Anthropic Lifts Cyber Blocks for Pen Testers Who Let It Keep Logs

Anthropic's Cyber Verification Program now has Defense, Red Team and Specialized tiers. Each requires data retention for misuse monitoring, so security leaders must decide whether SOC and pen-test data can sit in a vendor's logs.

By Rajesh Beri·October 6, 2026·9 min read
Share:
A penetration tester's laptop open on a desk in a dim security operations room, terminal windows glowing, next to a server rack with one drive bay lit and a padlocked log archive box on the shelf.

Illustration generated using AI

If your SOC analysts or pen testers keep running into Claude's cyber blocks, Anthropic now has a way past them, and the condition is that Anthropic keeps your prompts. The expanded Cyber Verification Program, announced October 6, 2026, splits access into three tiers (Defense, Red Team and Specialized), and every one of them requires data retention so Anthropic can monitor for misuse. Zero data retention is open only to organizations that already have it on Claude Fable 5.1 or Claude Mythos 5.1, or through Enterprise Frontier Safeguards, which has not launched. So the first decision is a data decision: can your incident data and your clients' vulnerability findings sit in a vendor's monitoring logs?

What Each Cyber Verification Program Tier Unlocks

The Cyber Verification Program (CVP) is Anthropic's vetting process for security organizations, and the tier you are approved for sets how far Claude's real-time cyber classifiers are relaxed for you. Without it, Anthropic says its generally available models, including Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, "have conservative cyber safeguards that block most cyber work." Those models still handle code review, patching known issues, finding vulnerabilities in your own source code and triaging alerts. The help center page on the safeguards warns that malware analysis or exploit validation "may be interrupted by our safety classifiers."

Tier Who qualifies What it unlocks Expected review
Defense Access Corporate, nonprofit, university and government security teams; hospitals and utilities; smaller security firms; open-source maintainers; individual researchers with a disclosure history SOC and incident response work, malware reverse engineering, vulnerability analysis and validation A few days
Red Team Access In-house and government red teams, security and penetration testing firms; organizations only Authorized penetration testing and red teaming on systems you are authorized to test, including IT in critical industries A few weeks
Specialized Access A limited set of organizations authorized to test safety-critical systems such as flight operating systems, power grids, telecom networks and interbank infrastructure The fewest cyber blocks; each applicant reviewed in collaboration with the US government Not stated

All three tiers include Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models going forward, per the announcement. Project Glasswing members move into Specialized Access without reapplying, and the help center says organizations already enrolled in Glasswing or the earlier CVP keep their access "under your existing terms." Anthropic weighs "the work an organization does, our ability to verify who it is, and the security controls it has in place." No price is attached to any tier.

How Far the Tier Choice Moves the Model

The gap between Defense and Red Team is close to the gap between a blocked model and an unblocked one. Anthropic tested the tiers on CyScenarioBench, 10 multi-stage cyber operation challenges run five times each. Without CVP, every attempt was blocked on the first prompt. With Defense Access, 46 of the 50 trials were still blocked. With Red Team Access, there were no blocks, and Claude Opus 5.5 completed 34 of the 50 tasks, which Anthropic calls "effectively equivalent to the model's 67.6% success rate on this evaluation with no safeguards applied."

So if your team's work is running attack chains, Defense Access will not cover it. It is built for the SOC, the incident responder and the malware analyst. Red Team review takes weeks, and Unite.AI reports that Anthropic enrolls qualifying organizations in Defense Access while their Red Team application is reviewed, so budget for a period where the red team has SOC-level access only.

Red Team Access still blocks in real time anything that could cause physical harm or mass disruption: deploying ransomware, damaging physical systems or pen testing high-risk safety systems. An OT assessment team that tests safety systems needs Specialized Access, which means a US government review. Readers who followed the CISA advisory on AI-written S7 exploit scripts will recognize why that line sits where it does.

Approval for the earlier version of the program was quick. One practitioner wrote in July that approval arrived the next morning, one business day after applying, and that prohibited categories such as ransomware and C2 infrastructure stayed blocked afterward.


The Retention Condition Is the Decision That Matters

Every CVP tier is conditional on Anthropic retaining your data, and the program pages do not say for how long. The announcement is direct: "Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse." The help center adds that retention "enables us to monitor for harmful cyber misuse in the program and detect bad actors." The exceptions are narrow. Organizations "with a data retention exemption for Claude Fable or Claude Mythos models can also use CVP with zero data retention," and everyone else can register interest in Enterprise Frontier Safeguards.

Neither page gives a retention period. Anthropic's general commercial retention policy says API inputs and outputs are deleted within 30 days, and that flagged content is kept for "up to 2 years and trust and safety classification scores for up to 7 years." Whether those defaults govern CVP traffic is not stated, so ask. Security work is the traffic a cyber-misuse classifier exists to inspect, which makes the flagged-content rule the one to pin down.

Think about what goes into these prompts. A SOC analyst pastes log lines with usernames, internal hostnames, IP ranges and sometimes customer records. A pen tester pastes a client's exposed services, working exploit paths and credentials found during the engagement. Many testing contracts restrict where client findings may be processed, and an MSA signed before anyone used an AI model will not mention Anthropic as a processor. If you already went through this with Fable 5's retention requirement, the pattern is the same: the most capable access comes with the least data minimization.

Anthropic's side of the argument is a strong one. Red Team Access removes every block on the benchmark, so monitoring is the main control left between a verified organization and a model that finishes two-thirds of multi-stage attack scenarios. Verification checks paperwork once; a front company or a hijacked account passes that check and is caught only by watching use. The authentication rules follow the same logic. The help center says Defense Access organizations have until December 15, 2026 "to adopt phishing-resistant multi-factor authentication and to stop using API keys," and until then API keys "will expire every seven days." Any SOAR playbook or enrichment script that calls Claude with a static key will need a new auth path.

Bedrock Customers Have the Fewest Options

Where you run Claude changes whether you can join at all. CVP is available on the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry, and the announcement states that "CVP is only available on Amazon Bedrock for customers eligible for Enterprise Frontier Safeguards." EFS, described as combining "the privacy of zero data retention with robust safeguards," is due "later this fall" and will let eligible organizations "store data in cloud infrastructure they control." There is an interest form and no date.

An AWS-standardized security team has two choices: wait for EFS, or route security work through a second cloud. The second option creates a new data path, and it has to clear your own review before a single log line goes through it. The six AI vendor security review questions apply directly: who processes the data, where, for how long, and under which subprocessor list.

Glasswing Shows the Bottleneck Moves to Validation

Once the blocks come off, finding vulnerabilities is the easy part and validating them becomes the work. Anthropic says Glasswing partners "uncovered at least 129,000 verified software vulnerabilities between April and July 2026," with "more than 33,000 have so far been rated as critical- or high-severity," and its own open-source scanning found 5,500 more. Unite.AI notes these figures come from a subset of partners and are likely undercounts.

The partners describe the same constraint. Noopur Davis, Comcast's chief information security and product privacy officer, said in Anthropic's partner write-up: "Validation of these volumes of findings is the new bottleneck." Comcast ran the model across 258 business-critical systems and about 170 million lines of code. At Booz Allen, one analyst reviewed 8 production systems across 138 repositories in 12 days, and the teams still validated findings, deduplicated patterns and routed them to owners. If you are also weighing continuous AI repo scanning from OpenAI, the same capacity math applies: staff the triage queue before you turn up the discovery rate.


What to Do Before You Apply

This Week:

  1. List the security work your team has had blocked in the past month and sort it by type: SOC and malware analysis maps to Defense Access, attack chains on client or internal systems map to Red Team.
  2. Have legal read your penetration testing MSAs and rules of engagement for limits on third-party processing of client findings. Do this before the Red Team application goes in.
  3. Register for Anthropic's CVP webinar on October 14 at 9am PT and bring one question: how long is CVP data retained, and does flagged content follow the 2-year rule?

This Month:

  1. Apply for Defense Access at the CVP portal; review takes days. If you do offensive testing, file for Red Team Access at the same time, since it takes weeks.
  2. Find every automation that calls Claude with a static API key and plan its move to phishing-resistant MFA before the December 15 deadline.
  3. If you run on Bedrock, register for EFS and decide in writing whether you will wait or approve a Vertex AI or Foundry path for security work.

Before Renewal:

  1. Get the CVP retention period, who at Anthropic can read retained security data, and the deletion terms into your order form or DPA. Keep a record of blocked requests and file them through the false-positive and appeal form so you have evidence when you negotiate.

The Bottom Line

In April, Anthropic held Mythos back from public release and gave it to a short list of partners through Project Glasswing. Now any security team can apply, and the control Anthropic leans on is watching how the model gets used. For a buyer, that makes CVP a data-governance decision your privacy team has to sign off on. Get the retention period in writing before the first red-team prompt goes in.

Continue Reading

Share:

Frequently Asked Questions

What are the three tiers of Anthropic's Cyber Verification Program?

Defense Access covers SOC, incident response, malware reverse engineering and vulnerability validation, with review in a few days. Red Team Access adds authorized penetration testing for organizations only, with review in a few weeks. Specialized Access covers testing of safety-critical systems such as power grids and interbank infrastructure, reviewed with the US government.

Does the Cyber Verification Program require data retention?

Yes. Anthropic requires data retention for every enrolled organization so it can monitor for cyber misuse. Zero data retention is available only to organizations that already have a retention exemption for Claude Fable or Claude Mythos models, or later through Enterprise Frontier Safeguards, which Anthropic says arrives this fall.

Can I use the Cyber Verification Program on Amazon Bedrock?

Only if you are eligible for Enterprise Frontier Safeguards. CVP is available on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry; on Bedrock it is limited to EFS-eligible customers, and EFS has not launched yet.

What does Red Team Access still block?

Real-time blocks remain on actions that could cause physical harm or mass disruption, including deploying ransomware, damaging physical systems and pen testing high-risk safety systems. Testing is limited to systems the organization is authorized to test.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →