Strobesstrobes
Platform
Solutions
Resources
Customers
Company
Pricing
Book a Demo
Strobesstrobes

Strobes connects every exposure signal to autonomous action, so security teams fix what matters, prove what works, and stop chasing noise.

Book a DemoTalk to an expert
ISO 27001SOC 2CREST
  • Platform
  • Platform Overview
  • Agentic Exposure Management
  • AI Agents
  • Integrations
  • API & Developers
  • Workflows & Automation
  • Analytics & Reporting
  • Solutions
  • Exposure Assessment (EAP)
  • Attack Surface Management
  • Application Security Posture
  • Risk-Based Vulnerability Management
  • Adversarial Exposure Validation (AEV)
  • AI Pentesting
  • Pentesting as a Service
  • CTEM Framework
  • By Industry
  • Financial Institutions
  • Technology
  • Retail
  • Healthcare
  • Manufacturing
  • By Roles
  • CISOs
  • Security Directors
  • Cloud Security Leaders
  • App Sec Leaders
  • Resources
  • Quick Agentic Pentest
  • Blog
  • Customer Stories
  • eBooks
  • Whitepapers
  • Datasheets
  • Videos & Demos
  • Exposure Management Academy
  • Pentesting ROI Calculator
  • Pentest Health Check
  • Security Tool ROI Calculator
  • Company
  • About Strobes
  • Meet the Team
  • Trust & Security
  • Contact Us
  • Careers
  • Become a Partner
  • Technology Partner
  • Partner Deal Registration
  • Press Release

Weekly insight for security leaders

CTEM research, agentic AI trends, and what's actually moving the needle.

© 2026 Strobes Security Inc. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibilitySitemap
Back to Blog
Anthropic Cyber Verification Program at Strobes, verified since June 2026
AI Security

Three months inside Anthropic's Cyber Verification Program at Strobes

Akhil ReniSeptember 21, 20263 min read

Authors

A
Akhil Reni

Share

Authors

A
Akhil Reni

Share

Every pentest is an attack that someone paid for. A model reading the request can't tell the difference, so it blocks both.

Strobes has been verified under Anthropic's Cyber Verification Program since June 2026, which lifts that block for authorized work. Claude models now run most of the agentic pentests we deliver. Three months in, here's what the program gates and what the access changed.

What is Anthropic's Cyber Verification Program?

CVP is an application-based review that lifts Anthropic's default restriction on high-risk dual-use cybersecurity work for a specific organization. Anthropic describes the program and the safeguard categories behind it on its transparency page. Verification is org-scoped and reviewed by Anthropic directly.

Anthropic draws a line between two categories. Prohibited use covers work with little to no defensive application: mass data exfiltration, ransomware development, command-and-control infrastructure. That stays blocked whether you're verified or not, and it isn't negotiable.

High-risk dual-use covers work that has real defensive value but overlaps with offensive technique. Vulnerability exploitation analysis, adversarial simulation, threat modeling, offensive tooling, and the practitioner workflows around them. Blocked by default. CVP is the path to opening it.

Why does agentic pentesting need dual-use access?

For Strobes, dual-use reasoning is not adjacent to the product. It is the product.

Our agents do not file a finding until they have proof. That means starting from recon, designing test cases against the target's actual attack surface, executing them, and then doing the part that scanners cannot: reasoning through whether a flaw is reachable, whether the surrounding configuration makes it exploitable, and whether several low-severity findings chain into one path that matters. An IDOR chained into SQL injection, reproduced end to end, is not something you arrive at by pattern matching. You get there by thinking the way the attacker thinks, which is precisely the reasoning that default safeguards restrict.

What changed after verification?

Before verification, that constraint showed up as interrupted runs in the middle of authorized engagements. After verification, the agents complete the work they were scoped to do.

Verified access strengthens the platform in specific places. Our web application workflows map to OWASP WSTG v4.2 and run concurrent specialist sub-agents across test categories, each designing and executing test cases in parallel. Exploit chaining across network, cloud, and Active Directory depends on the model holding an attacker's model of the environment across many steps. Proof-of-concept generation, full HTTP traces, and reproduction steps all come out of the same reasoning layer. Every validated finding then lands in the CTEM pipeline, where it gets prioritized, assigned, remediated, and retested.

Where verified access shows up: concurrent sub-agents mapped to OWASP WSTG v4.2, exploit chaining across network, cloud, and Active Directory, and the CTEM pipeline from prioritized to retested
Where verified access shows up: parallel WSTG-mapped testing, exploit chaining, and the CTEM pipeline.

Why this matters now

Raw model access is easy to come by. Verified access to a frontier model, under review and with governance attached, is not. That's where the defender advantage sits right now, and it has a shelf life.

FAQ

Is the Cyber Verification Program the same as an enterprise API agreement?

No. It's a separate application and review, scoped to one organization, that lifts default restrictions on high-risk dual-use cybersecurity work.

Does verification unblock everything?

No. Prohibited-use categories stay closed regardless of verification status.

Does Strobes run every engagement on Claude?

Claude models run most of the agentic pentests we deliver. Strobes also supports AWS Bedrock, Azure OpenAI, and OpenAI direct, including bring-your-own-LLM.

How does this affect customers who need evidence of authorization?

Nothing changes in scoping. Engagements still run against authorized targets under signed scope, with findings delivered through PTaaS workflows.

Strobes is CREST-accredited, SOC 2 Type II compliant, and CERT-In empanelled, serving 150+ enterprise customers across CTEM, agentic pentesting, and PTaaS.

Tags
agentic pentesting

Stop chasing vulnerabilities Start reducing exposure

See how Strobes AI agents validate and fix your most critical exposures automatically.

Book a Demo
Continue Reading

Related Posts

Are security practitioners actually ready for autonomous pentesting - a field perspective from Strobes Security
Penetration TestingAI Security

Are security practitioners actually ready for autonomous pentesting?

We asked 50+ security leaders one open question about autonomous pentesting. Here is the readiness spectrum that came back, and what vendors get wrong.

Sep 10, 202611 min
NIST just published AI prompts for CSF 2.0, here is what to settle first. Strobes banner showing document, AI model, and shield icons with the six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover
ComplianceAI Security

NIST just published AI prompts for CSF 2.0. Here is what to settle first

NIST's draft SP 1353 provides AI prompts for three CSF 2.0 tasks and says weeks of drafting compresses into hours. Here is what the prompts can draft, what only humans can validate, and the four things to settle before anyone opens a model.

Sep 4, 20268 min
How to automate pentest reporting without losing report quality
Penetration TestingAI Security

How to automate pentest reporting without losing report quality

Report quality is decided before the reporting layer runs. Here's the pipeline, the gates that stop bad output shipping, and what a real automated report contains.

Sep 1, 202615 min