PacificCompute

Our first cluster

Dedicated Compute for Open Frontier Safety

Bring a model, a planned evaluation, or a question you need resources to test.

Live now

We’ve started out renting compute to prove our thesis with models releasing in 2026. Our first small cluster of H200s is live in Singapore. For model releases, we can easily surge capacity by renting more compute from Singaporean partner providers.

Why Singapore

Singapore is a leader in AI safety work, and a practical location for pan-Pacific open model safety collaborations. Our first cluster’s funding is backed by private philanthropic donations to safeguard the open frontier.

Who it serves

Our Singapore cluster serves open model labs, academics and safety hubs in Asia, where access to dedicated AI safety compute and international evaluation networks is most limited. As the open frontier expands from China and the United States to other countries, we’re ready to expand our Singapore cluster to answer the need for sovereign AI safety compute.

For model developers

We provide compute for frontier model safety evaluations, free.

Testing dangerous capabilities before open-weight releases is a core mandate of our Singapore hub. Working with labs and evaluation partners before a model release means a safer open frontier.

Pre-release weights are sensitive, and many labs have private safety evals that contain proprietary techniques. We work with labs on both sides of the Pacific to make sure that no matter the safety or security requirements, we can provide compute to contribute to the safety and evaluation of new model launches.

For safety researchers

Discounted AI Safety Compute

Safety and alignment work needs sovereign, independent compute resources to thrive.

Affordable, effective compute resources will help create incentives for more safety work across the open frontier. From targeted red-teaming, to interpretability to replication, we’re providing the compute and support to power AI safety.

Working together

Trust, safety and security

Who handles what, from the first inquiry to the findings package.

First contact
Our intake team receives your contact details and a non-sensitive description through our email provider. WeChat follow-up is manual; do not send checkpoints or confidential findings in the first inquiry.
Target weights
For endpoint-based evaluations, your lab hosts the model and controls access. Unreleased weights stay on your side by default, with only trusted partnerships granting deeper access. Our compute runs the surrounding evaluation work.
Evaluation findings
Findings go privately to the lab’s designated team. Participation does not require publication of results or public acknowledgement of the collaboration.
Research materials
Confidentiality terms define who can handle research materials, what they may be used for, and how long they are retained. Access to job metadata and monitoring records is agreed separately.
Operational records
Pacific Compute keeps minimal records of the work performed with our cluster, to ensure that we keep our promise of safety-only work. We will work with your team to ensure that the privacy and security policies you have in place are respected.

Lab-controlled tenancy is designed to keep your engineers in control of the partition, model keys and approved users. We agree configuration, custody and security requirements directly with your lab before work begins.

Before sharing sensitive materials, we agree confidentiality terms and the people needed to carry out the evaluation. A first inquiry needs only a short, non-sensitive description.

Lab-controlled tenancy ↓
Why we do this work

Safety evaluations should not compete for GPUs with capability work. Our mission is to help open model labs release open-weight models with a full safety eval suite, and to support researchers doing important safety work with open frontier models.

Additional safety work in the pre-release window benefits the entire open model ecosystem by providing safer, more aligned models to the community of open model developers and researchers.

Access & custody

Pre-release is the priority.

Two configurations answer different needs. Endpoint access supports black-box evaluations.

Pre-release, without transferring target weights.

Endpoint workflow

At the lab
Target modelWeights stay here

The lab hosts the endpoint and sees every query.

Pacific Compute
Attacker modelsJudge modelsParallel experimentsMethod development

GPU-backed models run alongside tool environments and evaluation orchestration.

The resource split depends on the suite. Endpoint testing also requires agreement on model identity, access limits and evaluation independence.

Lab-controlled tenancy ↓

Safety fine-tuning

No gradient updates is our default rule. In rare cases where evaluation uncovers a dangerous issue requiring urgent mitigation, we can support limited supervised fine-tuning in a lab-controlled partition of our cluster, followed by re-evaluation.

After release: the supporting programme

Open weights can run locally for durability testing, interpretability and replication. This supporting programme complements the pre-release campaigns.

An illustrative campaign

Built around the release window.

Target three weeks. Four weeks maximum, from agreed kickoff through findings delivery and the scoped retest.

Model & access
One pre-release model, hosted by the lab. An identified version and agreed endpoint capacity.
Evaluation scope
Two agreed safety domains, initial tests, investigation and reproduction. A follow-up candidate can be retested within the agreed window.
What the lab receives
A private findings memo, supporting evidence, methods and limitations, a retest record and a resource statement. No safety certification.
  1. Week 1

    Calibrate and begin

    Confirm the eval suite, access conditions, and compute requirements. Run tests and configure.

  2. Week 2

    Investigate and reproduce

    Run the main evaluation. Bring material findings to the lab as they arise.

  3. Week 3 · Week 4 if needed

    Retest and deliver

    Finish the agreed retest and findings package.

Inside the findings package

Illustrative document structure—not findings from a completed campaign. Delivered privately to the lab.

Illustrative findings package
QuestionModel version, access mode and the safety question investigated.
Test coverageTests completed, trial counts, conditions and work left untested.
FindingsObservations tied to supporting evidence, including negative or inconclusive results.
LimitationsUncertainty, scoring checks and what the evidence cannot establish.
Reproduction & retestReproduction records and scoped retest results, or why a retest was not possible.
ResourcesCompute and endpoint use, staff time, storage/transfer and reconciled costs.

Findings go privately to the lab’s designated team. Participation does not require publication of results or public acknowledgement of the collaboration.

Discuss a campaign ↗

Cluster Rules

Rules of our Singapore Cluster

01

Open Frontier Safety Work Only

Pacific Compute offers compute for evaluation, diagnosis and safety research. Permitted jobs and access are agreed before work begins. Workload restrictions are part of our operating requirements; we work with partners on these narrow jobs, and never work on model capability.

No gradient updates is our default rule. In rare cases where evaluation uncovers a dangerous issue requiring urgent mitigation, we can support limited supervised fine-tuning in a lab-controlled partition of our cluster, followed by re-evaluation.

02

Open Frontier Models

We work with released open weights and models intended for open release. Unreleased target weights require an explicit access agreement.

03

Accountable use

We work with the open frontier labs while respecting their security and confidentiality requirements. To ensure all partners use our compute for safety work, we inspect job metadata and have simple, privacy-respecting monitoring systems in place. We are testing telemetry-based workload classification for the cluster, to ensure sensitive data and model weights can remain secure. Record access is agreed with the lab; philanthropic funders receive no access.

Read more on telemetric cluster monitoring: the paper and limitations ↗
04

No political work

Pacific Compute doesn’t support safety work related to politics: no bias-testing, censorship, or politics of any kind. This rule is strictly enforced, even for private evals. The same scope applies to every participating lab and researcher.

Put compute to work.

Bring a model, an evaluation, or the funding to make it happen.