PuppyIP Resource Center
AI Tool Updates 7 min read Published 2026-10-08

Who Can Apply for Claude CVP? Individual Defense Access and Next Steps

Individual security researchers can apply for Claude CVP, currently only paid-plan Defense Access. Organizations' authorized penetration testing belongs to another tier. After approval, implement access and security conditions for the chosen interface; subscription purchase is not approval.

Claude Cyber Verification Program Defense Access Red Team Access Workspace permissions

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • The October 6 expansion creates Defense, Red Team, and Specialized tiers with different verification and work scopes.
  • Check whether CVP is needed: ordinary code review, known-vulnerability fixes, and inspection of your own source remain available through general models.
  • Approved Console/API users must verify the workspace. Team, Max, and Pro authorization attaches at organization level.
  • Individual Defense traffic is retained and monitored without ZDR. Stricter identity and credential requirements apply by December 15.

Start with the work: Not every security task needs CVP

Anthropic expanded the Cyber Verification Program (CVP) October 6, 2026, giving eligible security practitioners advanced capabilities and fewer restrictions for corresponding work. The program covers models including Opus 5.5, Sonnet 5.5, and Mythos 5.1.

General models can still review code, fix known vulnerabilities, inspect your own source, and triage security alerts. If professional defense is persistently blocked, assess CVP fit. Successful model calls and specialized authorization are separate.

Hypothetically, maintaining your open-source project and performing authorized penetration testing for a client both find vulnerabilities but need different eligibility. This is not an application or usage test.

Which tier is available to individuals or organizations?

Defense Access supports incident response, malware analysis, and vulnerability verification. Examples include security teams, open-source maintainers, and researchers with vulnerability-reporting records. Individuals can currently apply only for this tier with a paid plan.

Red Team adds authorized penetration testing and red-team work, currently for organizations only. Test authorized systems only; restrictions remain for physical-harm and other high-risk activities. Reviews are expected to take weeks, with eligible organizations able to enter Defense meanwhile.

Specialized Access is for a small set of deeply verified organizations working on systems affecting life or critical infrastructure. It is not an individual paid upgrade. Existing Glasswing members do not need reapproval for existing models.

Where to apply, and what the review target means

Direct Anthropic users open Programs in the Verification Portal, choose Cyber Verification Program, then Apply. Prepare identity, organization, work description, and tier-appropriate security controls. Verification determines approval, not plan name alone.

Organizations submit once, with administrators assigning members; independent researchers apply individually. The help center targets a decision or request for more information within seven working days, not guaranteed approval in seven days or replacement of Red Team's longer review.

Cloud or third-party users need separate account linking. A third-party tool must support CVP; displaying a Claude model does not establish specialized authorization support. Identify the actual integration before following its application steps.

Why approved work can still be blocked

Console/API Owners or Admins should confirm authorization remains valid, the workspace qualifies, and calls use its credentials. Programs appears under Organization Settings; non-administrators may not see complete authorization information.

Some programs automatically cover qualifying workspaces; others need assignment. Read specific qualification errors instead of blindly opening accounts. Team, Max, and Pro authorization attaches at organization level, so API workspace steps do not apply universally.

Verify work remains within the approved tier. CVP does not remove usage policies. For in-scope work still blocked, retain errors and use official feedback rather than replacing verification with another network or shared session.

Individual data conditions and the December 15 deadline

Individual Defense traffic is retained and monitored without ZDR, and logins or sessions cannot be shared. From approval, enable multifactor authentication and use Google or an equivalent identity provider for the authorized account.

By December 15, 2026, use phishing-resistant authentication such as security keys or passkeys and disable email magic links. Static or long-lived API credentials cannot continue for model access; follow documented workload identity federation for programmatic access.

Keep the one transitional personal API key in a password manager or local secret store, rotate at least every seven days, and never share or commit it. Existing CVP members retain access under current terms; organization exceptions do not automatically extend to individual applicants.

Three checks to make first

Define the work: system maintained, defense versus authorized testing, and its owner or authorization. This determines individual Defense versus an organization application.

Identify Claude app, Console/API, cloud, or third-party access; who sees authorization; and how workspace/member permissions take effect. Approval, model visibility, and actual task access need independent checks.

Confirm material may enter the required retention and monitoring environment. Enterprise Frontier Safeguards remains a future official plan, not universally available today. This guide made no applications or calls; account, regional, and approval outcomes depend on verification.

Sources

Frequently Asked Questions

Must existing CVP members reapply?

Existing CVP or Glasswing organizations retain current model terms and transition to corresponding programs. New models are assessed under the expanded program; this does not grant every tier or unlimited usage.

Does CVP make models free?

No. It addresses capability and authorization, not waived subscription, model, or cloud charges. Check eligibility, approved access, and billing separately.

Can Bedrock use the ordinary activation path?

Do not assume so. Help guidance gives Bedrock separate retention-exemption and EFS eligibility conditions plus account linking and tier activation. Approval and model availability can differ in timing; follow its dedicated instructions.