Skip to content
Book a demo
All posts
News

Kairo and Anthropic's Cyber Verification Program

What the programme checks, and what it means for the models doing the reasoning inside every Kairo simulation.

Published
Reading
4 min
By
Kairo

Kairo participates in Anthropic’s Cyber Verification Program. The programme exists because security testing tools and model misuse look similar from the outside: both send a model unusual input and ask it to reason about how a system breaks. Verification is how a legitimate security vendor is distinguished from an attacker with the same prompt.

What verification covers

  • Who we are, who our customers are, and the contractual basis for testing each one.
  • That every target is scoped and authorised in writing before a single request is sent.
  • That findings go to the organisation that owns the system, and nowhere else.
  • That model access is used for analysis and simulation against consented environments, not for opportunistic scanning of the open internet.

Why it matters to a buyer

Most security products that claim to use frontier models are using them under ordinary commercial terms, with nothing between the vendor and the model but a billing relationship. Verification adds a party who has actually examined how the capability is used. If you are handing a vendor the authority to attack your own systems, that examination is worth asking about, of us and of anyone else.

What Kairo uses the models for

Claude models do the behavioral reasoning: building a model of how humans and agents will actually use an application, proposing what an attacker would try against it, and reading the evidence that comes back from a simulation. The probing itself runs in a shadow environment, never against production, and every finding is reproduced before it reaches a pull request.

Keep reading

More from the team
that verifies every change.

All posts

See what your application allows before an attacker does.