GuideUpdated 2026-10-07

Anthropic Expands Cyber Access: Check the Tier and Data Rules

Anthropic’s October 6 cyber program adds three access tiers. We explain eligibility, retained-data requirements, and what security teams should verify before applying.

By DiscoverAI Editorial TeamReviewed by DiscoverAI Editorial Review4 min readBuild, Design & GovernHow we evaluate
Paper security gates beside a shield, code document, approval token, and locked log folder
Original DiscoverAI editorial illustration. Original editorial illustration; not a product screenshot or measured result.

Bottom line

Anthropic’s October 6 cyber program adds three access tiers. We explain eligibility, retained-data requirements, and what security teams should verify before applying.

Editorial accountability

Who checked this guide

Meet the editorial team →
Evaluation type
Research-based verification
Last materially checked
Evidence
3 listed sources

Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.

Editorial basis

What this guidance is based on

Editorial basis
Source-led analysis
Primary references
3
Products covered
1
Last checked
2026-10-07

Important limits

  • • DiscoverAI has not independently reproduced the reported evaluations or tested the announced offering.
  • • Vendor announcements and research results do not establish production safety, universal effectiveness, or return on investment.
In this guide
  1. Short answer
  2. What changed on October 6
  3. Eligibility is a workflow decision
  4. Retention needs its own review
  5. A bounded evaluation for a small security team
  6. What would justify adoption

Short answer

Anthropic has expanded access for verified security professionals, but the access level and data rules matter as much as the model. For a small team, the useful question is whether a specific authorized workflow is blocked today and whether the proposed access resolves that problem within an acceptable operating environment.

What changed on October 6

The announcement combines the earlier Cyber Verification Program and Project Glasswing into three tiers. Defense Access covers defensive analysis. Red Team Access adds authorized adversarial testing. Specialized Access is for selected organizations testing sensitive safety systems. The tiers support Opus 5.5, Sonnet 5.5, and Mythos 5.1.

Anthropic reports that, in 50 Opus 5.5 evaluation trials per tier, Defense Access blocked 46 trials; Red Team Access had no blocks and completed 34. These vendor-run offensive scenarios measure a particular test configuration. They do not establish protection against every misuse or reliability on a buyer’s environment.

Eligibility is a workflow decision

The Help Center says organizations apply once and administrators assign access. Its FAQ allows individuals to apply for Defense Access on a paid plan. One application paragraph still calls individual access “Tier C,” so confirm the actual grant rather than interpreting that older label as an additional tier.

The same documentation says ordinary access still supports secure code review, threat modeling, patching known issues, and triaging alerts. Approval can be narrowed or withdrawn, and the usage policy continues to apply. Defense Access has a December 15, 2026 deadline for phishing-resistant MFA and stopping API-key use, with transitional requirements before then.

Our editorial recommendation is to document a concrete interrupted task before applying. A nonprofit with an external IT provider should first establish who owns security operations and who would administer an approved workspace. An access grant without an operator can add complexity without improving maintenance.

Retention needs its own review

The program requires retention for misuse monitoring, with an interim exception for organizations already eligible for zero-retention access to Fable or Mythos. Enterprise Frontier Safeguards is described as coming later in the fall. These details are in the announcement and current help documentation, not a promise that every customer can use zero retention immediately.

The EFS announcement describes customer-controlled storage and optional encryption and automated-review controls. It says Anthropic does not charge for EFS, but cloud storage and traffic costs can still apply. Confirm availability, contractual terms, and the exact cloud path before designing around that future arrangement.

Keep these questions separate: which capabilities are enabled, where prompts and outputs are stored, who can review them, and how access is revoked. A model entitlement does not answer the storage question. Neither does a reassuring product description establish that your own configuration meets an internal requirement.

A bounded evaluation for a small security team

The following is a proposed DiscoverAI evaluation, not a test we performed. Choose a sanitized, owned codebase with known defects and a documented repair history. Define the permitted task, expected deliverables, and who can authorize any change. Start with analysis and suggested patches; use your existing review process before applying them.

Record reproducible findings, irrelevant alerts, correction time, and the effort needed to inspect suggested repairs. Have the responsible engineer verify that a repair addresses the issue and preserves expected behavior. Include the cost of supervision in the comparison with your current process.

If access blocks a legitimate task, record the interruption and ask the vendor whether it belongs in the granted tier. Avoid expanding the scope simply to make a demonstration look productive. The most useful result may be learning that ordinary access already meets your needs.

What would justify adoption

A stronger adoption case would show useful results on your authorized workload, understandable grant boundaries, acceptable retention terms, and a named owner for review and maintenance. A benchmark completion rate alone cannot provide that evidence.

Our [earlier disclosure-dashboard analysis](/articles/anthropic-claude-vulnerability-dashboard-patching-gap-2026) explains why finding issues and deploying verified repairs are separate milestones. Use the [Decision Workspace](/decision-workspace) to keep the access decision, evidence, and operational costs together.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

Is this unrestricted access to Claude?

No. Access is verified, tier-specific, and remains subject to policy and security requirements.

Can an individual researcher apply?

The current Help Center FAQ allows individual applications for Defense Access on a paid plan; confirm eligibility and the assigned grant.

Does approval guarantee zero data retention?

No. Retention is required by default; exceptions and planned EFS arrangements depend on eligibility.

Did DiscoverAI reproduce the benchmark?

No. The evaluation figures are Anthropic-reported, and our buyer evaluation is proposed rather than completed.

Free AI governance buyer checklist

Know what the tool can read, write, retain, and trigger.

Get a checklist for access, evidence, security, ownership, and rollback—plus one decision-ready briefing a week.

Free · one email a week · unsubscribe any timePreview the checklist →

Tools mentioned in this article

Claude

Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning

4.5

Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.

FreemiumChatbotsWriting

Read next

More on Build, Design & Govern →