Our first cluster
Dedicated Compute for Open Frontier Safety
Bring a model, a planned evaluation, or a question you need resources to test.
Live now
We’ve started out renting compute to prove our thesis with models releasing in 2026. Our first small cluster of H200s is live in Singapore. For model releases, we can easily surge capacity by renting more compute from Singaporean partner providers.
Why Singapore
Singapore is a leader in AI safety work, and a practical location for pan-Pacific open model safety collaborations. Our first cluster’s funding is backed by private philanthropic donations to safeguard the open frontier.
Who it serves
Our Singapore cluster serves open model labs, academics and safety hubs in Asia, where access to dedicated AI safety compute and international evaluation networks is most limited. As the open frontier expands from China and the United States to other countries, we’re ready to expand our Singapore cluster to answer the need for sovereign AI safety compute.
For model developers
We provide compute for frontier model safety evaluations, free.
Testing dangerous capabilities before open-weight releases is a core mandate of our Singapore hub. Working with labs and evaluation partners before a model release means a safer open frontier.
Pre-release weights are sensitive, and many labs have private safety evals that contain proprietary techniques. We work with labs on both sides of the Pacific to make sure that no matter the safety or security requirements, we can provide compute to contribute to the safety and evaluation of new model launches.
For safety researchers
Discounted AI Safety Compute
Safety and alignment work needs sovereign, independent compute resources to thrive.
Affordable, effective compute resources will help create incentives for more safety work across the open frontier. From targeted red-teaming, to interpretability to replication, we’re providing the compute and support to power AI safety.
Working together
Trust, safety and security
Who handles what, from the first inquiry to the findings package.
- First contact
- Our intake team receives your contact details and a non-sensitive description through our email provider. WeChat follow-up is manual; do not send checkpoints or confidential findings in the first inquiry.
- Target weights
- For endpoint-based evaluations, your lab hosts the model and controls access. Unreleased weights stay on your side by default, with only trusted partnerships granting deeper access. Our compute runs the surrounding evaluation work.
- Evaluation findings
- Findings go privately to the lab’s designated team. Participation does not require publication of results or public acknowledgement of the collaboration.
- Research materials
- Confidentiality terms define who can handle research materials, what they may be used for, and how long they are retained. Access to job metadata and monitoring records is agreed separately.
- Operational records
- Pacific Compute keeps minimal records of the work performed with our cluster, to ensure that we keep our promise of safety-only work. We will work with your team to ensure that the privacy and security policies you have in place are respected.
Lab-controlled tenancy is designed to keep your engineers in control of the partition, model keys and approved users. We agree configuration, custody and security requirements directly with your lab before work begins.
Before sharing sensitive materials, we agree confidentiality terms and the people needed to carry out the evaluation. A first inquiry needs only a short, non-sensitive description.
Lab-controlled tenancy ↓Why we do this work
Safety evaluations should not compete for GPUs with capability work. Our mission is to help open model labs release open-weight models with a full safety eval suite, and to support researchers doing important safety work with open frontier models.
Additional safety work in the pre-release window benefits the entire open model ecosystem by providing safer, more aligned models to the community of open model developers and researchers.
Access & custody
Pre-release is the priority.
Two configurations answer different needs. Endpoint access supports black-box evaluations.
Pre-release, without transferring target weights.
Endpoint workflow
The lab hosts the endpoint and sees every query.
GPU-backed models run alongside tool environments and evaluation orchestration.
The resource split depends on the suite. Endpoint testing also requires agreement on model identity, access limits and evaluation independence.
White-box access, under the lab’s control.
Dedicated lab-operated partition
Private target weights + evaluationRestricted egress · Agreed workload policy
Lab-controlled tenancy is designed to keep your engineers in control of the partition, model keys and approved users. We agree configuration, custody and security requirements directly with your lab before work begins.
Safety fine-tuning
No gradient updates is our default rule. In rare cases where evaluation uncovers a dangerous issue requiring urgent mitigation, we can support limited supervised fine-tuning in a lab-controlled partition of our cluster, followed by re-evaluation.
After release: the supporting programme
Open weights can run locally for durability testing, interpretability and replication. This supporting programme complements the pre-release campaigns.
An illustrative campaign
Built around the release window.
Target three weeks. Four weeks maximum, from agreed kickoff through findings delivery and the scoped retest.
- Model & access
- One pre-release model, hosted by the lab. An identified version and agreed endpoint capacity.
- Evaluation scope
- Two agreed safety domains, initial tests, investigation and reproduction. A follow-up candidate can be retested within the agreed window.
- What the lab receives
- A private findings memo, supporting evidence, methods and limitations, a retest record and a resource statement. No safety certification.
- Week 1
Calibrate and begin
Confirm the eval suite, access conditions, and compute requirements. Run tests and configure.
- Week 2
Investigate and reproduce
Run the main evaluation. Bring material findings to the lab as they arise.
- Week 3 · Week 4 if needed
Retest and deliver
Finish the agreed retest and findings package.
Inside the findings package
Illustrative document structure—not findings from a completed campaign. Delivered privately to the lab.
| Question | Model version, access mode and the safety question investigated. |
|---|---|
| Test coverage | Tests completed, trial counts, conditions and work left untested. |
| Findings | Observations tied to supporting evidence, including negative or inconclusive results. |
| Limitations | Uncertainty, scoring checks and what the evidence cannot establish. |
| Reproduction & retest | Reproduction records and scoped retest results, or why a retest was not possible. |
| Resources | Compute and endpoint use, staff time, storage/transfer and reconciled costs. |
Findings go privately to the lab’s designated team. Participation does not require publication of results or public acknowledgement of the collaboration.
Discuss a campaign ↗Cluster Rules
Rules of our Singapore Cluster
Open Frontier Safety Work Only
Pacific Compute offers compute for evaluation, diagnosis and safety research. Permitted jobs and access are agreed before work begins. Workload restrictions are part of our operating requirements; we work with partners on these narrow jobs, and never work on model capability.
No gradient updates is our default rule. In rare cases where evaluation uncovers a dangerous issue requiring urgent mitigation, we can support limited supervised fine-tuning in a lab-controlled partition of our cluster, followed by re-evaluation.
Open Frontier Models
We work with released open weights and models intended for open release. Unreleased target weights require an explicit access agreement.
Accountable use
We work with the open frontier labs while respecting their security and confidentiality requirements. To ensure all partners use our compute for safety work, we inspect job metadata and have simple, privacy-respecting monitoring systems in place. We are testing telemetry-based workload classification for the cluster, to ensure sensitive data and model weights can remain secure. Record access is agreed with the lab; philanthropic funders receive no access.
Read more on telemetric cluster monitoring: the paper and limitations ↗No political work
Pacific Compute doesn’t support safety work related to politics: no bias-testing, censorship, or politics of any kind. This rule is strictly enforced, even for private evals. The same scope applies to every participating lab and researcher.
Put compute to work.
Bring a model, an evaluation, or the funding to make it happen.