Evolve Security Joins Anthropic’s Cyber Verification Program

By
Team Evolve Security
,
Contents

Evolve Security’s Offensive SOC now runs authorized adversarial AI research on verified, full-capability access to Claude.

Frontier AI labs are building safety guardrails directly into their models. Those guardrails can't always tell a chartered red team from an actual attacker. Prompt injection testing, exploit development, adversarial LLM research: the same techniques Evolve's Offensive SOC (OSOC) runs every day to find exposure before an adversary does are, by design, the exact behavior a frontier model is trained to be cautious about. That's not a flaw in the safety work. It's a verification problem, and until now it's been an unsolved one for the offensive security industry.

Evolve Security has been accepted into Anthropic's Cyber Verification Program (CVP), a vetting process that confirms our OSOC operators as legitimate defensive security professionals and preserves full, unthrottled access to Claude's reasoning for authorized offensive work.

CVP doesn't change how Evolve validates findings. It changes what gets in the way while our team does it. Continuous Penetration Testing runs on a simple division of labor: automated discovery plus human validation, not automated discovery standing in for it. Darwin Attack's AI Attack Planning layer already uses Claude to model attack paths and prioritize what the OSOC reviews next. CVP removes the friction of a model second-guessing legitimate red team activity mid-engagement, so operators spend their time on judgment calls, not workarounds.

The impact is most direct on Evolve's AI Penetration Testing practice. Testing an LLM or agent system for prompt injection, data leakage, and model-poisoning risk means deliberately trying to break the same category of model doing the defending. That's the dual-use tension CVP was built to resolve. Evolve's AIRTP+ certified engineers now do that work with verified standing, not around a safety net designed for a different threat model.

"Frontier models are becoming core infrastructure for both attackers and defenders.Verification programs like Anthropic's are how the industry keeps defenders on equal footing.Our OSOC operators can now do full-depth adversarial AI research without the platform mistaking their job for the threat it's designed to catch."

JASON ROWLAND, CHIEF DELIVERY OFFICER, EVOLVE SECURITY

This is the same principle behind every service Evolve runs: automation scales the work, human expertise decides what matters. CVP extends that principle to the AI layer itself. It doesn't replace OSOC validation and it doesn't change Evolve's 99% vulnerability validation accuracy. It just means one less obstacle between a real finding and the client who needs to know about it.

Legacy pen tests check a compliance box once a year. Continuous testing protects your business every day in between. Now that testing runs on verified, full-capability access to the same frontier models attackers are learning to use against you.

Are you ready to evolve?

Start with combining Threat Modeling with AI Pen Testing to uncover exposure in your AI systems before attackers do.

Published:
September 24, 2026
About the Author,

Team Evolve Security

Evolve Security is an offensive cybersecurity solution, delivering continuous penetration testing with the optimal blend of AI automation and human expertise, providing peace of mind through greater cyber resiliency.

Learn more about
Team Evolve Security

What is EPSS?

The Exploit Prediction Scoring System (EPSS) is a data-driven risk model maintained by FIRST that predicts the likelihood of vulnerability being exploited in the wild within the next 30 days. It complements CVSS by focusing on real-world exploitability.
For example, a CVSS 9.8 vulnerability with an EPSS of 0.1% may pose less immediate risk than a CVSS 7.5 vulnerability with a 75% EPSS.
EPSS updates daily and is publicly accessible at https://www.first.org/epss/.