Skip to content
worth noting Security

Anthropic expands Cyber Verification Program and introduces three access tiers

only one source so far

Anthropic is unifying Cyber Verification Program and Project Glasswing. Three tiers of verified access distinguish between defensive work, authorized attack testing and testing of critical systems; they differ in their verification requirements and security controls.

Anthropic announced an expansion of Cyber Verification Program (CVP), which it is unifying with Project Glasswing. Verified security specialists can apply for one of three access tiers with different security controls and limited blocking of security tasks. Each tier includes Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1.

Defense Access covers defensive operations, incident response, malware analysis and vulnerability verification. Open-source project maintainers and individual researchers with a documented history of reporting vulnerabilities can also apply. The company aims to respond within a few days. Red Team Access adds penetration testing and attack simulations only on systems the organization is authorized to test. It is available only to organizations; according to the company, the review is expected to take several weeks, and eligible organizations will receive Defense Access in the meantime. Activities that could cause physical harm or widespread operational disruption remain blocked.

Specialized Access has the fewest security blocks and is reserved for a limited number of verified organizations authorized to test systems whose failure could endanger lives or disrupt markets, such as power grids or interbank transfer infrastructure. Anthropic vets these organizations in cooperation with the US government. Existing Project Glasswing participants will move to this tier without a new approval process for current models.

The program requires data retention to monitor misuse. Anthropic plans to make Enterprise Frontier Safeguards (EFS) available later in the autumn. According to the company, EFS is intended to combine zero data retention, meaning no data is retained by the provider, with security controls and allow eligible organizations to store data in cloud infrastructure under their own control. Until then, organizations that already have zero data retention for Claude Fable 5.1 or Claude Mythos 5.1 can use the program with zero data retention.

What changed

Why it matters

Security specialists can apply for a scope of access that matches their work, but authorization for defensive analysis does not automatically include attack testing or testing of critical systems. According to the company, generally available models can still be used for routine code reviews, fixes for known bugs and searches for vulnerabilities in your own source code without joining the program.

Two audiences, two different impacts

What this means

01

For individuals

An independent researcher with a documented history of reporting vulnerabilities can apply for Defense Access for defensive work. Red Team Access is not available to individuals.

What to do Before applying for Defense Access, check whether your work and history of reporting vulnerabilities meet the requirements for this tier.
More practical updates →
02

For a business

Involving the company security team requires an assessment of the rules for retaining sensitive data. Zero data retention is currently available only under the stated exception; broader availability through EFS is still planned.

Risks and compliance
What to decide Before involving the team, check that the required data retention complies with company policies on security information.
More business impacts →
Anthropic Claude Mythos 5.1 Claude Opus 5.5 Claude Sonnet 5.5 Cyber Verification Program

Check the original

Event sources

only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
Anthropic News primary source · first detected Expanding the Cyber Verification Program