

If you’ve ever asked an AI assistant to help with real security work, you’ve hit the wall. Ask it to analyze a piece of malware that just hit a client’s site, reason through how an exploit chain works, or build the kind of tooling a red team uses, and the answer comes back polite and useless. That wall is there on purpose. The same capability that helps a defender understand an attack helps an attacker run one, and a company like Anthropic can’t tell the difference from a chat window.
So they built a door instead of removing the wall. The Cyber Verification Program is that door. An organization describes the security work it does, how it does it, and who it does it for. Anthropic’s Safeguards Team reviews the application, and if they’re satisfied, they adjust the safeguards on that organization’s account so Claude will do the dual-use parts of the job: vulnerability analysis, exploit reasoning, offensive tooling used for defensive ends.
On June 12 they approved us. The approval is scoped to the AZ Technology Solutions organization and to the use cases we described, and it stays subject to Anthropic’s Usage Policy.
The precise claim is the only one worth making. We are approved under Anthropic’s Cyber Verification Program. We are not Anthropic’s partner, and nobody here is a security researcher with Anthropic. If you ever catch us saying more than that, hold us to this sentence.
Why this is a trust story and not a capability story
Here’s the part we actually care about. The interesting thing isn’t that Claude will now help us reason through an exploit. Plenty of tools will do that if you’re willing to use ones with no guardrails at all. The interesting thing is who decided and on what basis. A team whose entire job is to say no looked at our company and processes, and said yes.
That is a third party checking our process, not our marketing. It’s the same reason n8n, the automation company our founder used to work for, brings us in for cybersecurity advice: people who know the work have looked at the work.
And it lines up with the thing we keep saying in this series: the value of AI in a business is never the model. It’s the control around the model. Who is allowed to point it at what, under which rules, with whom accountable at the end. Verification is that control, applied to us, by someone with every incentive to say no.
Guardrails exist because the tool can’t tell a defender from an attacker. Verification exists because a human can. The guardrails didn’t get weaker for us; the trust moved from the tool to the people holding it.
