Updated:
Anthropic on Tuesday, October 6, expanded its Cyber Verification Program, offering verified cybersecurity professionals tiered access to advanced Claude models for defensive work and authorized testing. The San Francisco-based AI company said the program covers Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, as well as future models.
The revised structure gives security teams different levels of access according to their work and security controls, with the broadest access reserved for a limited number of organizations reviewed in collaboration with the U.S. government. The change extends work begun through Project Glasswing, Anthropic’s initiative to help organizations find and fix vulnerabilities in critical software.
Three tiers distinguish defensive work from higher-risk testing
Defense Access is intended for tasks such as incident response, malware reverse-engineering, vulnerability analysis and security operations. Anthropic said eligible applicants could include security teams protecting systems they own or maintain, critical-infrastructure operators, universities, open-source maintainers and individual researchers with a track record of reporting vulnerabilities. The company expects many organizations doing defensive cybersecurity work to qualify and aims to respond to applications within a few days.
Red Team Access adds authorized penetration testing and red-team exercises. It is available to organizations, including government red teams and security firms, testing systems they have permission to assess. Anthropic said applications for this tier could take a few weeks to review; applicants are placed in Defense Access while their request is assessed. The company also said users will continue to face blocks on actions that could cause physical harm or broad disruption, including deploying ransomware or damaging physical systems.
Specialized Access is for a smaller group authorized to test systems where disruption could have serious consequences, such as power grids, flight systems, telecommunications networks, interbank-transfer infrastructure and government administrative networks. Anthropic said it reviews each organization in this tier in depth with the U.S. government. Existing Project Glasswing members will move into Specialized Access without needing reapproval for current models.
Anthropic reports different results across safeguards
To assess the tiered controls, Anthropic tested Claude Opus 5.5 on CyScenarioBench, an evaluation of multi-stage cyber operations. The company said that without Cyber Verification Program access, all 50 trials—five attempts at each of 10 challenges—were blocked on the first prompt.
In Defense Access, Anthropic said 46 of 50 trials were blocked at some point, while four tasks succeeded. In Red Team Access, the company reported no blocks and successful completion of 34 trials. Anthropic said that result was comparable to the model’s performance with no safeguards applied. These figures come from the company’s own evaluation; they do not establish how the model or controls would perform across every real-world security task.
Glasswing results underpin the expansion
Anthropic said Project Glasswing partners identified at least 129,000 verified software vulnerabilities from April through July 2026 using Claude Mythos models. Its own open-source scanning work found a further 5,500 verified vulnerabilities between April and October. More than 33,000 of the combined findings were rated critical or high severity, according to the company.
Anthropic cautioned that the partner total is based on reports from only a subset of Glasswing participants and is likely an undercount. It said that fewer than half of partners reported how many vulnerabilities had been patched, in part because fixes were still in progress. The company also relayed that some partners believed the models had accelerated their discovery work by months or years; that assessment was attributed to participants, not an independently measured industry-wide result.
Monitoring and deployment details
Organizations enrolled in the program must allow data retention so Anthropic can monitor for possible misuse. The company said eligible organizations will be able to keep data in cloud infrastructure they control once its Enterprise Frontier Safeguards solution becomes available later this fall. Until then, some organizations using Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention may also use the Cyber Verification Program under that arrangement.
Anthropic said the program is available through its Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. Availability on Amazon Bedrock is limited to customers eligible for Enterprise Frontier Safeguards. Existing members will be evaluated for access to the updated models, while other organizations can apply and must provide evidence of the security controls required for their selected tier.







