we_are_coded.by CODE · The world, decoded
БГ
Anthropic

Anthropic puts its cyber capabilities on three access tiers, and vets applicants for the third together with the US government

Anthropic · event date: 6 October 2026Frontier

Anthropic merged Project Glasswing and the old Cyber Verification Program into one program with three tiers for vetted security professionals: Defense, Red Team and Specialized. For the first Anthropic aims to answer within a few days; for the third, with the fewest blocks, it currently reviews every organization together with the US government.

In short
  • Three tiers: Defense Access (defensive work), Red Team Access (authorized pen testing, organizations only), Specialized Access (fewest blocks, reviewed with the US government).
  • Every tier includes Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Glasswing and the old CVP become one program.
  • By Anthropic's own data: in Red Team Access Opus 5.5 completes 34 of 50 tasks with no blocks, in Defense Access 46 of 50 trials are blocked. Enrolled organizations' data is retained.
Checked on7 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

You hand the generally available Claude some security work and you often hit a wall. Anthropic says so itself: the models anyone can use carry conservative safeguards that block most cyber work.

Now, three doors.

The facts: on 6 October 2026 Anthropic announced an expanded Cyber Verification Program (CVP) with three access tiers for vetted security professionals. Every tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models. Defense Access is for defensive work: security operations, incident response, reverse-engineering malware, analyzing and validating vulnerabilities; Anthropic aims to answer applications within a few days. Red Team Access adds authorized penetration testing and red-teaming, for organizations only, not individual researchers, with a review of a few weeks; real-time blocks remain on actions that could cause physical harm or mass disruption, such as deploying ransomware. Specialized Access has the fewest blocks and is for a limited set of verified organizations authorized to test safety systems that could affect people's lives or disrupt markets: flight operating systems, power grids, telecom networks, interbank transfer infrastructure, government administrative networks. For this tier Anthropic currently reviews every organization in depth together with the US government, and existing Project Glasswing members move there without reapproval for current models. Enrolled organizations must allow data retention so Anthropic can monitor for cyber misuse. Enterprise Frontier Safeguards, a new solution that combines the privacy of zero data retention with safeguards, is promised by Anthropic for “later this fall”. Until then, organizations that already use Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use the program with zero data retention. The program is available on the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry; on Amazon Bedrock only for customers eligible for Enterprise Frontier Safeguards.

A document opens the door. Anthropic verifies every applicant and asks for proof of the security controls for the tier.

The first tier is the widest. Anthropic expects many organizations to qualify: security teams at companies, nonprofits, universities and government bodies, operators of critical infrastructure of any size such as regional hospitals or municipal utilities, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. The second is for organizations only. While their application is reviewed, they sit in the first.

The fewer the blocks, the longer the vetting.

Anthropic measures its safeguards on one test, CyScenarioBench, with Opus 5.5. By its own data, without program access every task is blocked on the first prompt. In Defense Access 46 of 50 trials are blocked somewhere along the way and four succeed. In Red Team Access there is not a single block and Opus 5.5 completes 34 of 50 tasks, the same as with no safeguards at all. The test is on its model, with its safeguards, measured by it.

The upper limit does not vanish. Even in Red Team Access real-time blocks stay for ransomware and for anything that could damage physical systems. And the third tier, with the fewest blocks, is not for everyone.

The application is for the tier that fits your work. Before you send it, count the price: the data you send is retained so Anthropic can monitor for misuse. A cloud under your own control comes with Enterprise Frontier Safeguards, only for eligible organizations and “later this fall”, with no date.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Anthropic - Expanding the Cyber Verification Program, 06.10.2026
Original: https://wearecoded.com/en/articles/anthropic-cyber-verification-program-tri-niva.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news