Anthropic Expands Cyber Verification Program with Three Access Tiers
Key point
The program now offers Defense, Red Team, and Specialized access levels for security professionals to use models like Claude Opus 5.5 with reduced blocking.
Details
Anthropic has launched an expanded version of its Cyber Verification Program (CVP), integrating previous initiatives like Project Glasswing into a unified offering for security professionals. The program provides access to advanced cyber capabilities and reduced blocking classifiers for models including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1.
New Access Tiers
The updated program consists of three distinct access tiers, each with specific verification requirements and security controls:
- Defense Access: Designed for defensive tasks such as incident response, malware reverse-engineering, and vulnerability validation. Qualifying entities include security teams at companies, nonprofits, universities, government bodies, critical infrastructure operators, and open-source maintainers. Applications are expected to be reviewed within a few days.
- Red Team Access: Adds authorized penetration testing and red-teaming capabilities. This tier is restricted to organizations (in-house red teams, government red teams, and security firms) and requires stricter verification, with reviews taking a few weeks. Users remain subject to real-time blocks on actions causing physical harm or mass disruption.
- Specialized Access: Reserved for a limited set of verified organizations authorized to test safety-critical systems like flight operating systems and power grids. This tier has the fewest cyber blocks and involves in-depth review in collaboration with the US government. Existing Project Glasswing members transition to this tier automatically.
Efficacy and Impact
Anthropic evaluated the program's efficacy using CyScenarioBench, an evaluation measuring multi-stage cyber operations. Results showed that without CVP access, all tasks were blocked. In the Defense Access tier, 46 of 50 trials were blocked, while the Red Team Access tier saw no blocks and a 67.6% success rate, matching the model's performance with no safeguards.
The expansion aims to scale the success of Project Glasswing, which helped partners uncover at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic’s own scanning efforts identified an additional 5,500 verified vulnerabilities between April and October 2026, with over 33,000 rated as critical or high-severity. The company estimates the true impact is at least five times higher due to undercounting in partner reports.
Availability and Data Retention
CVP is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. Access on Amazon Bedrock is limited to customers eligible for Enterprise Frontier Safeguards (EFS). Data retention is currently required for monitoring, but eligible organizations will be able to use zero data retention once EFS is available later this fall.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.