IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
ArmourCode gets verified Claude access for cyber defence

ArmourCode gets verified Claude access for cyber defence

Sat, 15th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

ArmourCode has been accepted into Anthropic's Cyber Verification Program, giving the security company verified access to Anthropic's most advanced Claude models for defensive cyber work.

The program is designed for organisations that need to carry out high-risk, dual-use security analysis that could otherwise resemble offensive activity. Anthropic reviews applications directly and blocks prohibited uses for all participants.

ArmourCode's research and engineering teams will use the access to examine exploitability, attack paths, and how separate vulnerabilities can combine into broader security risk. The work will be carried out under Anthropic's security and governance requirements.

The arrangement matters because some of the most advanced artificial intelligence models can now reason through complex security scenarios in ways that are useful to both defenders and attackers. That creates a challenge for model providers, which must distinguish legitimate defensive work from misuse.

Anthropic's program addresses that issue by verifying organisations rather than opening these functions to all users. Under the scheme, accepted groups can use the models for defensive analysis while restrictions on prohibited conduct remain in place.

ArmourCode operates in the exposure management market, where vendors aim to help security teams decide which weaknesses pose the most immediate danger. Its platform handles more than 300 billion findings each year across application, infrastructure, cloud, and AI security.

Rather than simply identifying vulnerabilities, exposure management tools aim to rank them by likely real-world impact. That often involves linking issues across different layers of an organisation's technology environment and testing how an attacker could move between them.

Defensive analysis

ArmourCode will use the new access internally to build, test, and validate models that support Anya, which it describes as the agentic control plane within its platform. The work will initially be applied to its Vulnerability Insights module and attack path analysis.

The broader debate in cybersecurity has centred on whether defenders are falling behind attackers in the use of AI tools. Security companies argue that criminal groups do not face the same restrictions when applying automated reasoning to map targets, assess weaknesses, and chain flaws together.

That concern has helped drive interest in systems that move beyond static lists of technical findings. For security teams dealing with thousands or millions of alerts, the challenge is increasingly not detection but prioritisation.

Mark Lambert, Chief Product Officer at ArmourCode, said the company sees the program as a way to improve that process. "Attackers have never waited for permission to use powerful AI, and for too long defenders have been working with reasoning that stops short of how real threats actually operate," Lambert said.

"With verified access through Anthropic's Cyber Verification Program, our teams can reason about exploitability and attack paths with the same depth an adversary would and apply it to protection. That is exactly what Unified Exposure Management demands. It means our customers get an accurate picture of real risk across application, infrastructure, cloud, and AI, not another inflated list of findings," he added.

Market pressure

The announcement comes as companies across the cybersecurity sector try to show that AI can improve accuracy rather than add another layer of noise. Vendors have been under pressure to demonstrate that automated analysis can help customers cut through large volumes of vulnerability data and focus on the issues most likely to be exploited.

Anthropic's program reflects a wider shift among AI developers towards tighter controls for sensitive use cases. Model makers have become more cautious about providing unrestricted access to systems that can assist with exploit development, adversarial simulation, or other high-risk activity, even when there is a clear defensive rationale.

For security vendors, that creates a balancing act. They want access to advanced reasoning to test defences and model threats, but they also need to satisfy governance standards set by the AI providers that control those systems.

ArmourCode said acceptance into the program will help improve exploitability scoring and attack path analysis across its platform. It framed that as part of a broader push to give customers a clearer signal on what to fix first as the time between vulnerability disclosure and exploitation continues to narrow.

The company said the move is intended to ensure the AI reasoning behind its platform matches the sophistication of the threats its customers face.