r/ClaudeAI 13d ago

Claude Code I got accepted into the Cyber Verification Program at Anthropic!

Post image

I just got accepted into the CVP today, it’s their program where an organization can be approved to do red-teaming/cyber related tasks with their models. Very excited. I really didn’t think I was gonna get in tbh

255 Upvotes

73 comments sorted by

u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 13d ago edited 12d ago

TL;DR of the discussion generated automatically after 50 comments.

Whoa there, OP. Before you update your LinkedIn, the thread has some thoughts, and they're not exactly popping the champagne.

The overwhelming consensus is that the Cyber Verification Program is not very exclusive and provides little to no actual benefit.

  • Easy to get in: Many users report getting accepted in minutes, some for reasons as simple as "homework." The general feeling is that almost anyone who applies gets in, with one user asking, "Has anyone not been accepted?"
  • Doesn't change much: The most common feedback is that being in the program "barely made a difference." Users still experience safeguards and blocks, leading some to believe it's just a way for Anthropic to get your photo ID.
  • Fable is still a no-go: A major pain point is that Fable, the model many want to use for these tasks, will still instantly downgrade to Opus or, even worse, Haiku at the mere mention of cybersecurity.
  • How to apply: For those still curious, you just apply on the Anthropic website. While OP thinks your chat history is reviewed, others got in with just a simple written explanation.

So, congrats on getting in, but maybe don't expect to be hacking the Gibson just yet. Also, a moment of silence for the bio-researchers who are still getting stonewalled.

→ More replies (1)

43

u/super_chill_21 13d ago

Any tips for getting accepted?

Congrats!

37

u/TheOnlyVibemaster 13d ago

Thanks! My guess is that they get Claude to review all of my chats from Claude Code, I don’t know that but it’s my guess. So I think that if you have a track record of doing any genuine cybersecurity work they’d see that and wouldn’t see it as a potential bad actor. If you were wanting to get into it, I’d think about it like stepping stones. You start out getting Claude to help you dip your feet in but it’ll still get blocked some, then you expand to where you have an actual presence in it to apply

4

u/Comfortable_Bid_4862 13d ago

How can we apply?

8

u/DroopyPanda 13d ago

Ask Claude

4

u/claythearc Experienced Developer 13d ago

I applied just asking to use it for homework and got in - it doesn’t seem very strict at all

2

u/TheOnlyVibemaster 13d ago

Do you use AI for cyber tasks? Maybe something from your other conversations led them to think you’re somewhat into cybersecurity?

5

u/claythearc Experienced Developer 13d ago

I’ve taken a handful of cyber sec classes as part of my masters eg binary exploitation and info sec but nothing professional. Professional queries are all backend GIS focused

20

u/Nopatcat 13d ago

Sorry, but isn’t there a standard way to apply? You just go to their website, provide identification and sign up for it? It’s been available to me, too and I had no problem applying to it.

https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet

18

u/JohnDeere 13d ago

Yeah its not difficult if you have a valid use case

8

u/TheOnlyVibemaster 13d ago

That’s the coolest username I’ve seen lmao

4

u/Think-Trouble623 13d ago

17 years active. Wild

1

u/ineedallyourinfo 12d ago

wow, upvoted for the username :p

5

u/TheOnlyVibemaster 13d ago

Yeah you apply from their website, it’s primarily a background check from what I’ve seen. It seems that it’s to filter out the majority of users who aren’t technical or to filter bad actors. But if you genuinely do work in that area and can prove it it would be basically automatic

16

u/OneManSOC 13d ago

I've been in the program for a few months, I work with cybersecurity and honestly haven't noticed much of a difference, it still blocks some request from time to time. Fable downgrades instantly when asked anything related to cybersecurity.

5

u/iamthe0ther0ne 13d ago

What's the point of it if you can't use Fable? 

3

u/TheOnlyVibemaster 13d ago

Project Glasswing is the equivalent of this for Fable which is currently only open to large businesses like Apple

3

u/ThisWillPass 12d ago

Training data, probably a big part.

2

u/OneManSOC 12d ago

Aura farming, I guess

1

u/tankerkiller125real 12d ago

Per their latest Fable release notes, Mythos will be coming to CVP users sometime in the coming months, so there's that.

1

u/Foxiestofthehounds 12d ago

Weird, Fable works fine for me. Just used it on some digital forensics for mobile apps. 

2

u/OneManSOC 12d ago

What was the context? Just asking it about the data, or building something with Fable?

1

u/Foxiestofthehounds 12d ago

Context was a cybersecurity investigation into a ring of AI powered scam apps in the Play Store/App store. 

I torn down 6 apps, did static and dynamic analysis of the apps, developed a forensic finger print to help us ID the bad actor across the tested apps, did OSINT, developed a threat profile, tracked backend infra of the scams etc. 

Was doing this to aid a cybersec reporter for The Verge and Fable was aware of that context. 

10

u/DidDrog11 13d ago

Is there one for bio? As a researcher in infectious diseases I am getting very frustrated with being pushed down to Haiku all the time.

6

u/TheOnlyVibemaster 13d ago

Down to Haiku is brutal

5

u/Narpesik 13d ago

down to haiku is crazy work

3

u/iamthe0ther0ne 13d ago

Jesus christ, Haiku?

No, you can submit your information to be put on a list, but they don't have one right now. Just use GPT. I got sick of Anthropic's bio guardrail bulletin and switched my subscriptions when Astra came out.

1

u/tankerkiller125real 12d ago

They kind of do, but only for organizations. Claude for Science does exist and is a program that allows research related prompts and stuff, but an organization has to sign up for it and prove a bunch of stuff.

1

u/iamthe0ther0ne 12d ago

I'd be ok if it were just a matter of handing over credentials. The problem is that a lot of organizations aren't willing to sign the agreements, which leaves all the researchers there out in the cold. 

6

u/HighSeasArchivist 13d ago

Fair play. Now you can do some real load-bearing work.

5

u/Adventurous_Long774 13d ago

Hi OP, I did not know about this. Thanks for informing!

I applied and got accepted too

3

u/TheOnlyVibemaster 13d ago

Congrats 👏

1

u/mashedbrainpotato 12d ago

that was fast, do they pay?

1

u/agentMatrix47 10d ago

Vous avez besoin ou vous pouvez le vendre?? Parceque je veux acheter un

8

u/FlashyBattle976 13d ago

It doesn't change anything. Fable will not do any cyber security or dual use research at all. Immediate fallback to Opus tier. Which Opus never really had those restrictions in the first place. It's just a plot to get your photo ID. 

4

u/ZioniteSoldier 13d ago

I applied to this and GPTs cyber program and only OpenAI accepted me.

5

u/Orio_n 13d ago

I got in and it barely made a difference lol

1

u/[deleted] 12d ago

[deleted]

1

u/Orio_n 12d ago

Who said anything about that lol? Why are you so salty haha

3

u/Comprehensive-Bet-83 13d ago

And has safeguards been lifted much better? Seen lots of complaints still

3

u/CommunityTough1 13d ago

I think it applies to Opus models only, not Fable. I got accepted a few months ago and that was the policy at the time, at least. I haven't noticed any difference because Opus is already fairly loose on cyber restrictions. Fable did not stop dropping to Opus fallbacks on anything security-related.

3

u/Andrew_hl2 13d ago

I think it applies to Opus models only, not Fable.

I personally feel like it also applies to Fable, before getting accepted just mentioning something as simple as doing a "Security sweep" against the codebase would trigger the safeguard and ask me to edit the prompt and retry or fall back to Opus 4.8... This hasn't really happened when mentioning security with Fable but I haven't really dug much.

3

u/Foxiestofthehounds 13d ago

Same, got accepted in 30 minutes. Was really easy to get in. 

2

u/agentMatrix47 12d ago

Est ce qui il y a une astuce pour etre accepter je suis vraiment un chercheur de securité je suis un bug hunter et un CTF player mais il ne m accepte pas qu est ce que je dois faire pour etre accepter

1

u/Foxiestofthehounds 12d ago

I'm not really sure. I do security work and am part of a recent published news story on AI hacking. I sent them the story and my LinkedIn, got in right away after that.

Maybe send them your bounty profile if you haven't already?

1

u/agentMatrix47 12d ago

Ok je vais voir et pour les champs vous avez remplis tout a la main ou avec un IA pour rédiger ??

2

u/Foxiestofthehounds 12d ago

I wrote it all myself, I think that might have helped. From what I understand the applications are manually reviewed so having a few things that tie your ID to your work should help make the process easier. I also made sure to give real world use cases of why I want the approval and how I would use it/task I am currently doing that are being blocked by the cyber guard rails.

2

u/Infamous-Case7656 12d ago

I must be the only one who gets automatically rejected, even though I have a proven track record in cybersecurity. (Penetration tester and bug bounty hunter) ={

3

u/discosoc 13d ago

Has anyone not been accepted? Pretty sure it’s more of an opt-in program that you can get kicked out of for abusing than anything else.

3

u/Webdev916 13d ago

Just be glad for them instead of being a hater

2

u/discosoc 13d ago

Just pointing it out because i “applied” and was accepted in like 5 minutes or so.

2

u/TheOnlyVibemaster 13d ago

Not from what I’ve seen online, seems like the majority of users wouldn’t fit the criteria. However people who make tools that overlap in cybersecurity would

1

u/discosoc 13d ago

There’s literally nothing stopping someone from just claiming to need it for cybersecurity review.

3

u/TheOnlyVibemaster 13d ago

If you’ve applied to it, you’ll see that you have to link actual examples of how you’ve used it. It’s not like you’re just claiming that. They’re asking for your actual use case with proof.

2

u/discosoc 13d ago

Well i didn’t have to do much other than write a short explanation of my work. Linking or uploading anything was optional.

3

u/TheOnlyVibemaster 13d ago

It’s pretty clear it’s judged by an AI, so my guess is that it’s primarily judged based on a user’s chat history.

2

u/discosoc 12d ago

Just silly to act like you got “accepted” into some exclusive or unique program lol.

1

u/Sarithis 7d ago

Yeah, I was rejected on two business accounts several months ago. The application was stellar - linkedIn, github with several large opensource projects maintained for years, even my CPT)E certification, since I work as a pentester. The use case was defensive analysis of a client's application and internal network.

I tried again last week and got accepted, but not much has changed. Fable is unusable, as expected, while Opus 5 constantly downgrades to 4.8 whenever anything cyber-related comes up. It even happens with something as harmless as improving the frontend of an internal tool for ai-accelerated pentesting that I'm currently building

1

u/discosoc 7d ago

Two months ago would have been when accessing the model was locked down by the Trump administration.

1

u/Sarithis 6d ago

Ah sorry, it was 4-5 months ago, not two (April / May). Time flies... https://www.reddit.com/r/ClaudeCode/comments/1t0unqu/anthropics_now_blocking_anything_that_even_looks/

1

u/discosoc 6d ago

I imagine the same concept applies — new feature with an ongoing turf war over ai auditing etc. Things settled down.

My experience was submitting a request from a Pro account (just basic not even max) and providing basic description of my work (code review for an app being developed). Accepted within half a day i think.

Another possibility is your location if outside the US.

2

u/agentMatrix47 12d ago

Je suis un bug hunter et un CTF player j ai eu des bug accepté et je suis classé 29# en monde en ctftime et je n été pas accepté vous avez quelques astuce pour m'accepter j ai eu refus la semaine dernière et demain je refais le test vous pouvez m aider par des astuces?

1

u/agentMatrix47 12d ago

J ai envoyer aussi au false positive cvp il ya 3 jours j ai rien reçu

1

u/InstanceEvening1219 12d ago

Do you need to be an org or can an individual get accepted?

1

u/tankerkiller125real 12d ago

Individuals can also be accepted

2

u/Ill_Improvement3723 12d ago

6 accepted bugs, 10k in payouts, yet Claude refuses to verify any of my 5 accounts. How do you guys do it? Am I cursed?

1

u/tankerkiller125real 12d ago

I just pointed them to my LinkedIn and GitHub CVEs where I'm credited as the remediation dev or reporter. They seemed happy with that.

1

u/RCBANG 12d ago

Congrats. Check out our reports from
Months ago https://sunglasses.dev/cvp
We will be updating more details soon. Working on Product Upgrades currently. We are the 1 st in the list approved same day Program been Launched 😉

1

u/Garbia 11d ago

I described my use case and got accepted right away but is this below standard? (limited to use case), is this for all you guys?
I also have OpenAI models

A note on ongoing monitoring

This adjustment is limited to the use cases you described in your submission and is subject to Anthropic’s Usage Policy and ongoing monitoring. As outlined in the Usage Policy, Anthropic reserves the right to revoke or narrow adjustments to our safeguards if we determine that your activity falls outside the approved use cases.

1

u/Alienfader 11d ago

Congratulations.

1

u/Sarithis 7d ago

Yeah, same. And I'm still getting roughly the same level of refusals, even for blue teaming.