Anthropic Restructures Cyber Verification Program Into Three Access Tiers — Project Glasswing Absorbed
Anthropic today published an expanded Cyber Verification Program (CVP), restructuring its existing security-professional access programme into three distinct tiers and absorbing the separate Project Glasswing track into a single unified framework. Approved applicants gain access to Claude's most capable models — including Opus 5.5, Sonnet 5.5, Mythos 5.1, and all future releases — with reduced automated-blocking classifiers for legitimate security work that would otherwise trip content filters.
The three access tiers
- Tier 1 — Defence Access: For security operations centres, incident-response teams, and analysts doing malware reverse-engineering and vulnerability validation. The tier lifts blocks on detailed malware-behaviour descriptions, exploit PoC analysis, and CVE reproduction steps — tasks that are critical for defence but routinely flagged by default classifiers.
- Tier 2 — Red Team Access: For penetration testers and offensive security consultants working on authorised engagements. Adds permissions for adversary-simulation prompting, shellcode analysis, and social-engineering scenario drafting within scoped engagements. Requires documented evidence of employer, active engagement agreements, or professional certification (OSCP, GPEN, or equivalent).
- Tier 3 — Research Access: Inherits everything from Tier 2 and adds the ability to query Claude about novel attack-surface discovery, zero-day research methodology, and capability assessments for threat-intelligence reporting. This tier was previously available only through Project Glasswing (the critical-infrastructure programme) and is now accessible to any qualified independent researcher.
Project Glasswing integration
Project Glasswing — Anthropic's dedicated programme for organisations securing critical software — continues as a separate engagement track for government partners and critical-infrastructure operators, but its technical permissions are now mapped to Tier 3, removing the previous duplication where the same underlying access was governed by two separate application flows. Between April and July 2026, Glasswing partners used Claude Mythos models to surface over 129,000 verified software vulnerabilities in critical systems, a figure Anthropic cited as evidence that trusted-access programmes generate measurably more defensive value than blanket restrictions.
Applications are handled at anthropic.com/security/cvp. Each tier requires different supporting documentation — Tier 1 asks for an employer letter or LinkedIn verification; Tier 2 for active engagement evidence or certification; Tier 3 for a research portfolio or academic affiliation. Processing time is currently around 5 business days. Approved accounts are tied to an API key that logs usage separately from standard Claude API traffic, and Anthropic may audit usage quarterly as a condition of continued access.
The reduced classifiers are specifically scoped to the submitted use-case description. Prompts outside that scope — for example, a Tier 1 defender using their access to assist in an offensive operation against an organisation that was not the stated context — are still policy violations and grounds for immediate revocation. The CVP is not a blanket "red-card" that unlocks anything; it is a narrowly scoped reduction in defensive friction for stated, verifiable work.