An organization seeking access submits an application and goes through a vetting process run by Anthropic. Once approved, it receives structured access to advanced Claude models in which the default restrictions on high-risk dual-use activity are lifted: vulnerability discovery, penetration testing and threat modelling. The lifting is not total — prohibited-use categories remain unavailable, so the program widens the scope of legitimate work rather than suspending the usage policy. CVP access is also documented on the cloud partner side; Claude models served through Google Cloud have separate documentation covering the program.
A model's safeguards cannot tell the difference between a security analyst studying a vulnerability and someone preparing an attack — the prompt looks the same. Blocking such tasks by default guards against misuse but cuts defenders off from the tool. CVP resolves this by moving the assessment of intent to the level of the organization and its vetting, instead of guessing it from the content of the query.
Access is not automatic — an organization applies and is vetted by Anthropic.
Approved organizations do not hit the default blocks on vulnerability discovery, penetration testing and threat modelling.
Outright prohibited uses remain blocked regardless of participation in the program.
Participation widens the scope of legitimate work but does not grant free rein — prohibited categories still apply.
It is the organization that is vetted; the expanded access does not follow an individual specialist who changes employer.
From mid-2026 successive security companies publicly announce acceptance into the CVP; the announcements appear between June and August 2026.