Wingback Security has been accepted into Anthropic’s Cyber Verification Program (CVP). On paper it is a short approval. In practice it changes what we can do for customers: our red-team engine can now use Claude for the offensive security work that defending AI systems actually requires.
What the program is
Frontier models are dual-use. The same capability that lets Claude reason about an exploit chain in order to defend against it could, in the wrong hands, help build one. Anthropic’s approach is not to pretend that tension away. It is to draw a clear line and verify who sits on each side of it.
There are two categories behind that line. Prohibited use covers the things with no legitimate defensive story, like ransomware development or mass data exfiltration, and it stays blocked for everyone whether you are verified or not. High-risk dual-use work covers vulnerability exploitation analysis, adversarial simulation, and offensive security tooling. That work is blocked by default, and the CVP is the application-based, organization-scoped review that lifts the block for vetted teams with a genuine defensive purpose.
Being accepted means Anthropic has reviewed Wingback as an organization and confirmed that our use of these capabilities is what we say it is: security.
Why it matters for Wingback
Our platform includes an adaptive red-team engine. It is an LLM-driven attacker that probes your models, agents, and RAG pipelines the way a real adversary would, across dozens of techniques and vulnerability classes, and it maps every finding to frameworks like the OWASP LLM and Agentic Top 10 and MITRE ATLAS.
That work is, by definition, high-risk dual-use. To simulate prompt injection, tool misuse, and privilege-escalation attacks convincingly, the attacker has to think like an attacker. Verified access means our engine can do that with Claude at full strength, with no watered-down simulations and no blind spots a real adversary would not have. The model’s prohibited-use guardrails stay firmly in place around everything else.
Here is the part customers care about: a red team that finds what a real one would, where every validated finding auto-compiles into a runtime guard so the same attack cannot run twice.
Building where the models are governed
We have said before that the wingback is the defender who runs with the attack. Securing AI means working inside the AI ecosystem, not bolted on beside it, and that includes doing offensive work under the same governance the rest of the industry is being held to. Joining the CVP is us doing exactly that: using frontier capability for defense, verifiably, and on the record.
If you want to see the adaptive red team run against your own agents, request a demo. If you would rather read first, start with the platform one-pager.
Learn more about the program on Anthropic's site. Wingback's use of Claude for red teaming operates within the program's approved dual-use scope; prohibited-use restrictions apply regardless of verification status.
Wingback Security