Glemad
    Glemad EditorialAnnouncements6 min read

    Introducing Ollandi 5 Preview

    Meet Ollandi 5, our newest and most capable security-native reasoning model, built for continuous intelligence across hybrid infrastructure.

    Introducing Ollandi 5 Preview
    6 min read


    Introducing Ollandi 5 Preview

    Our newest and most capable security-native reasoning model is now live

    Today, we are introducing Ollandi 5 Preview, our newest and most capable security-native reasoning model.

    Ollandi 5 is now live through the Ollandi platform and API.

    We founded Glemad in 2020 to develop dependable intelligence capable of protecting global digital infrastructure. Ollandi 5 represents meaningful progress toward that mission.

    Modern infrastructure has become deeply distributed.

    Identity, applications, networks, operational systems, data, and third-party services now extend across public cloud, private data centers, edge environments, and on-premises infrastructure.

    Yet most security and infrastructure tools still observe these environments separately.

    This creates fragmented visibility, delayed investigation, incomplete reasoning, and slow response.

    Ollandi 5 addresses this problem by reasoning across infrastructure as one continuously changing state.

    It does not only process isolated alerts. It correlates identities, permissions, services, dependencies, configuration changes, operational events, and security signals across time.

    This allows the model to understand how individual events relate, how risk develops across environments, and what may happen next.

    A security-native reasoning architecture

    Ollandi 5 builds on the research foundations of earlier model research and coordination research.

    Earlier model research introduced security-native reasoning at the model level.

    This included continuous infrastructure state tracking, threat interpretation under uncertainty, policy-aware action validation, and structured evidence generation.

    The coordination research extended this work through distributed coordination between specialized intelligence systems across identity, cloud, network, endpoint, and application environments.

    Ollandi 5 brings these foundations into a unified production architecture.

    The model combines five core system layers:

    • A Unified Hybrid Fabric
    • A Cognitive Security Core
    • A Multi-Agent Coordination Mesh
    • Policy-Bounded Action Verification
    • Continuous Evidence Generation

    Together, these layers allow Ollandi 5 to observe infrastructure, construct shared state, reason about emerging threats, coordinate specialized intelligence, validate possible actions, and generate evidence for every significant decision.

    Unified reasoning across hybrid infrastructure

    The Unified Hybrid Fabric gives Ollandi 5 a consistent view across cloud and on-premises environments.

    Infrastructure signals arrive in different formats and carry different meanings.

    A cloud identity event, an Active Directory change, a network connection, an application request, and a database operation may appear unrelated when viewed independently.

    Ollandi 5 normalizes these signals while preserving their source, identity, timing, policy context, and relationships.

    This creates a unified infrastructure state that can be reasoned over continuously.

    The model can connect activity across environments and identify patterns that would remain hidden inside isolated dashboards, logs, or tools.

    This is important because modern attacks rarely remain inside one control plane.

    An incident may begin with an identity compromise, move through a cloud environment, affect an application, and later disrupt an operational service.

    Ollandi 5 is designed to reason across the full sequence.

    Neuro-Symbolic Threat Intelligence

    Ollandi 5 introduces Neuro-Symbolic Threat Intelligence.

    This combines neural pattern recognition with symbolic reasoning.

    Neural reasoning allows the model to identify complex, uncertain, and previously unseen patterns.

    Symbolic reasoning allows it to evaluate those patterns against infrastructure relationships, policy constraints, known attack behavior, and logical rules.

    The result is threat intelligence that can be both adaptive and explainable.

    Ollandi 5 does not only produce a conclusion.

    It can produce a structured explanation of what it observed, how the signals relate, why the behavior is significant, what competing explanations were considered, and what evidence supports the final assessment.

    This makes the model more useful for investigation, governance, compliance, and operational accountability.

    Reasoning about what happens next

    Traditional security systems focus heavily on what has already happened.

    Ollandi 5 introduces Adversarial Counter-Reasoning to reason about what an attacker may attempt next.

    The model evaluates current infrastructure state, attacker behavior, available privileges, exposed dependencies, and likely objectives.

    It then forms possible next-step hypotheses.

    This changes the defensive posture from reactive interpretation to predictive reasoning.

    The goal is not to claim certainty about future actions.

    The goal is to help teams understand how an incident may develop, which assets are likely to become exposed, and where defensive attention should move before the next stage occurs.

    Coordinated intelligence at machine speed

    Ollandi 5 uses a Multi-Agent Coordination Mesh to bring together specialized reasoning across infrastructure domains.

    Identity intelligence may understand sessions, roles, credentials, and privilege changes.

    Cloud intelligence may understand workloads, control planes, configurations, and service dependencies.

    Network intelligence may understand traffic paths, segmentation, and communication behavior.

    Application intelligence may understand requests, data access, and service-level activity.

    Each system contributes evidence and hypotheses to a shared state.

    Ollandi 5 coordinates these systems through the Zero-Latency Consensus Protocol, designed for sub-second collective decision-making in critical scenarios.

    The model can preserve disagreement, evaluate confidence, detect abnormal participants, and maintain correctness under partial failure.

    This allows distributed intelligence to operate as one coordinated reasoning system without removing domain specialization.

    Policy-bounded action

    Ollandi 5 is not designed to operate without governance.

    Every proposed action can be evaluated against organizational policy, authority, blast radius, reversibility, timing, and safety constraints.

    Actions are classified according to their impact.

    Observational actions can remain autonomous.

    Reversible containment actions can operate within defined policy boundaries.

    High-impact or irreversible actions require stronger authority and human approval.

    Human override remains fundamental.

    Rollback remains part of the control model.

    Ollandi 5 enforces policy. It does not replace the people responsible for defining that policy.

    This distinction matters.

    Dependable intelligence must operate with clear limits, traceable authority, and visible accountability.

    Continuous evidence as a first-class output

    Evidence is not treated as documentation created after a decision.

    Ollandi 5 generates evidence as part of the reasoning process.

    Every significant inference, hypothesis, decision, and action can produce structured, audit-grade records.

    These records can support:

    • Security investigations
    • Incident review
    • Regulatory reporting
    • Compliance validation
    • Legal accountability
    • Model evaluation
    • Human oversight

    This gives infrastructure and security teams a continuous record of what the model observed, what it concluded, what it recommended, and what occurred afterward.

    A model that improves through verified experience

    Ollandi 5 introduces Self-Evolving Defense Surfaces.

    This allows the model to improve its defensive reasoning through verified threat encounters, policy updates, infrastructure changes, and operational feedback.

    Learning remains governed.

    Changes can be tested, staged, monitored, and rolled back.

    The system is not allowed to expand its authority or modify safety boundaries without validation.

    This allows Ollandi 5 to adapt without depending on uncontrolled model drift.

    Built for continuous infrastructure intelligence

    Ollandi 5 is not a general-purpose model adapted to security after training.

    It is security-native at the architectural level.

    Infrastructure semantics, attacker behavior, identities, permissions, dependencies, policy constraints, state transitions, and evidence requirements are part of how the model reasons.

    Our goal is not to remove human judgment.

    Our goal is to give infrastructure and security teams continuous intelligence that can reason across fragmented environments, identify emerging risk earlier, explain its conclusions, coordinate specialized systems, and support action within clear policy boundaries.

    Ollandi 5 is now live through Ollandi and the Ollandi API.

    The full Ollandi 5 technical paper is available.