Anthropic Expands Cyber Access: Check the Tier and Data Rules
Anthropic’s October 6 cyber program adds three access tiers. We explain eligibility, retained-data requirements, and what security teams should verify before applying.

Bottom line
Anthropic’s October 6 cyber program adds three access tiers. We explain eligibility, retained-data requirements, and what security teams should verify before applying.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 3 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 3
- Products covered
- 1
- Last checked
- 2026-10-07
Important limits
- • DiscoverAI has not independently reproduced the reported evaluations or tested the announced offering.
- • Vendor announcements and research results do not establish production safety, universal effectiveness, or return on investment.
In this guide
Short answer
Anthropic has expanded access for verified security professionals, but the access level and data rules matter as much as the model. For a small team, the useful question is whether a specific authorized workflow is blocked today and whether the proposed access resolves that problem within an acceptable operating environment.
What changed on October 6
The announcement combines the earlier Cyber Verification Program and Project Glasswing into three tiers. Defense Access covers defensive analysis. Red Team Access adds authorized adversarial testing. Specialized Access is for selected organizations testing sensitive safety systems. The tiers support Opus 5.5, Sonnet 5.5, and Mythos 5.1.
Anthropic reports that, in 50 Opus 5.5 evaluation trials per tier, Defense Access blocked 46 trials; Red Team Access had no blocks and completed 34. These vendor-run offensive scenarios measure a particular test configuration. They do not establish protection against every misuse or reliability on a buyer’s environment.
Eligibility is a workflow decision
The Help Center says organizations apply once and administrators assign access. Its FAQ allows individuals to apply for Defense Access on a paid plan. One application paragraph still calls individual access “Tier C,” so confirm the actual grant rather than interpreting that older label as an additional tier.
The same documentation says ordinary access still supports secure code review, threat modeling, patching known issues, and triaging alerts. Approval can be narrowed or withdrawn, and the usage policy continues to apply. Defense Access has a December 15, 2026 deadline for phishing-resistant MFA and stopping API-key use, with transitional requirements before then.
Our editorial recommendation is to document a concrete interrupted task before applying. A nonprofit with an external IT provider should first establish who owns security operations and who would administer an approved workspace. An access grant without an operator can add complexity without improving maintenance.
Retention needs its own review
The program requires retention for misuse monitoring, with an interim exception for organizations already eligible for zero-retention access to Fable or Mythos. Enterprise Frontier Safeguards is described as coming later in the fall. These details are in the announcement and current help documentation, not a promise that every customer can use zero retention immediately.
The EFS announcement describes customer-controlled storage and optional encryption and automated-review controls. It says Anthropic does not charge for EFS, but cloud storage and traffic costs can still apply. Confirm availability, contractual terms, and the exact cloud path before designing around that future arrangement.
Keep these questions separate: which capabilities are enabled, where prompts and outputs are stored, who can review them, and how access is revoked. A model entitlement does not answer the storage question. Neither does a reassuring product description establish that your own configuration meets an internal requirement.
A bounded evaluation for a small security team
The following is a proposed DiscoverAI evaluation, not a test we performed. Choose a sanitized, owned codebase with known defects and a documented repair history. Define the permitted task, expected deliverables, and who can authorize any change. Start with analysis and suggested patches; use your existing review process before applying them.
Record reproducible findings, irrelevant alerts, correction time, and the effort needed to inspect suggested repairs. Have the responsible engineer verify that a repair addresses the issue and preserves expected behavior. Include the cost of supervision in the comparison with your current process.
If access blocks a legitimate task, record the interruption and ask the vendor whether it belongs in the granted tier. Avoid expanding the scope simply to make a demonstration look productive. The most useful result may be learning that ordinary access already meets your needs.
What would justify adoption
A stronger adoption case would show useful results on your authorized workload, understandable grant boundaries, acceptable retention terms, and a named owner for review and maintenance. A benchmark completion rate alone cannot provide that evidence.
Our [earlier disclosure-dashboard analysis](/articles/anthropic-claude-vulnerability-dashboard-patching-gap-2026) explains why finding issues and deploying verified repairs are separate milestones. Use the [Decision Workspace](/decision-workspace) to keep the access decision, evidence, and operational costs together.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Is this unrestricted access to Claude?
No. Access is verified, tier-specific, and remains subject to policy and security requirements.
Can an individual researcher apply?
The current Help Center FAQ allows individual applications for Defense Access on a paid plan; confirm eligibility and the assigned grant.
Does approval guarantee zero data retention?
No. Retention is required by default; exceptions and planned EFS arrangements depend on eligibility.
Did DiscoverAI reproduce the benchmark?
No. The evaluation figures are Anthropic-reported, and our buyer evaluation is proposed rather than completed.
Tools mentioned in this article
Claude
Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning
Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.
Read next
Recommended for you

Run an AI Accessibility Acceptance Test Before Launch
A feature is not accessible because it has an accessibility label; representative users must be able to complete the real task and recover when the AI is wrong.
Test AI accessibility as an end-to-end workflow. This checklist covers input, output, uncertainty, errors, privacy, human fallback, and safe stop behavior.
Read guide
ChatGPT Dots vs. Claude Dispatch: Cloud Agent or Desktop Delegate?
Run a Two-Week AI Desktop Assistant Pilot
Codex vs. Claude Code: Which Coding Agent Should Teams Pilot?