Table of Contents
Anthropic has officially announced the expansion and consolidation of its cybersecurity testing initiatives into a single unified framework: the Cyber Verification Program (CVP).
The move merges the original CVP with Project Glasswing, allowing vetted cybersecurity professionals, critical infrastructure operators, and enterprise red teams to access Anthropic’s frontier models with reduced cyber safeguards.
Discovery Metrics: Over 134,000 Flaws Identified
The expansion follows massive vulnerability discovery figures surfaced by Anthropic and its research partners:
- 129,000+ Verified Flaws: Discovered by Glasswing partner organizations between April and July 2026.
- 5,500+ Open-Source Vulnerabilities: Uncovered directly through Anthropic’s open-source codebase scanning initiatives between April and October 2026.
- 33,000+ High or Critical Severity: More than 33,000 of the discovered issues have been formally triaged as high- or critical-severity vulnerabilities.
- Estimated 5x Undercount: Because these figures reflect data from only a subset of participating partners, Anthropic projects the true real-world impact to be at least five times higher.
Understanding the Three CVP Access Tiers
The consolidated program organizes access into three functional tiers, unlocking access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1:
- Defense Access:
- Scope: Incident response, malware reverse-engineering, patch verification, and vulnerability analysis.
- Eligibility: Open to enterprise security teams, critical infrastructure operators, open-source maintainers, and independent researchers with documented disclosure records.
- Turnaround: Vetted within days.
- Red Team Access:
- Scope: Adds authorized penetration testing and adversarial red-teaming workflows to the defensive feature set.
- Eligibility: Restricted exclusively to verified corporate and research organizations (applications take several weeks to review).
- Specialized Access:
- Scope: Operates with the fewest automated guardrails for safety-critical testing across aviation flight systems, power grids, telecommunication hubs, and interbank transaction networks.
- Eligibility: Vetted in direct collaboration with the U.S. government. Existing Project Glasswing participants will transition automatically into this tier.
Cloud Availability and Data Governance
Approved participants can deploy CVP models across the Claude API Platform, Google Cloud Vertex AI, and Microsoft Foundry, with Amazon Bedrock support available for qualified enterprise setups.
To mitigate abuse risks inherent in reduced-safeguard endpoints, Anthropic requires a default 30-day data retention policy for audit and safety logging. To accommodate strict compliance demands, Anthropic plans to introduce Enterprise Frontier Safeguards later this fall, allowing eligible organizations to store interaction logs within their own self-managed cloud perimeters.
Frequently Asked Questions
Which models are included under Anthropic’s expanded CVP?
Enrolled participants receive tiered access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, as well as future frontier checkpoints.
Who qualifies for Defense Access versus Red Team Access?
Defense Access is available to both organizations and individual researchers/maintainers for defensive auditing. Red Team Access includes offensive penetration testing capabilities and is restricted strictly to verified organizations.
How is data handled for queries sent through CVP?
Queries run under a mandatory 30-day retention window for safety review, with private-cloud logging capabilities arriving later this year via Enterprise Frontier Safeguards.






