Access now follows the work being done

Anthropic expanded its Cyber Verification Program on October 6, combining it with the access route used by Project Glasswing. The revised program separates ordinary defence, authorised adversarial testing and work on sensitive systems into three tiers. It includes Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, according to the company.

Defense Access covers tasks such as incident response and malware analysis. Red Team Access adds authorised penetration testing, where a team deliberately probes a system for weaknesses. Specialized Access is reserved for selected organisations testing safety-critical systems. Individuals can seek defensive access, but the red-team tier is currently limited to organisations. These are verified grants, not an unrestricted public release.

The application is only the start

The program guide says an organisation should apply once, with its administrators assigning access afterward. Applicants describe their security work and attest to the required controls. Approval can be reviewed, narrowed or withdrawn, and Anthropic's usage policy continues to apply.

The published security requirements make the identity boundary concrete. Users must sign in as themselves; shared sessions are prohibited. Requests must be attributable to a named user or workload identity. The organisation also needs a security contact able to act on misuse alerts.

Defense Access users must have multi-factor authentication from the outset. By December 15, the requirements call for phishing-resistant authentication, such as passkeys or security keys, and an end to long-lived static credentials. Until that cutoff, permitted API keys must be replaced at least every seven days. Red-team access has stronger controls immediately, including managed devices and restrictions on outbound traffic during offensive or agentic work.

Fewer blocks still means boundaries

The announcement says red-team users will still encounter blocks on actions that could cause physical harm or mass disruption. Permission to test a system remains essential. Access to a more capable model is not permission to target somebody else's infrastructure.

Anthropic generally requires retention to monitor program misuse. It describes a transitional zero-retention exception for some organisations already using Fable 5.1 or Mythos 5.1. Its separate rules say individual defensive grants are retained and monitored, without zero retention.

The planned Enterprise Frontier Safeguards system would instead store monitoring data in customer-controlled cloud infrastructure and send flags to the customer's own reviewers. Anthropic says it will roll out in phases later this fall. That is a future route, not a privacy setting every applicant can enable now.

For a security team, the relevant decision is therefore not just which model can find a weakness. It is whether the authorised scope, identity controls and data arrangements fit the work. How well the expanded safeguards perform outside the company's evaluations remains open.

Sources

  1. Anthropic: Cyber Verification Program expansion, October 6Primary dated announcement defining three tiers, allowed scope, model access, residual blocks and transitional retention exception. Company efficacy figures not repeated.
  2. Claude Help: Cyber Verification ProgramPrimary application, grant administration and continuing usage-policy requirements. No application submitted.
  3. Claude Help: Cyber Verification Program security requirementsPrimary identity, credential, December 15 cutoff, managed-device and individual retention rules.
  4. Anthropic: Enterprise Frontier SafeguardsPrimary September 1 description of future customer-controlled monitoring data and customer review; rollout remains planned later this fall.