跳到主要內容

Anthropic CVP評測:三層授權才能解鎖的Claude資安版 | Anthropic CVP Review: Claude's Three-Tier Security Unlock

By Kit 小克 | AI Tool Observer | 2026-10-07

🇹🇼 Anthropic CVP評測:三層授權才能解鎖的Claude資安版

Anthropic Cyber Verification Program(CVP)是Anthropic在10月6日正式推出的資安授權機制,把原本的Project Glasswing計畫併入,分成三層權限讓資安團隊申請「解鎖」Claude平常擋掉的資安功能。簡單說,一般人用Claude Opus 5.5、Sonnet 5.5寫滲透測試程式碼或分析惡意程式,常會被安全分類器擋下來;通過CVP審核的團隊可以拿到降低或移除這些限制的存取權,前提是要先讓Anthropic審核你的組織身份。

Anthropic Cyber Verification Program是什麼?

CVP是Anthropic對「資安工作本質上是雙面刃」這個問題的解法:公開版Claude為了防止被拿去開發勒索病毒等攻擊工具,預設擋掉大量資安相關請求,CVP則讓通過身份驗證的防守方拿到較寬鬆的存取權限。

三層授權怎麼分?

  • Defense Access:門檻最低,給事件應變、惡意程式逆向工程、漏洞驗證等防守型工作,企業、大學、政府單位都能申請,Anthropic表示審核幾天內就會回覆。
  • Red Team Access:開放經授權的滲透測試與紅隊演練,但限於你有權測試的系統。
  • Specialized Access:限制最少、門檻最高,只給經過嚴格審查、測試電網、飛航系統、電信或銀行轉帳等關鍵基礎設施的機構,部分審查還跟美國政府合作。

三個層級都能用到Claude Opus 5.5、Sonnet 5.5與Mythos 5.1,未來新模型上線也會同步開放。

Project Glasswing交出了什麼成績單?

前身Glasswing計畫從4月開跑,6月擴大到150個新組織,4到7月間合作夥伴驗證出至少12.9萬個真實軟體漏洞,其中3.3萬個以上被評為高危或極高危;Anthropic自己的開源掃描另外在4到10月間抓出5,500個。這組數字是CVP最大的賣點:證明「解鎖」後的Claude確實能挖出真漏洞,不是噱頭。

申請門檻高嗎?代價是什麼?

老實說,CVP不是公開功能,一般開發者或獨立研究者申請不到,身份審核偏向有組織背書的團隊。更現實的代價是:要加入計畫,組織得同意讓Anthropic保留使用記錄做監控與審查,這對在意資料隱私的資安團隊是個取捨——用更強的Claude資安能力,換出部分操作記錄的掌控權。如果你的組織本來就受監管或已經有合規的日誌留存流程,這筆交易不難接受;但對想「偷偷測試」的團隊來說,CVP不是捷徑。

好不好用,試了才知道。


🇺🇸 Anthropic CVP Review: Claude's Three-Tier Security Unlock

The Anthropic Cyber Verification Program (CVP) launched on October 6, folding the earlier Project Glasswing initiative into a three-tier access structure that lets vetted security teams unlock cybersecurity features Claude normally blocks. In plain terms: ask Claude Opus 5.5 or Sonnet 5.5 to write exploit code or analyze malware, and the default safety classifiers usually shut it down. Organizations approved through CVP get reduced or removed restrictions — but only after Anthropic verifies who they are.

What Is the Anthropic Cyber Verification Program?

CVP is Anthropic's answer to cybersecurity's dual-use problem: public Claude ships with conservative cyber safeguards to stop bad actors building attack tools, while CVP gives verified defenders a looser leash once their identity is confirmed.

How Do the Three Tiers Work?

  • Defense Access — the entry tier, for incident response, malware reverse engineering, and vulnerability validation. Companies, universities, and government bodies all qualify, and Anthropic says it aims to respond within a few days.
  • Red Team Access — opens authorized penetration testing and red-teaming, limited to systems you have permission to test.
  • Specialized Access — the fewest restrictions, reserved for rigorously vetted institutions testing critical infrastructure like power grids, flight systems, telecoms, or banking transfers, with some reviews run jointly with the U.S. government.

All three tiers get Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1, with future models added as they ship.

What Did Project Glasswing Actually Deliver?

Glasswing launched in April, expanded to 150 more organizations in June, and between April and July its partners verified at least 129,000 real software vulnerabilities, over 33,000 of them rated critical or high severity. Anthropic's own open-source scanning caught another 5,500 between April and October. That's the real selling point behind CVP — proof that an "unlocked" Claude finds genuine vulnerabilities, not just a marketing claim.

Is It Worth Applying? What's the Catch?

Honestly, CVP isn't a public feature — solo researchers and unaffiliated developers are unlikely to pass vetting; it favors organizations with institutional backing. The bigger trade-off: joining requires letting Anthropic retain usage logs for monitoring and review. For privacy-conscious security teams, that's a real cost — stronger cyber capability in exchange for giving up some control over your activity records. If your org already runs compliant logging, it's an easy trade; if you were hoping for a quiet backdoor around Claude's safeguards, CVP isn't it.

好不好用,試了才知道。

Sources / 資料來源

常見問題 FAQ

Anthropic Cyber Verification Program是什麼?

是Anthropic在2026年10月6日推出的三層資安授權機制,讓通過身份審核的資安團隊取得降低或移除安全限制的Claude存取權,用於防守、滲透測試與關鍵基礎設施驗證。

一般開發者可以申請CVP嗎?

偏難。CVP主要核准有組織背書的企業、大學或政府單位,獨立研究者或個人開發者通過審核的機會較低。

申請CVP要付出什麼代價?

最大的代價是必須同意讓Anthropic保留使用記錄做監控與審查,用資料掌控權換取更寬鬆的資安功能存取。

Project Glasswing和CVP有什麼關係?

Project Glasswing是CVP的前身,4月上線後6月擴大到150個組織,4到7月間驗證出至少12.9萬個真實漏洞,這些成果被併入新的三層CVP架構中。

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code