Why the program exists
Anthropic says cyber capabilities are inherently dual use: the same ability that lets a security team find and fix a vulnerability can help a malicious actor exploit it. That is why its generally available models鈥擟laude Opus 5.5, Fable 5.1 and Sonnet 5.5鈥攃arry conservative safeguards that block most cyber work.
Two programs, one offering
For the past six months, trusted access ran through two programs: Project Glasswing, which gave organizations securing critical software access to Claude Mythos, and the CVP, which gave vetted security teams reduced safeguards on Opus and Sonnet models. Anthropic is now merging them into a single, expanded program.
Three access tiers
- Defense Access: For defensive work such as security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Qualifying organizations include security teams at companies, nonprofits, universities and government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. Anthropic aims to respond within a few days.
- Red Team Access: Adds authorized penetration testing and red-teaming to the defensive uses. In-house red teams, government red teams, and security and penetration testing firms qualify. Real-time blocks remain on actions that could cause physical harm or mass disruption, such as deploying ransomware or damaging physical systems. Reviews are expected to take a few weeks, and applicants are enrolled in Defense Access while they wait.
Models and applications
Each tier includes access to Anthropic's most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models moving forward. Interested customers can apply through Anthropic's application page.



