AVARIXO

Type and hit Enter to search

Anthropic logo for the Cyber Verification Program
AI & Tech

Anthropic Cyber Verification Program: Defense, Red Team and Specialized Access

AVARIXO
October 7, 2026 5 Mins Read
7 Views
0 Comments

Anthropic expanded its Cyber Verification Program on October 6, 2026 into three access tiers—Defense Access, Red Team Access and Specialized Access—while folding the earlier Project Glasswing program into the same framework. The goal is to give legitimate cybersecurity teams more useful access to advanced Claude capabilities without removing safeguards indiscriminately.

The program applies to verified organizations and, for some defensive use cases, qualified individuals. It is meant for work such as incident response, malware analysis, vulnerability research, authorized penetration testing and safety-critical security testing.

The three Cyber Verification Program tiers

TierWho it is forAccess levelTypical review
Defense AccessDefensive security teams, researchers, open-source maintainers and qualified individualsBroader defensive cyber capability with safety controlsOften days
Red Team AccessVerified organizations conducting authorized penetration testing or red teamingFewer blocks for legitimate offensive testingOften weeks
Specialized AccessA small set of verified organizations testing safety-critical systemsFewest cyber-specific blocks under additional reviewCase-by-case, including government coordination

What is the Cyber Verification Program?

Anthropic’s Cyber Verification Program, or CVP, is a controlled-access system for users who need Claude to perform cybersecurity work that can look risky to automated abuse filters. A defensive analyst reverse-engineering malware and an attacker writing malicious code can produce superficially similar prompts. The verification process is intended to distinguish legitimate professional use from harmful intent.

Rather than giving every user unrestricted access, Anthropic verifies the organization, purpose and expected activity, then applies a tier designed for that work.

Defense Access: who qualifies?

Defense Access is the broadest entry point. Anthropic says it is intended for defensive cybersecurity work such as security operations, incident response, malware reverse engineering and vulnerability validation.

Eligible applicants can include established security organizations, smaller security firms, open-source maintainers and individuals with a credible track record. That makes Defense Access materially more accessible than programs limited to large enterprises.

Examples of tasks that can fit the tier include:

  • Investigating suspicious binaries and scripts.
  • Triaging alerts from a security operations center.
  • Validating whether a reported vulnerability is real.
  • Reviewing code for exploitable weaknesses.
  • Analyzing incident artifacts and attacker behavior.
  • Building or improving defensive detection rules.

Red Team Access: authorized offensive testing

Red Team Access is for verified organizations conducting authorized penetration tests, red-team exercises and similar offensive-security assessments. These tasks naturally involve exploit chains, payload logic and attack simulation, so they can collide with ordinary model safety filters more often than defensive analysis.

Anthropic therefore applies a stronger verification process. The company says review can take weeks, although organizations applying for Red Team Access can receive Defense Access while the broader application is pending.

Red Team Access does not mean “no rules.” Certain harmful actions can still be blocked, and authorization remains essential.

Specialized Access: the narrowest and most permissive tier

Specialized Access is designed for a small number of verified organizations working on high-stakes, safety-critical systems where conventional cyber restrictions could prevent important testing. Anthropic describes this tier as having the fewest cyber-specific blocks.

Because of the risk, admission is much narrower. Anthropic says the review process can involve coordination with the U.S. government. This is not positioned as a general enterprise upgrade; it is an exceptional access path for organizations with a strong, verifiable need.

What happened to Project Glasswing?

Project Glasswing is being folded into the expanded CVP. Existing Glasswing members will transition into the new framework without needing to reapply for access to current models.

That consolidation matters because it replaces separate program branding with one tiered structure. Organizations already participating in Glasswing should therefore look for CVP terminology in future documentation and support communication.

Which Claude models are available?

Anthropic says verified cyber users can access advanced Claude models including Claude Opus 5.5, Claude Sonnet 5.5 and Mythos 5.1, with future models also expected to participate in the program as appropriate.

Model availability can still depend on platform, region, tier and product updates, so organizations should confirm the currently enabled model list at the time of approval.

Where is CVP available?

Anthropic says the program is available through the Claude Platform and supported cloud channels including Google Cloud Vertex AI and Microsoft Foundry. Amazon Bedrock availability is more limited and tied to eligible safeguard arrangements.

For security teams already standardized on a cloud platform, that matters because they may be able to keep existing identity, billing and network controls instead of moving sensitive workflows to a separate environment.

What data-retention rules apply?

Cyber access requires enough monitoring for Anthropic to detect misuse, so participating organizations should not assume the same zero-data-retention posture they may use for ordinary enterprise workloads. Anthropic says retention is needed for abuse monitoring under the program.

The company also says an Enterprise Frontier Safeguards option is planned for later in the fall, intended to offer stronger enterprise privacy arrangements while preserving additional safeguards for high-capability cyber access.

Before onboarding sensitive incident data, organizations should review the current contractual retention terms rather than relying on assumptions from a different Claude product.

Why Anthropic expanded the program

Anthropic argues that powerful models can materially improve legitimate security work, but broad cyber filters can produce false positives. The expanded tiering is an attempt to improve the usefulness of Claude for verified defenders without giving every account the same capability.

The company also published security outcomes from earlier work. Anthropic says Project Glasswing partners identified at least 129,000 verified vulnerabilities between April and July, with more than 33,000 classified as critical or high severity. Anthropic’s own open-source scanning work identified thousands more vulnerabilities from April through October.

How effective are the different access tiers?

Anthropic also shared evaluation results showing why verification tiers matter. In one internal test set, the standard defensive configuration blocked most difficult offensive-style prompts at some stage. Red Team Access allowed substantially more of the authorized workflows to complete.

Those results should not be read as a universal benchmark for every security task. They illustrate the tradeoff the program is trying to manage: reducing false refusals for verified users while retaining stronger barriers for ordinary accounts.

How to choose the right tier

  • Choose Defense Access if your work is primarily SOC, incident response, malware analysis, defensive research or vulnerability validation.
  • Choose Red Team Access if your organization performs authorized penetration testing or adversarial simulation that regularly triggers cyber restrictions.
  • Consider Specialized Access only if your organization has an exceptional safety-critical use case requiring the lowest level of cyber-specific blocking.

What should applicants prepare?

A strong application should make the legitimate use case easy to verify. Prepare the organization’s legal identity, security website or public track record, the type of testing performed, authorization practices, expected Claude workflows and the people responsible for governance.

Independent researchers applying for Defense Access should be ready to show a credible history through published research, open-source projects, vulnerability disclosures or comparable evidence.

Frequently asked questions

Is CVP the same as unrestricted Claude?

No. It is a verified-access program with different safety thresholds for legitimate cyber work. Policy and monitoring still apply.

Can individuals apply?

Qualified individuals can be eligible for Defense Access. Red Team and Specialized tiers are oriented toward verified organizations.

Do existing Project Glasswing members need to reapply?

Anthropic says existing Glasswing members transition into the new system without reapproval for current models.

Does CVP support zero data retention?

Do not assume standard ZDR applies. The program requires monitoring and has its own retention considerations; Anthropic has announced additional enterprise safeguard options.

Sources and related reading

Primary source: Anthropic’s Cyber Verification Program announcement, published October 6, 2026.

For more current AI platform coverage, visit AVARIXO’s AI & Tech section and our ChatGPT text watermark explainer.

Share Article

Follow Me Written By

AVARIXO

Other Articles

Official Marathon game artwork for the Nightfall refresh
Previous

Marathon Nightfall Refresh: Reset, Reward Pass and PvE Changes Explained

OpenAI symbol for ChatGPT custom MCP servers
Next

ChatGPT Custom MCP Servers No Longer Need Developer Mode: What Changed

Next
OpenAI symbol for ChatGPT custom MCP servers
October 7, 2026

ChatGPT Custom MCP Servers No Longer Need Developer Mode: What Changed

Previous
October 7, 2026

Marathon Nightfall Refresh: Reset, Reward Pass and PvE Changes Explained

Official Marathon game artwork for the Nightfall refresh

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    AVARIXO — Know More. Sooner.
    Gaming AI & Tech Entertainment Internet Alerts Sports Deals Money News & Explainers Travel
    ☰
    Gaming AI & Tech Entertainment Internet Alerts Sports Deals Money News & Explainers Travel
    More⌄
    ⚡Avarixo ToolsCalculators & converters ◈Original DataTrackers & live datasets
    AVARIXO — Know More. Sooner.

    Fast, useful explainers for what people are searching, discussing and deciding right now.

    ☆

    Join readers who trust Avarixo

    Add Avarixo as a preferred source on Google to see more of our guides in your news results.

    Add to Google Preferences →
    © 2026 AVARIXO
    AboutContactPrivacyTerms