Anthropic loosens Claude’s cyber restrictions for verified defenders
Anthropic expanded its Cyber Verification Program (CVP), giving approved security professionals access to advanced Claude capabilities with fewer automated blocks on work such as malware analysis and vulnerability testing.

Three tiers for cybersecurity work
The program now has three tiers based on the scope of applicants’ cybersecurity work. The expansion combines CVP and Project Glasswing into a single program.
Each tier has verification requirements and security controls tailored to the work it permits.
Defense Access covers incident investigation, malware analysis, and vulnerability analysis and validation. Eligible applicants include security teams at businesses, nonprofits, universities, and government organizations protecting systems they own or maintain. Critical infrastructure operators, smaller security firms, open-source maintainers, and individual researchers with a record of reporting vulnerabilities may also qualify. The company expects many companies conducting defensive security work to qualify and aims to respond to applications within a few days.
Red Team Access adds authorized penetration testing and simulated attacks to those defensive tasks. It is intended for internal and government red teams and security testing firms. Participants may test only systems they are authorized to assess. Actions that could cause physical harm or widespread disruption, including deploying ransomware or testing high-risk safety systems, remain subject to real-time blocks. Reviews may take a few weeks. Qualifying organizations will receive Defense Access during the review. Individual researchers are currently ineligible for this tier.
Specialized Access has the fewest cybersecurity blocks and is reserved for a limited group of verified organizations authorized to test high-risk systems. These include flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks, where disruption could affect people’s lives or markets. The company reviews each applicant in collaboration with the US government. Existing Project Glasswing members will move to this tier without reapproval for the models they already use.
“Our generally available models can continue to be used for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts,” the company explained.
The program requires data retention to allow Anthropic to monitor for cybersecurity misuse. Enterprise Frontier Safeguards, expected later this fall, will allow eligible companies to store data in cloud infrastructure they control while maintaining safeguards against misuse. Until Enterprise Frontier Safeguards becomes available, organizations approved to use Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP with zero data retention.
Benchmark results by access tier
Anthropic tested Claude Opus 5.5 using CyScenarioBench, which measures whether models can plan and execute multistage cyber operations under realistic constraints. The tests used safeguards configured for the CVP tiers, with five attempts at each of the benchmark’s 10 challenges.
Without CVP access, all 50 trials were blocked at the first prompt. Under Defense Access, 46 trials were blocked at some point, and four succeeded. Under Red Team Access, none encountered blocks, and the model completed 34 of the 50 trials.
Vulnerabilities found through Project Glasswing
Project Glasswing partners used Claude Mythos models to uncover at least 129,000 verified software vulnerabilities in their systems between April and July 2026. Anthropic identified another 5,500 through open-source scanning between April and October.
More than 33,000 of the vulnerabilities have been rated critical or high severity. The company said the figures likely undercount the findings because they draw on data from only a subset of Glasswing partners.
Access and availability
Existing CVP members will be evaluated automatically for access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Their settings for previous models will remain in place. Applicants must undergo verification and provide proof of the security controls required for their access tier.
The program is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. Access through Amazon Bedrock is limited to customers eligible for Enterprise Frontier Safeguards.