Anthropic announced that scanning in Claude Security now runs on Claude Mythos 5, the company's most powerful model. The feature is in public beta for Claude Enterprise plan customers: it does not provide direct access to Mythos 5, the model runs in the background, and only findings and proposed fixes go out.
!image.jpg)

What happened
An administrator enables Claude Security in the admin console, and a user selects a repository in claude.ai/security. The model returns each finding with a CWE category, a standard classification of vulnerability types, confidence and severity scores, and a proposed fix. Fixes in Claude Code are executed by the models already available to the organization, and each patch must be reviewed and approved by a human. Scanning is billed as regular tokens under the current plan, with no extra charges. Along with the announcement, Anthropic is launching the Defender Advantage (0xDAF) fund, worth $35 million in Claude credits.
Context
Claude Mythos 5 is Anthropic's flagship frontier model. Instead of an open API, the company is building a managed service: the model runs in the background within Claude Security and partner products, and the user only receives defensive artifacts, namely findings, patches, and alerts, and cannot request the model to create an exploit. The announcement is accompanied by an expansion of the Cyber Verification Program, a security verification program, and an integration principle that Anthropic describes as foundational: out goes only the artifact, without dialogue with the model.
Why this matters for the industry
Anthropic is demonstrating a reproducible pattern for safely releasing frontier model capabilities: the top model is embedded in a managed product and partner products, and only defensive artifacts go out. The company itself describes the "model-oracle with a limited interface" pattern as a foundational principle for future integrations, and it sets the framework for how the market will gain access to top cyber capabilities of frontier models. For Enterprise customers, built-in scanning will reshape the economics of buying independent scanners in the next renewal cycles, and the $35 million fund is a signal that major players are beginning to systematically fund software supply chain protection.
Why this matters for users
For organizations on the Claude Enterprise plan, launch is trivial: a toggle in the admin console and a repository selection in claude.ai/security. A pilot on one or two key repositories can be launched right now, expecting structured findings with a CWE category and ready-made patches. Even outside Enterprise, it is important to note the principle: Anthropic separates what the model can do from what the user receives, and this approach will likely become the standard for all frontier models as their cyber capabilities grow.
What is still unknown / limitations
The entire evidence base is from the vendor itself: the only sources of technical facts are the Anthropic blog and product page, with no independent assessments or open methodology. The claim of the company's most powerful model is a marketing statement without numbers: the sources contain no metrics, no comparison with other models, and no scanning benchmark against specialized SAST/DAST tools. Confidence scores lack calibration data, so they cannot be used as a quantitative measure of risk. The mandatory human approval of each patch indicates that the model's fixes are not yet considered reliable enough for autonomous application, and the public beta is not accompanied by published data on scanner quality.
Sources
- Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders (Anthropic blog)
- Claude Security (official Anthropic product page)
Author
Look at AI, editorial team
