Anthropic Eases Claude’s Cybersecurity Restrictions for Verified Defenders
Anthropic has introduced an updated framework for its Cyber Verification Program (CVP), granting verified cybersecurity professionals enhanced access to advanced Claude models with reduced automated restrictions on activities such as malware analysis and vulnerability assessment.
Three-tiered Access Structure
The program categorizes users into three distinct tiers, each with specific verification criteria and security protocols.
Defense Access
Enables cybersecurity professionals to conduct incident investigations, malware analysis, and vulnerability validation. Eligible participants include security teams from enterprises, academic institutions, government agencies, and organizations responsible for critical infrastructure. Additionally, smaller security firms, open-source maintainers, and researchers with a history of disclosing vulnerabilities may qualify. Anthropic aims to process applications within days, with initial access granted to qualifying entities.
Red Team Access
Allows authorized penetration testing and simulated attacks, targeting internal and government red teams as well as security testing firms. Users in this category are restricted to systems they have explicit authorization to evaluate. Activities posing risks of physical harm or large-scale disruption, such as ransomware deployment or testing of safety-critical systems, remain subject to real-time blocking. Applications for this tier require extended reviews, typically spanning weeks, with Defense Access provided during the evaluation period. Individual researchers are currently excluded from this tier.
Specialized Access
Offers the least restrictive environment and is reserved for a select group of verified organizations tasked with testing high-risk systems. These include aviation control systems, energy grids, telecommunications networks, interbank transfer platforms, and government administrative networks. Disruptions in these domains could impact public safety or economic stability. Anthropic collaborates with U.S. government entities to evaluate applicants for this tier, with existing Project Glasswing members transitioning automatically without reapproval for their current model usage.
Operational Parameters and Testing
Anthropic outlined that its standard models remain suitable for tasks such as code reviews, patching known vulnerabilities, and triaging security alerts. The program mandates data retention to monitor for potential misuse. A forthcoming feature, Enterprise Frontier Safeguards, will enable eligible organizations to store data in their own cloud infrastructure while maintaining security controls. Until this release, approved users of Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can continue utilizing CVP under similar conditions.
Benchmarking Results
To assess performance under the new framework, Anthropic tested Claude Opus 5.5 against CyScenarioBench, a tool evaluating a model’s ability to execute multi-stage cyber operations under constraints. The test involved 50 challenges, with five attempts per scenario. Without CVP access, all trials were blocked at the initial prompt. Under Defense Access, 46 attempts failed at some stage, while four succeeded. Red Team Access allowed all 50 trials to complete without interruption, with 34 successfully executed.
Vulnerability Discoveries
Anthropic noted that these figures likely represent a fraction of total findings, as data was sourced from a subset of partners.
Project Glasswing partners utilized Claude Mythos models to identify 129,000 verified software vulnerabilities in their systems between April and July 2026. An additional 5,500 vulnerabilities were detected through open-source scanning between April and October. Over 33,000 of these were classified as critical or high severity.
Access and Implementation
Current CVP members will be automatically assessed for access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with prior settings retained. Applicants must verify their eligibility and demonstrate compliance with security controls specific to their tier. The program is accessible via the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. Amazon Bedrock access is restricted to users enrolled in Enterprise Frontier Safeguards. The initiative reflects Anthropic’s commitment to balancing advanced AI capabilities with rigorous safeguards, ensuring responsible use in high-stakes cybersecurity environments.
