Table of Contents
The Cyber Verification Program Explained
The Cyber Verification Program (CVP) is Anthropic's free, application-based program that lets vetted security organizations use Claude for legitimate dual-use defensive work that its real-time cyber safeguards block by default. Anthropic reviews each application, and approval applies to one organization. Prohibited uses stay blocked for everyone, verified or not.
The program exists because the same request can serve an attacker or a defender. Asking a large language model how an exploit chain works, or to build a realistic attack for a test, is routine work for a red team and a starting point for a criminal. CVP gives the model provider a way to tell the two apart before it answers.
How the Cyber Verification Program Works
- Two tiers of blocked activity. Anthropic's cyber safeguards block prohibited use (ransomware development, mass data exfiltration) and high-risk dual use (vulnerability exploitation, offensive security tooling). CVP applies only to the second tier.
- Organization-level vetting. An authorized admin applies through Anthropic's verification portal, verifies their identity, and describes the defensive use case. Anthropic aims to return a decision within two business days.
- Scoped approval. Approval covers one organization ID. The same user working from a personal workspace still hits the default safeguards.
- Ongoing policy terms. Verified organizations stay bound by Anthropic's Usage Policy, and Anthropic can revise or end participation.
Who Uses the Cyber Verification Program
CVP participants are organizations whose daily work sits in the dual-use tier: penetration testing firms, threat intelligence teams, detection engineering groups, and security vendors that model attacks to defend against them. In email security, that means building realistic phishing simulation campaigns from public reconnaissance, reconstructing how a live campaign was assembled, and testing detection against attacks that haven't reached an inbox yet. An agentic security system that runs these tasks on its own needs the model to stay useful at exactly the point where a general-purpose safeguard would refuse.
IRONSCALES was the first email security vendor verified under Anthropic's Cyber Verification Program, and Anthropic's safety controls apply to everything it does in the program. That access supports the adversarial modeling behind the IRONSCALES Red Teaming Agent, which gathers open-source intelligence (OSINT) on a customer's public footprint with the customer's consent, builds the phishing attacks an attacker could aim at that organization, and turns each one into a detection update for that customer's protection.
Cyber Verification Program vs. Related Controls
CVP is a provider-side access control. It governs what a model will do for a known organization. It has nothing to do with AI jailbreaking, where an anonymous user tries to trick a model past its safeguards. It also differs from internal AI governance frameworks such as AI TRiSM, which a company applies to its own AI use. OpenAI runs a comparable program for its models, Trusted Access for Cyber.
Frequently Asked Questions About the Cyber Verification Program
What is the Anthropic Cyber Verification Program? The Cyber Verification Program is a free, application-based Anthropic program. It lets vetted security organizations use Claude for legitimate dual-use defensive work, such as adversarial simulation or exploit analysis, that Claude's cyber safeguards block by default.
What does the Cyber Verification Program not allow? CVP never unblocks prohibited uses. Ransomware development, mass data exfiltration, and similar activities with little or no defensive value stay blocked for every organization, verified or not.
Who can apply for the Cyber Verification Program? Any organization with a legitimate defensive use case can apply through an authorized admin. Organizations on Zero Data Retention agreements are not currently eligible.
How long does Cyber Verification Program approval take? Anthropic aims to email a decision within two business days of an application, after identity verification.
Why does CVP matter to security buyers? Verification tells a buyer that a vendor's AI work was reviewed by the model provider and runs under that provider's safeguards. It is an external check on how a vendor uses frontier AI, separate from any claim the vendor makes about itself.
Related Terms
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.