Anthropic merged Project Glasswing and the old Cyber Verification Program into one program with three tiers for vetted security professionals: Defense, Red Team and Specialized. For the first Anthropic aims to answer within a few days; for the third, with the fewest blocks, it currently reviews every organization together with the US government.
- Three tiers: Defense Access (defensive work), Red Team Access (authorized pen testing, organizations only), Specialized Access (fewest blocks, reviewed with the US government).
- Every tier includes Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Glasswing and the old CVP become one program.
- By Anthropic's own data: in Red Team Access Opus 5.5 completes 34 of 50 tasks with no blocks, in Defense Access 46 of 50 trials are blocked. Enrolled organizations' data is retained.
You hand the generally available Claude some security work and you often hit a wall. Anthropic says so itself: the models anyone can use carry conservative safeguards that block most cyber work.
Now, three doors.
A document opens the door. Anthropic verifies every applicant and asks for proof of the security controls for the tier.
The first tier is the widest. Anthropic expects many organizations to qualify: security teams at companies, nonprofits, universities and government bodies, operators of critical infrastructure of any size such as regional hospitals or municipal utilities, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. The second is for organizations only. While their application is reviewed, they sit in the first.
Anthropic measures its safeguards on one test, CyScenarioBench, with Opus 5.5. By its own data, without program access every task is blocked on the first prompt. In Defense Access 46 of 50 trials are blocked somewhere along the way and four succeed. In Red Team Access there is not a single block and Opus 5.5 completes 34 of 50 tasks, the same as with no safeguards at all. The test is on its model, with its safeguards, measured by it.
The upper limit does not vanish. Even in Red Team Access real-time blocks stay for ransomware and for anything that could damage physical systems. And the third tier, with the fewest blocks, is not for everyone.
The application is for the tier that fits your work. Before you send it, count the price: the data you send is retained so Anthropic can monitor for misuse. A cloud under your own control comes with Enterprise Frontier Safeguards, only for eligible organizations and “later this fall”, with no date.