AI has changed the economics of finding weaknesses. The same models that help defenders audit code and reason about how an attack would run help attackers do that work faster. Discovery is becoming a solved problem on both sides of the fence. The bottleneck has moved to remediation: fixing what your tools already find, on your own stack, without breaking the business.

Anthropic’s Project Glasswing made that shift plain, and it raised a practical problem for defenders. The research that keeps a security team ahead of attackers often looks, to a frontier model’s default safeguards, a lot like the work attackers do. Today we are addressing that problem directly. Reclaim Security has been accepted into Anthropic’s Cyber Verification Program (CVP).

“Defenders have always had to think like attackers to fix what matters. The Cyber Verification Program gives our research team that room without fighting default safeguards. What does not change: the model informs our intelligence, it never runs the fix. Every remediation in a customer environment stays deterministic, reversible, and governed.”

Barak Klinghofer, Co-Founder and CEO, Reclaim Security

What the Cyber Verification Program is

A lot of legitimate defensive work overlaps with techniques an attacker would use. Exploitability analysis, adversarial simulation, and threat modeling all require reasoning about how an attack would actually run. Frontier models apply default safeguards to this dual-use work, which can interrupt the research defensive teams rely on.

Anthropic draws a clear line between two categories. Prohibited use, such as mass data exfiltration or ransomware development, stays blocked for everyone and is not open to adjustment. High-risk dual-use work, such as vulnerability exploitation analysis and offensive security tooling, is also blocked by default, but the CVP lifts that restriction for vetted organizations with legitimate defensive use cases. The program is free, application-based, and scoped to each organization, and it runs under Anthropic’s security, confidentiality, and responsible-use requirements.

How we use the CVP

Verified access strengthens the research pipeline behind the platform in three concrete ways.

We study exploitability with more depth. Understanding whether and how a disclosed flaw can actually run in a realistic environment is what separates a noisy vulnerability feed from an accurate read on risk. Dual-use access lets our team reason through these questions the way an attacker would, then turn that understanding into hardening logic for the Susceptible Components we track: the software and application components with a history of recurring flaws. When we harden a component, a new flaw against it can be born mitigated in the customer’s environment.

We keep our threat models current and pressure-test our own coverage. As attacker tooling changes, our research has to change with it. We run adversarial simulations against the controls we model to find where coverage is thin before an attacker does.

We validate the controls customers already own. Most incidents come from misconfigured tools, not missing ones. Studying how an attacker would work around a given configuration tells us which compensating controls actually hold and which need to change, so a security team gets more protection from the stack it already pays for.

One boundary matters here. This research sharpens the intelligence that feeds remediation. It does not put a model in the remediation path. The fix that runs against a customer’s production environment stays deterministic, policy-bound, reversible, and governed by the customer’s approval boundaries. Customers interact with Reclaim, not with the underlying research access.

What changes for our customers

Reclaim was built for this. The platform sits on the existing security stack, maps every finding to the compensating controls already present in the environment, and predicts business impact with PIPE™, our Productivity Impact Prediction Engine, before any change runs. When a new disclosure lands, a security team can see which assets are exposed, which are already protected, and where the real gaps are.

Feeding that loop with sharper, better-validated research means a shorter exposure window and mitigation that can start before a patch is available. Exploits routinely land before a patch does, and execution speed at that moment is what closes the window. It also gives the board a clear answer to the question it now asks after every disclosure: are we exposed, and what are we doing about it.

A durable advantage for defenders

Anthropic has framed its goal as a lasting advantage for defenders. We share that aim. Capable models with strong cyber skills are reaching attackers quickly, and many will arrive without the safeguards that keep them from being misused. The organizations that build continuous, mitigation-first remediation before that happens are the ones that stay standing when AI-assisted attacks become routine.

Acceptance into the Cyber Verification Program moves that advantage closer for the teams we serve. We will share more as the program develops.

Sources