![]()
ArmorCode, the leading Unified Exposure Management platform, today announced that it has been accepted into Anthropic’s Cyber Verification Program (CVP). The program gives ArmorCode’s research and engineering teams verified access to the full dual-use reasoning capabilities of Anthropic’s most capable Claude models for legitimate defensive security work, under Anthropic’s security and governance requirements.
The security industry has spent years getting better at finding vulnerabilities. The harder problem is determining which ones actually matter, in what order, and in the context of how an attacker would move through a real environment. That is the problem ArmorCode was built to solve, and it is why acceptance into the CVP is a meaningful step forward for the platform.
What is the Anthropic Cyber Verification Program
Anthropic’s most capable models can now reason through complex offensive security scenarios, including traversing attack paths, assessing exploitability, and modeling how vulnerabilities chain together into real risk. By default, Anthropic blocks two categories of activity on these models. The first is prohibited use, such as ransomware development or mass data exfiltration tooling, which is blocked for everyone with no exceptions. The second is high-risk dual-use work, such as vulnerability exploitation analysis and adversarial simulation, which has genuine defensive value but is indistinguishable from attacker intent without verification.
The CVP is Anthropic’s structured answer to that challenge. Acceptance is application-based, organization-scoped, and reviewed by Anthropic directly. Verified organizations can lift the dual-use restrictions for legitimate defensive work while prohibited-use restrictions remain in place regardless of verification status. ArmorCode has met that standard and been accepted into the program.
Adversarial Reasoning at Exposure Management Scale
ArmorCode processes more than 300 billion findings annually across application, infrastructure, cloud, and AI security, unifying them into a single exposure management layer. The platform’s job is not to surface more findings. It is to help security teams extract the signal about exposures that represent real, exploitable risk and what to fix first. That requires thinking the way an attacker would: modeling how a flaw in one layer connects to an exposure in another, and how a chain of lower-severity findings becomes a critical choke point when viewed together.
CVP-enabled access lets ArmorCode’s research and engineering teams perform that exploitability analysis at depth, without the default interruptions that would otherwise limit it. ArmorCode will use this access internally to build, test, and validate the models that power Anya, the ArmorCode Platform’s Agentic Control Plane. The result is sharper platform output: higher-fidelity exploitability scoring, more accurate attack path analysis, and a stronger prioritization signal, applied first to ArmorCode’s Vulnerability Insights module and attack path analysis work.
“Attackers have never waited for permission to use powerful AI, and for too long defenders have been working with reasoning that stops short of how real threats actually operate,” said Mark Lambert, Chief Product Officer at ArmorCode. “With verified access through Anthropic’s Cyber Verification Program, our teams can reason about exploitability and attack paths with the same depth an adversary would and apply it to protection. That is exactly what Unified Exposure Management demands. It means our customers get an accurate picture of real risk across application, infrastructure, cloud, and AI, not another inflated list of findings.”
Closing the Defender Asymmetry Gap
The window between a vulnerability being discovered and being exploited is collapsing. Security teams that rely on noisy, unvalidated finding lists are increasingly exposed, while threat actors already apply sophisticated AI reasoning without guardrails. Anthropic designed the CVP to close that gap by giving verified defenders the same depth of reasoning, applied to defense rather than exploitation, and only after an organization demonstrates a genuinely defensive use case and meets Anthropic’s security requirements.
ArmorCode’s acceptance is one step toward making sure the AI reasoning behind its platform reflects the sophistication of the threats its customers face. As that research matures, it will continue to raise the quality bar on exploitability analysis across the platform and improve the signal security teams rely on to make remediation decisions.
About ArmorCode
ArmorCode helps enterprises manage security risk and governance across today’s heterogeneous technology environments. The ArmorCode Agentic AI Platform gives security teams a system of action, moving from fragmented signals to owned, policy-driven, auditable decisions. Its unified exposure management capabilities deliver visibility, insight and control across four solutions: Application Security Posture Management, Vulnerability Management, Software Supply Chain Security and AI Exposure Management.
Processing over 300 billion findings a year across hundreds of native integrations, ArmorCode unifies, prioritizes and drives remediation across applications, cloud, code, infrastructure and AI. Powered by Anya, the industry’s first agentic AI framework for enterprise security, ArmorCode is trusted by global enterprises to reduce exposure and adopt AI and modern software practices with confidence, without replacing existing tools or forcing vendor consolidation.
For more information, visit www.armorcode.com.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260728748020/en/
Media gallery
