Repository navigation
Anthropic and OpenAI Cyber Verification Programs #483
ezl-keygraph
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Anthropic and OpenAI apply cyber safeguards to security workloads and offer verification programs for authorized security practitioners. Shannon's vulnerability analysis and exploitation tasks can trigger these safeguards even during an authorized engagement. A pentest can start successfully and still be blocked at a later stage, so completing verification in advance helps reduce interruptions. This post covers provider enrollment, validating model access in Shannon, and the model options available while awaiting approval.
Before running Shannon with the latest Anthropic models (Claude Opus 5 and Sonnet 5) and OpenAI models (GPT-5.5, GPT-5.6 series, and GPT-6 series), complete your provider's cyber verification program.
These requirements are also covered in our AI provider guide.
Anthropic - Cyber Verification Program
Shannon supports the Anthropic API. Follow the Anthropic first-party instructions in Anthropic's Cyber Verification Program guidance to enroll your API organization. Approval is tied to that organization, so use an API key from it when running Shannon.
Opus 5.5 and Sonnet 5.5 are not yet covered by the current program. Anthropic has announced that CVP access will expand in the coming weeks to include both models.
OpenAI - Daybreak Blue
Daybreak Blue is OpenAI's verified access tier for defensive cybersecurity work with its general-purpose models. Enroll for the OpenAI product you use with Shannon:
The same organization can have different IDs for OpenAI API and ChatGPT. Approval for one does not automatically enable the other.
Validate model access before a pentest
Once enrolled, run
startwith--validate-modelusing the model and credentials you intend to use for the pentest. This checks model and credential readiness and, for theopenaiandanthropicproviders in Shannon, probes whether the model accepts a security workload. It then stops without running a full pentest.Model options while awaiting verification approval
While your verification application is awaiting approval, you can try one of these models by setting the
SHANNON_AI_MODELenvironment variable:SHANNON_AI_MODELxai:grok-4.7openrouter:deepseek/deepseek-v4.1-flashanthropic:claude-sonnet-4-6openai:gpt-5.4Pass the selected provider's API key through the
SHANNON_AI_API_KEYenvironment variable.Our AI provider guide covers configuring other providers, switching models, and additional options such as gateways and custom models.
All reactions