October 9, 2026

Anthropic Cyber Verification Program: tiers, data retention and who should apply

Anthropic merged Glasswing into a three-tier Cyber Verification Program: who qualifies, the data retention catch, review times and the free OSS scanner.

News

Insight

On October 6, 2026, Anthropic folded Project Glasswing into an expanded Anthropic Cyber Verification Program with three tiers: Defense, Red Team and Specialized Access. It's aimed at companies with an AppSec or platform function that want fewer cyber blocks on Claude, and enrollment comes with required data retention. If you have no security owner, skip to the paragraph on whether you need it at all: the answer is probably no. For other vendor policy shifts, see AI model releases and pricing: what changes for engineering teams.

What the Cyber Verification Program is now

The program announcement says Anthropic is integrating two things into one offering. One is Project Glasswing, which gave Mythos access to "a group of organizations securing the most critical software." The other is the earlier Cyber Verification Program, which offered "reduced safeguards on Claude Opus and Claude Sonnet models."

Each tier covers "Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward." If you want the Opus 5.5 pricing and migration details, what the Opus 5.5 release changed for API users covers them, and we won't repeat them here.

Who qualifies for Defense, Red Team and Specialized Access

The announcement describes Defense as work by security teams at companies, nonprofits, universities and government bodies defending systems they own or maintain: SOC and incident response, malware reverse-engineering, and vulnerability analysis and validation. Open-source maintainers and individuals with a track record of reported vulnerabilities can also apply, and individual Defense Access requires a paid plan, per the Help Center. Red Team adds authorized penetration testing and red teaming. Specialized Access is for a limited set of verified organizations authorized to test safety systems such as flight operating systems and power grids.

TierWho it's forWhat changesReview time
DefenseTeams at companies, nonprofits, universities and government bodies defending systems they own or maintain; individuals can apply here onlySOC, incident response, malware reverse-engineering, vulnerability analysis and validation"A few days" per the announcement, "within seven business days" per the Help Center
Red TeamOrganizations onlyAdds authorized pen testing and red teaming; keeps "real-time blocks on actions that could cause physical harm or mass disruption""A few weeks"; you're enrolled in Defense meanwhile
SpecializedLimited set of verified organizations authorized to test safety systems (flight operating systems, power grids and similar)"Fewest cyber blocks"; in-depth review "in collaboration with the US government"Not stated on the pages we could read

Glasswing members move to Specialized "without reapproval for current models," per the announcement.

Anthropic's Help Center article on the program's safeguards adds that only Defense access is available to individual applicants right now, and that independent researchers, maintainers and bug bounty hunters apply as individuals. Organizations apply once.

The two Anthropic pages disagree on how long Defense review takes. The announcement says "We aim to respond to applications within a few days." The Help Center says the decision or a request for more information arrives "within seven business days." We're reporting both. Plan for the longer one.

What each tier actually unblocks

The announcement says the generally available models "have conservative cyber safeguards that block most cyber work." The same page says they "can continue to be used for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts."

That second sentence is the one to read before applying. If your need is code review, fixing known issues, or finding vulnerabilities in code you own, Anthropic says the models you already have cover it.

Anthropic backs the tiers with its own benchmark, CyScenarioBench, and these are Anthropic's numbers, not independent ones. On the generally available models, every task was blocked on the first prompt. At the Defense tier, 46 of the 50 trials were blocked at some point in the challenge, so four were never blocked. The test used Claude Opus 5.5 across 10 challenges with 5 attempts per tier. At Red Team there were no blocks and 34 of 50 trials completed, which Anthropic says is effectively the model's 67.6% success rate with no safeguards.

So Defense isn't "safeguards off." The Help Center says approved users may still see work like malware analysis or exploit validation interrupted by safety classifiers (we're paraphrasing that page, not quoting it). It also says: "We may review, narrow, or withdraw a grant." Don't build a workflow that assumes the grant is permanent.

On impact, the announcement claims at least 129,000 verified software vulnerabilities from Glasswing partners between April and July 2026, and calls that "likely an undercount," based on survey data from only a subset of Glasswing partners.

The data retention requirement and your own policies

The announcement states it plainly: "Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse."

Anthropic says organizations with ZDR access to Claude Fable 5.1 or Claude Mythos 5.1 can also use the program with zero data retention until Enterprise Frontier Safeguards (EFS) is available. For eligible organizations, that's the promised alternative. Anthropic's EFS announcement would store data "in cloud infrastructure controlled by the customer, not Anthropic," and the program post says it's "available later this fall," rolling out to customers in phases. It isn't something you can use today. Amazon Bedrock customers get the program only if they're EFS-eligible.

No page we read states a retention period for the program. The Enterprise Frontier Safeguards page mentions 30-day retention introduced with Fable 5, but it doesn't say that applies to the program, so ask Anthropic. That gap is the practical problem, and what follows is our judgment, not Anthropic's: before anyone files the application, check your customer DPAs, any zero-retention clauses in your own contracts, and what code or vulnerability data your team would actually send. Then ask Anthropic for the retention period in writing.

How to apply and how long it takes

The announcement says "Interested organizations can apply to CVP here," and the Help Center says requirements rise with the level of access. Anthropic verifies applicants and requests proof of the required security controls.

The Help Center also states a deadline for Defense Access organizations: move to phishing-resistant MFA and stop using API keys by 15 December 2026. Until then some MFA is required and API keys expire every seven days. Anthropic recommends Workload Identity Federation.

We couldn't read the full per-tier control list. It's in an image on the announcement, and the portal sits behind a login. Look at it before you commit.

Once approved, an Admin or Owner in the Claude Console assigns the grant to workspaces, per Anthropic's workspace assignment guide. The steps are Settings, then Workspaces, then Add Workspace if you need a new one. Then open Settings, then Programs (or Grants), choose Add grant, and set it to Active. Some programs have seat caps.

If a legitimate request gets blocked, the announcement links a false-positive report form for blocked work.

The free open-source scanner

The Cyber Mission post of October 8 pairs the program with a free OSS Scanner, an opt-in vulnerability-finding service inspired by Google's OSS-Fuzz. It's for open-source maintainers, not for scanning your company's private code.

Maintainers enroll by pull request, adding projects/<project>/project.yaml with the repo, primary_contact and Dockerfile. The service is free, per the scanner's page. Agents run in sandboxes with the internet disabled, and reports include a proof of concept, an explanation and a patch where one exists. On the fast track the reports are model-generated, without human review. It targets projects that, per the scanner's page, "are already able to keep up with verified high/critical vulnerability reports."

Accuracy depends on which Anthropic page you read. The Cyber Mission post says "We expect a true-positive rate above 90%." The scanner launch post gives a breakdown: of 97 critical and high-severity findings reviewed, "85 (88%) met the bar for our CVD process," 11 were real but duplicates and one was invalid. The 90% is an expectation and the 88% is a measured sample, so don't treat them as the same number.

What this means for your security and platform team

The decision is whether to apply, and who owns it.

If your work is code review, patching known issues or finding vulnerabilities in your own source, don't apply. Anthropic says generally available models already allow it. Malware analysis, incident response or vulnerability validation points to Defense. Authorized pen testing or red teaming points to Red Team, which is organization-only and takes longer to review, with Defense access in the meantime.

Our sequence, as judgment: ask Anthropic for the retention period, check it against your DPAs and customer commitments, then apply once as an organization. Don't let each team file its own. Name one owner, and make sure an Admin or Owner can assign the grant. Budget for the grant being narrowed or withdrawn.

Teams without a security function get a better return from fundamentals. A code review checklist for engineering leaders is the next read. If you're configuring agents rather than seeking model access, the UK NCSC's controls for agentic AI is the closer match.

FAQ

Who can apply for the Anthropic Cyber Verification Program?

Organizations and individuals. Per the Help Center, organizations apply once, and only Defense access is available to individuals, including independent researchers, maintainers and bug bounty hunters. Red Team is organization-only.

Does the Cyber Verification Program require data retention?

Yes. The announcement says retention is required for enrolled organizations so Anthropic can monitor for cyber misuse. Anthropic says organizations with ZDR access to Claude Fable 5.1 or Claude Mythos 5.1 can also use the program with zero data retention until EFS is available, and customer-controlled storage is promised for later this fall. No page we read states a retention period for the program. The Enterprise Frontier Safeguards page mentions 30-day retention introduced with Fable 5, but it doesn't say that applies to the program, so ask Anthropic.

How long does Defense Access approval take?

Anthropic's pages differ. The announcement says it aims to respond within a few days. The Help Center says within seven business days. Red Team review takes "a few weeks."

Is the Anthropic OSS Scanner free?

Yes, Anthropic says it's offered at no cost. It's for open-source maintainers who enroll their project by pull request, not for scanning private company code.

Do I need the Cyber Verification Program to use Claude for code review?

No. Anthropic says generally available models can still be used for code review, patching known issues, vulnerability finding in owned source code and triage of security alerts.

Share this article

Author Image

HighCircl Editorial Team

The HighCircl editorial team writes about hiring software engineers, nearshore development, and engineering team building. Our articles draw on direct experience sourcing and placing senior developers across Poland, Hungary, Slovakia, Serbia, Slovenia, Romania, and Spain — and on candid conversations with the CTOs and engineering leads who hire them.

HighCircl is a nearshore engineering network that delivers matched candidate shortlists in 72 hours. Every piece of content we publish is informed by real engagement data: actual developer rates, real hiring timelines, and what separates engineering teams that scale cleanly from those that stall.

Take Me to the Experts

Access our network of industry-leading software engineers.

Start Now