
Every pentest is an attack that someone paid for. A model reading the request can't tell the difference, so it blocks both.
Strobes has been verified under Anthropic's Cyber Verification Program since June 2026, which lifts that block for authorized work. Claude models now run most of the agentic pentests we deliver. Three months in, here's what the program gates and what the access changed.
CVP is an application-based review that lifts Anthropic's default restriction on high-risk dual-use cybersecurity work for a specific organization. Anthropic describes the program and the safeguard categories behind it on its transparency page. Verification is org-scoped and reviewed by Anthropic directly.
Anthropic draws a line between two categories. Prohibited use covers work with little to no defensive application: mass data exfiltration, ransomware development, command-and-control infrastructure. That stays blocked whether you're verified or not, and it isn't negotiable.
High-risk dual-use covers work that has real defensive value but overlaps with offensive technique. Vulnerability exploitation analysis, adversarial simulation, threat modeling, offensive tooling, and the practitioner workflows around them. Blocked by default. CVP is the path to opening it.
For Strobes, dual-use reasoning is not adjacent to the product. It is the product.
Our agents do not file a finding until they have proof. That means starting from recon, designing test cases against the target's actual attack surface, executing them, and then doing the part that scanners cannot: reasoning through whether a flaw is reachable, whether the surrounding configuration makes it exploitable, and whether several low-severity findings chain into one path that matters. An IDOR chained into SQL injection, reproduced end to end, is not something you arrive at by pattern matching. You get there by thinking the way the attacker thinks, which is precisely the reasoning that default safeguards restrict.
Before verification, that constraint showed up as interrupted runs in the middle of authorized engagements. After verification, the agents complete the work they were scoped to do.
Verified access strengthens the platform in specific places. Our web application workflows map to OWASP WSTG v4.2 and run concurrent specialist sub-agents across test categories, each designing and executing test cases in parallel. Exploit chaining across network, cloud, and Active Directory depends on the model holding an attacker's model of the environment across many steps. Proof-of-concept generation, full HTTP traces, and reproduction steps all come out of the same reasoning layer. Every validated finding then lands in the CTEM pipeline, where it gets prioritized, assigned, remediated, and retested.
Raw model access is easy to come by. Verified access to a frontier model, under review and with governance attached, is not. That's where the defender advantage sits right now, and it has a shelf life.
Is the Cyber Verification Program the same as an enterprise API agreement?
No. It's a separate application and review, scoped to one organization, that lifts default restrictions on high-risk dual-use cybersecurity work.
Does verification unblock everything?
No. Prohibited-use categories stay closed regardless of verification status.
Does Strobes run every engagement on Claude?
Claude models run most of the agentic pentests we deliver. Strobes also supports AWS Bedrock, Azure OpenAI, and OpenAI direct, including bring-your-own-LLM.
How does this affect customers who need evidence of authorization?
Nothing changes in scoping. Engagements still run against authorized targets under signed scope, with findings delivered through PTaaS workflows.
Strobes is CREST-accredited, SOC 2 Type II compliant, and CERT-In empanelled, serving 150+ enterprise customers across CTEM, agentic pentesting, and PTaaS.