AZ Technology Solutions, approved under the Cyber Verification Program

THE LAST LAYER · TRUST

Anthropic turned off the guardrails for us. Here’s why that’s a trust story.

In June, Anthropic’s Safeguards Team approved AZ Technology Solutions into its Cyber Verification Program. That sentence is easy to inflate and easy to misread, so this post is about what it actually means, what it doesn’t, and what it changes for the security work you might bring us.

The wall and the door: a lit doorway in a dark wall, the AZ Tech mark above it

If you’ve ever asked an AI assistant to help with real security work, you’ve hit the wall. Ask it to analyze a piece of malware that just hit a client’s site, reason through how an exploit chain works, or build the kind of tooling a red team uses, and the answer comes back polite and useless. That wall is there on purpose. The same capability that helps a defender understand an attack helps an attacker run one, and a company like Anthropic can’t tell the difference from a chat window.

So they built a door instead of removing the wall. The Cyber Verification Program is that door. An organization describes the security work it does, how it does it, and who it does it for. Anthropic’s Safeguards Team reviews the application, and if they’re satisfied, they adjust the safeguards on that organization’s account so Claude will do the dual-use parts of the job: vulnerability analysis, exploit reasoning, offensive tooling used for defensive ends.

On June 12 they approved us. The approval is scoped to the AZ Technology Solutions organization and to the use cases we described, and it stays subject to Anthropic’s Usage Policy.

The precise claim is the only one worth making. We are approved under Anthropic’s Cyber Verification Program. We are not Anthropic’s partner, and nobody here is a security researcher with Anthropic. If you ever catch us saying more than that, hold us to this sentence.

What the approval is

What the approval is

A review of how we do security work, and a decision to trust us with the capabilities that are blocked by default. It is scoped to our organization and our described use cases, and it stays subject to Anthropic’s Usage Policy.

It means the hard parts of incident response, phishing analysis, and reconnaissance no longer stop at the wall.

What it is not

What it is not

Not a partnership, not an endorsement, not an affiliation. Anthropic does not vouch for our services. The approval is monitored and it can be revoked. Genuinely prohibited uses stay blocked no matter who is asking.

It is permission to do a job well, on the condition that we keep doing it responsibly.

Why this is a trust story and not a capability story

Here’s the part we actually care about. The interesting thing isn’t that Claude will now help us reason through an exploit. Plenty of tools will do that if you’re willing to use ones with no guardrails at all. The interesting thing is who decided and on what basis. A team whose entire job is to say no looked at our company and processes, and said yes.

That is a third party checking our process, not our marketing. It’s the same reason n8n, the automation company our founder used to work for, brings us in for cybersecurity advice: people who know the work have looked at the work.

And it lines up with the thing we keep saying in this series: the value of AI in a business is never the model. It’s the control around the model. Who is allowed to point it at what, under which rules, with whom accountable at the end. Verification is that control, applied to us, by someone with every incentive to say no.

Guardrails exist because the tool can’t tell a defender from an attacker. Verification exists because a human can. The guardrails didn’t get weaker for us; the trust moved from the tool to the people holding it.

What it changes for the work you’d hire us for

THE HONEST PART

Anthropic opened the door. Doing the work right is still on us.

We want to be careful not to let a credential do work it can’t do. Anthropic reviewed our use cases; they did not audit our client engagements. If a cleanup misses a backdoor or a report gets a finding wrong, that’s our name on it, not theirs. The approval removes a wall between us and the work. It does not remove the part where a person has to be right.

That’s the whole thesis of The Last Layer, and it’s why we’re comfortable putting this on the About page instead of in a sales deck. AI takes the labor out of security work. It does not take the ownership out. Somebody still signs the report, and we’d rather you know exactly what the signature covers.

Approved under Anthropic’s Cyber Verification Program. Accountable to you. Two different sentences, and we intend to keep both true.

Have a security problem your current tools keep flinching at?

Bring it to office hours. We’ll tell you honestly whether it’s a job for us, what it would take, and what you can do yourself first. No alarm, no hard sell.

ABOUT THE AUTHOR

Angel Menendez, Founder of AZ Technology Solutions

Former Staff Developer Advocate at n8n, with 20+ years at the intersection of cybersecurity, automation, and AI: SOAR playbooks at Palo Alto Networks, AI-agent infrastructure at n8n, and production systems for organizations that can’t afford “AI that demos.” I build the tools and stay accountable for what they protect. The harness, the writing, and the experiments live at djangelic.com.

See what I speak about →  ·  Grab free office hours →

Stay curious out there.