Anthropic Grants Security Teams Deeper Claude 5.5 Access
Anthropic has expanded its Cyber Verification Program into three tiers, granting vetted security teams less-restricted access to Claude 5.5 models to accelerate vulnerability discovery.

Anthropic is restructuring its Cyber Verification Program (CVP) into a three-tiered system to give authorized security professionals access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 with fewer automated safety blocks. The new tiers—Defense Access, Red Team Access, and Specialized Access—adjust conservative cyber classifiers based on the user's identity and intent. Defense Access covers tasks like malware reverse engineering and incident response. Red Team Access adds authorized penetration testing for organizations, while Specialized Access allows testing of critical infrastructure like power grids and flight operations under joint review with the U.S. government.
To evaluate the impact of these relaxed guardrails, Anthropic tested Claude Opus 5.5 on CyScenarioBench, a benchmark for multi-stage cyber operations. Under Red Team Access, the model achieved a 67.6 percent task completion rate, matching the performance of an entirely unsafeguarded baseline. In contrast, the more restrictive Defense Access tier blocked 92 percent of offensive trials. Out of 50 trials under the Red Team setting, 16 failed to complete due to non-classifier issues rather than safety blocks.
The program's expansion follows successful trials under Project Glasswing. Between April and July 2026, participating organizations discovered more than 129,000 verified vulnerabilities. Anthropic's own open-source scanning uncovered an additional 5,500 bugs between April and October 2026, bringing the total to over 134,500. More than 33,000 of these vulnerabilities received critical- or high-severity ratings. Some participants reported that the Mythos model shortened their discovery timelines by months or even years.
Vetted teams can apply for CVP access through Anthropic's portal, with models hosted on the Claude Platform, Google Cloud's Vertex AI, and Microsoft Foundry. Access via Amazon Bedrock requires eligibility for Enterprise Frontier Safeguards, a feature launching in fall 2026 that will allow organizations to retain data within their own controlled cloud infrastructure.
This is our own summary of reporting by AlphaSignal



