TL;DR
Secure.com has been accepted into Anthropic’s Cyber Verification Program (CVP). This gives our security research team verified access to Claude’s full dual-use capabilities, the kind of offensive reasoning that frontier models block for everyone by default.
We use it to study how attacks actually work so our Digital Security Teammate can detect, prioritize, and remediate with more accuracy. Being vetted by the team that built the model is an independent read on how we operate, not a marketing badge.
What the Cyber Verification Program Actually Is
Anthropic puts safeguards on its most capable Claude models for a reason. Some cybersecurity work sits in a gray zone. The same reasoning that helps a defender model an attack path also helps an attacker build one.
Anthropic sorts this work into two buckets. Prohibited use covers things like ransomware development and mass data theft. Those stay blocked for everyone, verified or not. High-risk dual use covers vulnerability research, exploitability analysis, and adversarial simulation. That work is blocked by default too, but legitimate defenders can apply to lift it.
CVP is the application that lifts it. It is free, organization-scoped, and reviewed by Anthropic. Decisions come back in about two business days. Approval ties to one specific organization ID and only clears dual-use work. The prohibited stuff never opens up.
Why We Applied
To defend a system, you have to understand how it gets broken. That means reasoning about how a real attacker would find a flaw, reach it, and chain it into a breach.
Most AI models in security run with those guardrails on. If a model cannot think through how a vulnerability gets exploited, its prioritization is a guess. If it cannot model attacker behavior, its remediation advice maps to compliance checkboxes instead of real risk.
Secure.com fixes issues, not just flags them. Fixing them well means understanding them the way the attacker does. We applied for CVP because our work needs that depth, not because the program happened to exist.
What the Clearance Changes
Here is where it shows up in the product:
- Deeper exploitability analysis. We can reason through whether a disclosed flaw is actually exploitable in a real environment, which separates a noisy finding from a genuine risk.
- Sharper attack path modeling. Our teammate maps how an exposed asset, a KEV vulnerability, and a misconfigured IAM role could reach a crown-jewel database, then calculates blast radius.
- Stronger remediation logic. Better inputs produce better fixes, and the gap between what a scanner flags and what an attacker exploits is exactly where teams get hurt.
- Current threat models. As attacker tooling changes, our research changes with it, so detection stays ahead of the curve.
Why This Matters if You Are Evaluating Security Vendors
Anthropic has framed its goal as building a lasting advantage for defenders over attackers. We share that aim.
Threat actors already lean on open and uncensored AI to speed up their work. What they cannot reach is verified access to frontier models. That gap is where a real defender advantage lives, and closing it first is the whole point.
For anyone comparing vendors, CVP verification is a useful signal. It confirms that the research behind the product cleared an independent review by the people who built the model. That is a different bar than a claim about being “AI-powered.” Treat it as real but specific. It vets our dual-use access. It does not, on its own, prove one product beats another, so weigh it alongside everything else you measure.
How Secure.com Helps
Secure.com offer Digital Security Teammates that unifies detection, compliance, and remediation. CVP access sharpens the research that powers it.
- Runs full Level-1 SOC investigations autonomously, with traceable reasoning and human approval before any action.
- Monitors cloud configs across AWS, Azure, and GCP in real time and catches IAM drift within minutes.
- Correlates vulnerabilities, misconfigurations, identity issues, and app flaws into attacker-centric paths, not 10,000 scattered findings.
- Prioritizes fixes using CVSS, KEV, threat intel, and business context, then runs the remediation workflow to close them.
- Turns the same telemetry into audit-ready evidence for ISO, SOC 2, PCI, and HIPAA.