trio a general developer can’t touch.

What developers can use today instead

You can’t run Cyber, but you’re not stuck. Two practical moves cover most of what people wanted it for.

For general coding and security-review prompts, use Gemini 3.6 Flash. It’s public, it has a free tier, and it’s a capable code model. You can paste a function and ask it to flag risky patterns, missing input validation, or auth gaps. It’s not a specialized vulnerability finder, and you should treat its output as a first pass rather than an audit. But it’s available now, which Cyber is not.

For hardening your own APIs, run normal security tests against them. Most real-world API weaknesses aren’t exotic. They’re missing authentication, weak transport security, and endpoints that quietly break their own contract after a change. You can test all three without any special model.

This is where an API client like Apidog fits. You point it at your endpoints and check the things that actually get exploited:

None of that needs a gated model. It needs the discipline to run the checks every time you deploy. Want to follow along? Download Apidog and start with the auth cases; they catch the most for the least effort.

FAQ

Can I access Gemini 3.5 Flash Cyber? No. It’s a limited-access pilot for governments and trusted partners. It is not available to the general public, and there’s no self-serve way to turn it on.

How do I request access? Access is invite and partner based, not open signup. There’s no public form that grants it. If your organization is a government body or an established Google security partner, the route runs through your Google relationship. Everyone else should watch Google’s official channels, the Google blog and the DeepMind model pages, for any change in status.

Is there an API or a published price? Not publicly. There’s no callable model ID for general use and no per-token rate. If a page shows one, it’s not from Google.

What is CodeMender? It’s Google’s effort to find and fix vulnerabilities in code. Gemini 3.5 Flash Cyber is the model tuned for that work. Think of CodeMender as the program and Cyber as the model inside it.

What should I use for security work in the meantime? Use the public Gemini 3.6 Flash for code review prompts, and run standard API security tests, auth, mTLS, and contract checks, against your own services. That combination covers the ground most teams need.

The short version

Gemini 3.5 Flash Cyber is a real model with a narrow job: find and fix security vulnerabilities as part of Google’s CodeMender effort. It’s also gated. Governments and trusted partners can use it; you probably can’t, and there’s no public API or pricing to work with. Anyone selling you a Cyber setup guide is selling something Google hasn’t released.

The useful takeaway is what you can do today. Reach for Gemini 3.6 Flash for general coding and security-review prompts, and harden your own APIs with the tests that actually catch problems. Keep an eye on Google’s official channels if the access story changes.

button

Practice API Design-first in Apidog

Discover an easier way to build and use APIs

What is Gemini 3.5 Flash Cyber? Google's gated security model