If your SOC analysts or pen testers keep running into Claude's cyber blocks, Anthropic now has a way past them, and the condition is that Anthropic keeps your prompts. The expanded Cyber Verification Program, announced October 6, 2026, splits access into three tiers (Defense, Red Team and Specialized), and every one of them requires data retention so Anthropic can monitor for misuse. Zero data retention is open only to organizations that already have it on Claude Fable 5.1 or Claude Mythos 5.1, or through Enterprise Frontier Safeguards, which has not launched. So the first decision is a data decision: can your incident data and your clients' vulnerability findings sit in a vendor's monitoring logs?
What Each Cyber Verification Program Tier Unlocks
The Cyber Verification Program (CVP) is Anthropic's vetting process for security organizations, and the tier you are approved for sets how far Claude's real-time cyber classifiers are relaxed for you. Without it, Anthropic says its generally available models, including Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, "have conservative cyber safeguards that block most cyber work." Those models still handle code review, patching known issues, finding vulnerabilities in your own source code and triaging alerts. The help center page on the safeguards warns that malware analysis or exploit validation "may be interrupted by our safety classifiers."
| Tier | Who qualifies | What it unlocks | Expected review |
|---|---|---|---|
| Defense Access | Corporate, nonprofit, university and government security teams; hospitals and utilities; smaller security firms; open-source maintainers; individual researchers with a disclosure history | SOC and incident response work, malware reverse engineering, vulnerability analysis and validation | A few days |
| Red Team Access | In-house and government red teams, security and penetration testing firms; organizations only | Authorized penetration testing and red teaming on systems you are authorized to test, including IT in critical industries | A few weeks |
| Specialized Access | A limited set of organizations authorized to test safety-critical systems such as flight operating systems, power grids, telecom networks and interbank infrastructure | The fewest cyber blocks; each applicant reviewed in collaboration with the US government | Not stated |
All three tiers include Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models going forward, per the announcement. Project Glasswing members move into Specialized Access without reapplying, and the help center says organizations already enrolled in Glasswing or the earlier CVP keep their access "under your existing terms." Anthropic weighs "the work an organization does, our ability to verify who it is, and the security controls it has in place." No price is attached to any tier.
How Far the Tier Choice Moves the Model
The gap between Defense and Red Team is close to the gap between a blocked model and an unblocked one. Anthropic tested the tiers on CyScenarioBench, 10 multi-stage cyber operation challenges run five times each. Without CVP, every attempt was blocked on the first prompt. With Defense Access, 46 of the 50 trials were still blocked. With Red Team Access, there were no blocks, and Claude Opus 5.5 completed 34 of the 50 tasks, which Anthropic calls "effectively equivalent to the model's 67.6% success rate on this evaluation with no safeguards applied."
So if your team's work is running attack chains, Defense Access will not cover it. It is built for the SOC, the incident responder and the malware analyst. Red Team review takes weeks, and Unite.AI reports that Anthropic enrolls qualifying organizations in Defense Access while their Red Team application is reviewed, so budget for a period where the red team has SOC-level access only.
Red Team Access still blocks in real time anything that could cause physical harm or mass disruption: deploying ransomware, damaging physical systems or pen testing high-risk safety systems. An OT assessment team that tests safety systems needs Specialized Access, which means a US government review. Readers who followed the CISA advisory on AI-written S7 exploit scripts will recognize why that line sits where it does.
Approval for the earlier version of the program was quick. One practitioner wrote in July that approval arrived the next morning, one business day after applying, and that prohibited categories such as ransomware and C2 infrastructure stayed blocked afterward.
The Retention Condition Is the Decision That Matters
Every CVP tier is conditional on Anthropic retaining your data, and the program pages do not say for how long. The announcement is direct: "Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse." The help center adds that retention "enables us to monitor for harmful cyber misuse in the program and detect bad actors." The exceptions are narrow. Organizations "with a data retention exemption for Claude Fable or Claude Mythos models can also use CVP with zero data retention," and everyone else can register interest in Enterprise Frontier Safeguards.
Neither page gives a retention period. Anthropic's general commercial retention policy says API inputs and outputs are deleted within 30 days, and that flagged content is kept for "up to 2 years and trust and safety classification scores for up to 7 years." Whether those defaults govern CVP traffic is not stated, so ask. Security work is the traffic a cyber-misuse classifier exists to inspect, which makes the flagged-content rule the one to pin down.
Think about what goes into these prompts. A SOC analyst pastes log lines with usernames, internal hostnames, IP ranges and sometimes customer records. A pen tester pastes a client's exposed services, working exploit paths and credentials found during the engagement. Many testing contracts restrict where client findings may be processed, and an MSA signed before anyone used an AI model will not mention Anthropic as a processor. If you already went through this with Fable 5's retention requirement, the pattern is the same: the most capable access comes with the least data minimization.
Anthropic's side of the argument is a strong one. Red Team Access removes every block on the benchmark, so monitoring is the main control left between a verified organization and a model that finishes two-thirds of multi-stage attack scenarios. Verification checks paperwork once; a front company or a hijacked account passes that check and is caught only by watching use. The authentication rules follow the same logic. The help center says Defense Access organizations have until December 15, 2026 "to adopt phishing-resistant multi-factor authentication and to stop using API keys," and until then API keys "will expire every seven days." Any SOAR playbook or enrichment script that calls Claude with a static key will need a new auth path.
Bedrock Customers Have the Fewest Options
Where you run Claude changes whether you can join at all. CVP is available on the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry, and the announcement states that "CVP is only available on Amazon Bedrock for customers eligible for Enterprise Frontier Safeguards." EFS, described as combining "the privacy of zero data retention with robust safeguards," is due "later this fall" and will let eligible organizations "store data in cloud infrastructure they control." There is an interest form and no date.
An AWS-standardized security team has two choices: wait for EFS, or route security work through a second cloud. The second option creates a new data path, and it has to clear your own review before a single log line goes through it. The six AI vendor security review questions apply directly: who processes the data, where, for how long, and under which subprocessor list.
Glasswing Shows the Bottleneck Moves to Validation
Once the blocks come off, finding vulnerabilities is the easy part and validating them becomes the work. Anthropic says Glasswing partners "uncovered at least 129,000 verified software vulnerabilities between April and July 2026," with "more than 33,000 have so far been rated as critical- or high-severity," and its own open-source scanning found 5,500 more. Unite.AI notes these figures come from a subset of partners and are likely undercounts.
The partners describe the same constraint. Noopur Davis, Comcast's chief information security and product privacy officer, said in Anthropic's partner write-up: "Validation of these volumes of findings is the new bottleneck." Comcast ran the model across 258 business-critical systems and about 170 million lines of code. At Booz Allen, one analyst reviewed 8 production systems across 138 repositories in 12 days, and the teams still validated findings, deduplicated patterns and routed them to owners. If you are also weighing continuous AI repo scanning from OpenAI, the same capacity math applies: staff the triage queue before you turn up the discovery rate.
What to Do Before You Apply
This Week:
- List the security work your team has had blocked in the past month and sort it by type: SOC and malware analysis maps to Defense Access, attack chains on client or internal systems map to Red Team.
- Have legal read your penetration testing MSAs and rules of engagement for limits on third-party processing of client findings. Do this before the Red Team application goes in.
- Register for Anthropic's CVP webinar on October 14 at 9am PT and bring one question: how long is CVP data retained, and does flagged content follow the 2-year rule?
This Month:
- Apply for Defense Access at the CVP portal; review takes days. If you do offensive testing, file for Red Team Access at the same time, since it takes weeks.
- Find every automation that calls Claude with a static API key and plan its move to phishing-resistant MFA before the December 15 deadline.
- If you run on Bedrock, register for EFS and decide in writing whether you will wait or approve a Vertex AI or Foundry path for security work.
Before Renewal:
- Get the CVP retention period, who at Anthropic can read retained security data, and the deletion terms into your order form or DPA. Keep a record of blocked requests and file them through the false-positive and appeal form so you have evidence when you negotiate.
The Bottom Line
In April, Anthropic held Mythos back from public release and gave it to a short list of partners through Project Glasswing. Now any security team can apply, and the control Anthropic leans on is watching how the model gets used. For a buyer, that makes CVP a data-governance decision your privacy team has to sign off on. Get the retention period in writing before the first red-team prompt goes in.
Continue Reading
- Fable 5 Needs Retention On. ZDR Was Never Zero.
- AI Vendor Security Review: 6 Questions That Change the Answer
- One Firm Ran Four Labs' Cyber Evals. Name Yours.
- Codex Security Cloud Scans New Commits With No Per-Scan Price
- Beacon Bought Haize Labs. Who Red-Teams Your Agents Now?
- AI Wrote the S7 Exploit. There Is No CVE to Patch.
