Analysis frame
Primary-source evidence
Compare eligibility, allowed tasks and safeguards across three company-run access tiers while keeping simulated benchmark performance separate from real misuse rates.
- Hospital, municipal and open-source defenders applying for stronger tools
- Operators and users of high-risk systems that may be penetration tested
- No public independent audit establishes how often the authorization checks reject misuse
- CyScenarioBench trials do not measure actual attacks, victim harm or long-term defender benefit
- Qualified small defenders may gain capacity previously reserved for major vendors
- Differential access and data-retention rules may concentrate power or deter privacy-sensitive teams
Three access levels, different powers
Defense Access includes defensive analysis; Red Team Access adds authorized penetration testing; Specialized Access covers a smaller group permitted to test systems whose failure could hurt people or markets. Anthropic says verification and controls grow with the tier.
The program is a policy enforced by one provider. It does not replace legal authorization from the system owner or independent oversight of consequential tests.
A benchmark is not an incident rate
Anthropic's 50-trial benchmark shows that the Red Team configuration enables much more simulated offensive work than Defense Access. That is its intended design for authorized testers, not a report of 34 actual breaches.
What matters next is how the company verifies permissions, audits misuse, handles false rejections and reports incidents. Its privacy and data-retention terms will also affect who can participate.
Go to the source
Read the evidence behind this analysis. External links open in a new tab.
Anthropic — Cyber Verification Program expansion Anthropic — Project Glasswing background


