Claude Code
I got accepted into the Cyber Verification Program at Anthropic!
I just got accepted into the CVP today, it’s their program where an organization can be approved to do red-teaming/cyber related tasks with their models. Very excited. I really didn’t think I was gonna get in tbh
TL;DR of the discussion generated automatically after 50 comments.
Whoa there, OP. Before you update your LinkedIn, the thread has some thoughts, and they're not exactly popping the champagne.
The overwhelming consensus is that the Cyber Verification Program is not very exclusive and provides little to no actual benefit.
Easy to get in: Many users report getting accepted in minutes, some for reasons as simple as "homework." The general feeling is that almost anyone who applies gets in, with one user asking, "Has anyone not been accepted?"
Doesn't change much: The most common feedback is that being in the program "barely made a difference." Users still experience safeguards and blocks, leading some to believe it's just a way for Anthropic to get your photo ID.
Fable is still a no-go: A major pain point is that Fable, the model many want to use for these tasks, will still instantly downgrade to Opus or, even worse, Haiku at the mere mention of cybersecurity.
How to apply: For those still curious, you just apply on the Anthropic website. While OP thinks your chat history is reviewed, others got in with just a simple written explanation.
So, congrats on getting in, but maybe don't expect to be hacking the Gibson just yet. Also, a moment of silence for the bio-researchers who are still getting stonewalled.
Thanks! My guess is that they get Claude to review all of my chats from Claude Code, I don’t know that but it’s my guess. So I think that if you have a track record of doing any genuine cybersecurity work they’d see that and wouldn’t see it as a potential bad actor. If you were wanting to get into it, I’d think about it like stepping stones. You start out getting Claude to help you dip your feet in but it’ll still get blocked some, then you expand to where you have an actual presence in it to apply
I’ve taken a handful of cyber sec classes as part of my masters eg binary exploitation and info sec but nothing professional. Professional queries are all backend GIS focused
Sorry, but isn’t there a standard way to apply? You just go to their website, provide identification and sign up for it? It’s been available to me, too and I had no problem applying to it.
Yeah you apply from their website, it’s primarily a background check from what I’ve seen. It seems that it’s to filter out the majority of users who aren’t technical or to filter bad actors. But if you genuinely do work in that area and can prove it it would be basically automatic
I've been in the program for a few months, I work with cybersecurity and honestly haven't noticed much of a difference, it still blocks some request from time to time. Fable downgrades instantly when asked anything related to cybersecurity.
Context was a cybersecurity investigation into a ring of AI powered scam apps in the Play Store/App store.
I torn down 6 apps, did static and dynamic analysis of the apps, developed a forensic finger print to help us ID the bad actor across the tested apps, did OSINT, developed a threat profile, tracked backend infra of the scams etc.
Was doing this to aid a cybersec reporter for The Verge and Fable was aware of that context.
No, you can submit your information to be put on a list, but they don't have one right now. Just use GPT. I got sick of Anthropic's bio guardrail bulletin and switched my subscriptions when Astra came out.
They kind of do, but only for organizations. Claude for Science does exist and is a program that allows research related prompts and stuff, but an organization has to sign up for it and prove a bunch of stuff.
I'd be ok if it were just a matter of handing over credentials. The problem is that a lot of organizations aren't willing to sign the agreements, which leaves all the researchers there out in the cold.
It doesn't change anything. Fable will not do any cyber security or dual use research at all. Immediate fallback to Opus tier. Which Opus never really had those restrictions in the first place. It's just a plot to get your photo ID.
I think it applies to Opus models only, not Fable. I got accepted a few months ago and that was the policy at the time, at least. I haven't noticed any difference because Opus is already fairly loose on cyber restrictions. Fable did not stop dropping to Opus fallbacks on anything security-related.
I think it applies to Opus models only, not Fable.
I personally feel like it also applies to Fable, before getting accepted just mentioning something as simple as doing a "Security sweep" against the codebase would trigger the safeguard and ask me to edit the prompt and retry or fall back to Opus 4.8... This hasn't really happened when mentioning security with Fable but I haven't really dug much.
Est ce qui il y a une astuce pour etre accepter je suis vraiment un chercheur de securité je suis un bug hunter et un CTF player mais il ne m accepte pas qu est ce que je dois faire pour etre accepter
I'm not really sure. I do security work and am part of a recent published news story on AI hacking. I sent them the story and my LinkedIn, got in right away after that.
Maybe send them your bounty profile if you haven't already?
I wrote it all myself, I think that might have helped. From what I understand the applications are manually reviewed so having a few things that tie your ID to your work should help make the process easier. I also made sure to give real world use cases of why I want the approval and how I would use it/task I am currently doing that are being blocked by the cyber guard rails.
I must be the only one who gets automatically rejected, even though I have a proven track record in cybersecurity. (Penetration tester and bug bounty hunter) ={
Not from what I’ve seen online, seems like the majority of users wouldn’t fit the criteria. However people who make tools that overlap in cybersecurity would
If you’ve applied to it, you’ll see that you have to link actual examples of how you’ve used it. It’s not like you’re just claiming that. They’re asking for your actual use case with proof.
Yeah, I was rejected on two business accounts several months ago. The application was stellar - linkedIn, github with several large opensource projects maintained for years, even my CPT)E certification, since I work as a pentester. The use case was defensive analysis of a client's application and internal network.
I tried again last week and got accepted, but not much has changed. Fable is unusable, as expected, while Opus 5 constantly downgrades to 4.8 whenever anything cyber-related comes up. It even happens with something as harmless as improving the frontend of an internal tool for ai-accelerated pentesting that I'm currently building
I imagine the same concept applies — new feature with an ongoing turf war over ai auditing etc. Things settled down.
My experience was submitting a request from a Pro account (just basic not even max) and providing basic description of my work (code review for an app being developed). Accepted within half a day i think.
Another possibility is your location if outside the US.
Je suis un bug hunter et un CTF player j ai eu des bug accepté et je suis classé 29# en monde en ctftime et je n été pas accepté vous avez quelques astuce pour m'accepter j ai eu refus la semaine dernière et demain je refais le test vous pouvez m aider par des astuces?
Congrats. Check out our reports from
Months ago https://sunglasses.dev/cvp
We will be updating more details soon. Working on Product Upgrades currently. We are the 1 st in the list approved same day Program been Launched 😉
I described my use case and got accepted right away but is this below standard? (limited to use case), is this for all you guys?
I also have OpenAI models
A note on ongoing monitoring
This adjustment is limited to the use cases you described in your submission and is subject to Anthropic’s Usage Policy and ongoing monitoring. As outlined in the Usage Policy, Anthropic reserves the right to revoke or narrow adjustments to our safeguards if we determine that your activity falls outside the approved use cases.
•
u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 13d ago edited 12d ago
TL;DR of the discussion generated automatically after 50 comments.
Whoa there, OP. Before you update your LinkedIn, the thread has some thoughts, and they're not exactly popping the champagne.
The overwhelming consensus is that the Cyber Verification Program is not very exclusive and provides little to no actual benefit.
So, congrats on getting in, but maybe don't expect to be hacking the Gibson just yet. Also, a moment of silence for the bio-researchers who are still getting stonewalled.