Security professionals can now apply for broader Claude access through an expanded Cyber Verification Program. Announced October 6, the change combines CVP and Project Glasswing into three tiers covering defensive investigations, authorized attack simulations and testing of high-risk systems.
Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 are included. Applicants must establish their identity, security controls and the scope of their work. A Claude subscription alone does not grant these permissions. Google makes a similar distinction between its public model and restricted Gemini Flash Cyber access.
Defensive access extends to independent researchers
Defense Access covers incident response, malware analysis and vulnerability checks on systems an applicant owns or maintains. Eligible applicants can include hospitals, universities, small security firms and open-source maintainers, alongside independent researchers with a record of reporting vulnerabilities.
Red Team Access permits authorized penetration testing, where a team attempts to break into a system to identify weaknesses. Only organizations can join this tier. Restrictions remain on actions that could cause physical harm or widespread disruption.
Specialized Access is intended for a limited group authorized to test high-risk systems such as power grids and flight software. Anthropic reviews applicants with the US government. Existing Glasswing members move into this tier without reapproval for the models they already use.

Approval and activation are separate steps
According to the application instructions, applicants use Anthropic’s Verification Portal, then Programs > Cyber Verification Program > Apply. An organization submits one application describing its work and demonstrating the required security controls. Independent applicants can seek access for defensive work.
Once approved, a Console administrator needs to check that the relevant workspaces meet the program’s requirements and have the appropriate access. Anthropic’s workspace setup guide covers activation and troubleshooting. Approval for CVP does not remove provider-specific setup requirements.
Data retention remains a condition
CVP requires retained data for misuse monitoring. Organizations already approved for zero data retention on Fable or Mythos have a temporary exception. Enterprise Frontier Safeguards, planned for later this fall, would let eligible customers keep monitoring data in cloud infrastructure they control. That remains cloud computing, rather than a model running on your own computer. Our local AI versus cloud AI guide explains that distinction.
Anthropic’s accompanying chart shows an internal Opus 5.5 evaluation. Red Team completed 34 of 50 offensive-scenario attempts. None of the 50 attempts encountered a block. A lack of blocks does not guarantee completion, and this test does not establish safety across real-world systems. Ordinary code reviews and fixes for known issues remain available through generally accessible Claude models without CVP approval.

The conversation starts here
Sign in with a supporter account to comment. Sign in




Nobody has commented yet. Want to go first?