- The Cyber Verification Program now has three access tiers, and each includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models.
- Defense Access covers defensive security work, while Red Team Access adds authorized penetration testing and red teaming.
- Specialized Access has the fewest cyber blocks and is limited to verified organizations testing safety systems that could affect people’s lives or disrupt markets.
Anthropic expanded its Cyber Verification Program on Oct 6, 2026, creating three access tiers for qualifying cybersecurity professionals. The program provides advanced cyber capabilities and reduced blocking classifiers, the company said.
Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation, and Red Team Access adds authorized penetration testing and red-teaming. Specialized Access is reserved for verified organizations authorized to test safety systems that could impact people’s lives or disrupt markets.
Anthropic said organizations enrolled in the program must retain data so it can monitor for cyber misuse. The Cyber Verification Program is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry.
On this page
Anthropic measured different blocking levels across the tiers
Anthropic’s CyScenarioBench testing showed that every task was blocked on its first prompt without Cyber Verification Program access. Defense Access blocked 46 of 50 trials at some point, while four tasks succeeded.
Red Team Access produced no blocks in the test, and Claude Opus 5.5 completed 34 of 50 CyScenarioBench tasks.
Project Glasswing partners found 129,000 verified vulnerabilities
Anthropic said Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. More than 33,000 of those vulnerabilities had been rated critical or high severity.
The company said its own open-source scanning found another 5,500 verified software vulnerabilities between April and October 2026. Anthropic said its vulnerability total is likely an undercount and it expects the true impact to be at least five times higher.
Anthropic requires data retention for enrolled organizations
Data retention is required for organizations enrolled in the program so Anthropic can monitor for cyber misuse. The company said Enterprise Frontier Safeguards will later offer eligible organizations a way to store data in cloud infrastructure they control.
The company said Enterprise Frontier Safeguards combines the privacy of zero data retention with safeguards and will be available later this fall.
Organizations can apply to the program, but Anthropic said applicants will be verified and must provide proof of the security controls required for the relevant access tier.
FAQ
What did Anthropic change in its Cyber Verification Program?
Anthropic expanded the program into three access tiers that provide qualifying security professionals with advanced cyber capabilities and reduced blocking classifiers.
What are Anthropic’s three Cyber Verification Program tiers?
The tiers are Defense Access, Red Team Access and Specialized Access. Defense Access supports defensive work, Red Team Access adds authorized penetration testing and red teaming, and Specialized Access is reserved for verified organizations testing high-impact safety systems.
Which models are included in Anthropic’s cyber access tiers?
Each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models moving forward.
How does Anthropic control cyber misuse in the program?
Anthropic requires data retention for organizations enrolled in the program so it can monitor for cyber misuse. Applicants must also provide proof of the security controls required for their access tier.
Where is Anthropic’s Cyber Verification Program available?
The program is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry.
How many vulnerabilities did Project Glasswing uncover?
Anthropic said Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, while its own open-source scanning found another 5,500 between April and October 2026.
Sources
- We Asked 100+ AI Models to Write Code. Here’s How Many Failed Security Tests. | Veracode, VeracodePrimary
- GitHub - patrickmgarrity/Anthropic-Credited-CVEs: Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team, GitHubPrimary
- Expanding the Cyber Verification Program, AnthropicPrimary
- Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws, The Hacker News
- Anthropic loosens Claude’s cyber restrictions for verified defenders, Help Net Security
How we checked this story
| Claim | Source | Status |
|---|---|---|
| Anthropic said its expanded Cyber Verification Program makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. | Anthropic | Confirmed |
| Anthropic’s program has three access tiers, each including access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models. | Anthropic | Confirmed |
| Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. | Anthropic | Confirmed |
| Red Team Access adds authorized penetration testing and red-teaming to defensive uses. | Anthropic | Confirmed |
| Specialized Access has the fewest cyber blocks and is reserved for verified organizations authorized to test high-impact safety systems. | Anthropic | Confirmed |
| Anthropic requires data retention for organizations enrolled in the program to monitor for cyber misuse. | Anthropic | Confirmed |
| Anthropic said Enterprise Frontier Safeguards will later let eligible organizations store data in cloud infrastructure they control. | Anthropic | Confirmed |
| Without CVP access, every CyScenarioBench task was blocked on the first prompt. | Anthropic | Confirmed |
| Defense Access blocked 46 of 50 CyScenarioBench trials, while four tasks succeeded. | Anthropic | Confirmed |
| Red Team Access had no blocks and Claude Opus 5.5 completed 34 of 50 CyScenarioBench tasks. | Anthropic | Confirmed |
| Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. | Anthropic | Confirmed |
| Anthropic found an additional 5,500 verified software vulnerabilities through open-source scanning between April and October 2026. | Anthropic | Confirmed |
| More than 33,000 of the verified vulnerabilities had been rated critical or high severity. | Anthropic | Confirmed |
| Anthropic said its vulnerability total is likely an undercount and expects the true impact to be at least five times higher. | Anthropic | Confirmed |
| Anthropic said organizations can apply to the Cyber Verification Program and that applicants must provide proof of required security controls. | Anthropic | Confirmed |
| The Cyber Verification Program is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. | Anthropic | Confirmed |
| Help Net Security reported that Anthropic expanded its Cyber Verification Program with three access tiers for security teams. | Help Net Security | Attributed |
| The Hacker News reported that Anthropic said it was expanding a program allowing vetted cybersecurity professionals to test advanced models with reduced safeguards and blocking classifiers. | Anthropic, via The Hacker News | Attributed |
| The Hacker News reported that Anthropic claimed Project Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026. | The Hacker News | Attributed |
| VulnCheck researcher Patrick Garrity reported that two of 300 vulnerabilities discovered by Anthropic or Project Glasswing had been exploited in the wild. | Patrick Garrity, via The Hacker News | Attributed |
| The Hacker News said the two vulnerabilities with active exploitation efforts were CVE-2026-26980 in Ghost CMS and CVE-2026-61500 in Rejetto HTTP File Server. | The Hacker News | Attributed |
| Veracode’s 2025 report tested more than 100 large language models across Java, Python, C#, and JavaScript. | Veracode | Confirmed |
| Veracode reported that 45% of code samples failed security tests and introduced OWASP Top 10 vulnerabilities. | Veracode | Confirmed |
| Patrick Garrity said a GitHub tracker lists 128 fixed Anthropic findings without CVEs and 243 findings withdrawn by Anthropic. | Patrick Garrity, via GitHub | Attributed |
| veracode.com published its report on Jul 30, 2025. | veracode.com | Confirmed |
| Anthropic published its report on Oct 6, 2026. | Anthropic | Confirmed |
Could not verify
- Whether the 129,000 reported vulnerabilities were independently validated is not established.
- Whether the vulnerabilities discovered through Project Glasswing were exploited beyond the two reported cases is not established.
- How many organizations or people have received CVP access is not established.
- Whether CVP access caused any real-world security improvement is not established.



