Anthropic Expands Cyber Verification Program for Claude
Anthropic has expanded its Cyber Verification Program to offer security researchers tiered, low-restriction access to powerful models like Claude Opus 5.5 for defensive and offensive testing.
Anthropic is launching an expanded version of its Cyber Verification Program (CVP), combining its previous CVP and Project Glasswing initiatives into a single, three-tiered offering. The program grants qualified security professionals access to advanced cyber capabilities with reduced safety-blocking classifiers on the company's most powerful models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and Claude Fable 5.1. Because cybersecurity tools are inherently dual-use, Anthropic's generally available models maintain strict safeguards, but the new CVP tiers allow defenders to bypass these restrictions based on their specific roles.
The program features three distinct access levels. Defense Access is designed for defensive tasks like malware reverse-engineering and vulnerability analysis, with applications reviewed in a few days. Red Team Access adds authorized penetration testing capabilities, though it still blocks actions causing physical harm or mass disruption; this tier takes several weeks to approve. Specialized Access, reviewed in collaboration with the U.S. government, offers the fewest restrictions for testing critical infrastructure like power grids and flight systems. To monitor for misuse, Anthropic requires data retention unless organizations use the upcoming Enterprise Frontier Safeguards (EFS) system, which launches this fall to enable zero data retention on cloud infrastructure controlled by the user.
To test these safeguards, Anthropic evaluated Claude Opus 5.5 on CyScenarioBench. Without CVP access, the model was blocked on every task. Under the Defense Access tier, 46 out of 50 trials were blocked, while the Red Team Access tier experienced zero blocks and successfully completed 34 of 50 tasks, matching the model's baseline 67.6% success rate. This tiered approach builds on Project Glasswing, where partners using Claude Mythos identified 129,000 verified software vulnerabilities between April and July 2026, while Anthropic's open-source scanning found another 5,500 between April and October 2026. Over 33,000 of these vulnerabilities were classified as high- or critical-severity, with partners reporting that the models accelerated their vulnerability discovery by months or years.
This is our own summary of reporting by Anthropic



