Models

Anthropic expands Cyber Verification Program with three access tiers

October 11, 2026 · 3 min read

a close up of a computer screen with a menu on it
Emiliano Vittoriosi / Unsplash

Anthropic has extended its Cyber Verification Program by merging it with the Glasswing project to provide verified users with access to its most advanced artificial intelligence models without standard safety filters. This initiative targets cybersecurity professionals, researchers, enterprises, public organizations, and governments seeking to enhance their defensive capabilities against cyber threats. The expansion introduces a structured framework for granting access to reasoning models that are typically restricted due to their potential misuse in creating malicious software.

The program establishes three distinct levels of access: Defense, Red Team, and Specialized. The Defense tier is available to cybersecurity teams, researchers, software publishers, and open-source maintainers. These users can review code, update threat models, identify and fix known vulnerabilities, and triage security alerts using publicly available Claude models. While basic tasks remain accessible without special verification, advanced functions such as malware analysis, exploitation validation, and vulnerability prioritization by severity are blocked for general users but unlocked for those with Defense access.

The Red Team tier is designed primarily for penetration testing firms. Participants in this category can use Anthropic's large language models to emulate attacks, conduct penetration tests, and develop tools for finding and validating vulnerabilities. This access allows for more aggressive testing scenarios that are not permitted under the standard Defense tier, enabling security firms to better prepare for real-world attack vectors.

The Specialized tier is reserved for a limited group of entities, including maintainers of critical infrastructure such as power grids, telecommunications, airport systems, and financial networks. It also includes the United States government, allied governments, banks, regulated enterprises, and a select few cybersecurity companies. Existing members of the Glasswing project automatically qualify for this tier. New applicants must undergo a rigorous vetting process, with the U.S. government validating candidates. This level permits penetration testing on critical infrastructure and research into the most severe exploitation techniques.

Independent researchers are restricted to the Defense tier, while enterprises need only submit a single application form. Applicants must provide details about their organization and the individuals who will use the models. Anthropic verifies eligibility and requires proof of necessary security controls for the requested access level. The process includes identity verification and a brief questionnaire about use cases, supported by minimal evidence. Justin Scott, founder and CEO of Outpost Business Solutions, reported being approved within hours of applying and noted an immediate difference in capability.

The program covers Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future large language models from the provider. Users with Defense access must stop using direct API keys and switch to multi-factor authentication, such as through Workload Identity Federation, by December 15. Data retention is mandatory for enrolled organizations to allow Anthropic to monitor for abuse. Once Enterprise Frontier Safeguards becomes available at the end of autumn, eligible organizations will be able to store their data in cloud infrastructure they control. Currently, only companies with access to Claude Fable 5.1 and Mythos 5.1 under a no-conversation data policy can retain this option within the program.

The expansion does not incur additional billing beyond Anthropic's public pricing grid. Access is available through the Claude platform, Google Cloud Vertex AI, and Microsoft Foundry. Organizations interested in the Enterprise Frontier Safeguards option must use Amazon Bedrock. Anthropic states that its partners identified at least 129,000 verified software vulnerabilities between April and July 2026. Additionally, Anthropic's own analysis of open-source software discovered 5,500 additional verified vulnerabilities between April and October 2026. The company asserts that this expansion aims to equip a larger number of cyber defenders with the necessary tools.