Claude Security is now in public beta (4 minute read)
Anthropic launches Claude Security in public beta, allowing enterprises to scan codebases for vulnerabilities using the Opus 4.7 model with automated patch generation.
What: Claude Security is a vulnerability scanning tool powered by Opus 4.7 that analyzes code to find security flaws and generates fixes, available directly through Claude.ai or via integrations with major security platforms like Microsoft Security, CrowdStrike, and Palo Alto Networks.
Why it matters: This matters because AI is accelerating both vulnerability discovery and exploitation—giving defenders access to frontier AI models for automated security scanning could help organizations stay ahead of AI-powered attacks.
Takeaway: Enterprise customers can start scanning code immediately through claude.ai/security without custom integration, with results exportable to existing security workflows via CSV, Markdown, or webhooks.
Deep dive
- Claude Security uses Opus 4.7 to analyze code like a security researcher, understanding component interactions and data flows rather than just pattern matching
- The tool includes multi-stage validation to reduce false positives and assigns confidence ratings to each finding
- Hundreds of organizations tested it in preview, with feedback leading to features like scheduled scans, targeted directory scanning, and dismissing findings with documented reasons
- Results can be exported to CSV/Markdown or pushed to tools like Slack and Jira via webhooks
- Users reported going from scan to patch in a single session instead of days of back-and-forth between security and engineering teams
- Integration partners include major security platforms (CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, TrendAI, Wiz) and consulting firms (Accenture, BCG, Deloitte, Infosys, PwC)
- The tool is part of a broader effort alongside Project Glasswing, which uses Claude Mythos Preview for elite-level vulnerability discovery and exploitation
- Anthropic positions this as defensive preparation for a future where AI makes working exploits much easier to discover
- Opus 4.7 includes cyber safeguards that block high-risk security uses, with a Cyber Verification Program for legitimate security work
- Currently available to Enterprise customers, with Team and Max customer access coming soon
Decoder
- Opus 4.7: Anthropic's most powerful generally-available language model, specialized for finding and patching software vulnerabilities
- Project Glasswing: Anthropic's partnership program providing Claude Mythos Preview to select partners for elite-level vulnerability research
- Claude Mythos Preview: A specialized model that matches expert-level performance at finding and exploiting vulnerabilities, more advanced than Opus 4.7
- False positives: Security alerts that incorrectly flag safe code as vulnerable, wasting analyst time
Original article
Claude Security, now in public beta for Claude Enterprise customers, leverages the powerful Opus 4.7 model to identify and patch software vulnerabilities. The model, integrated into tools used by partners like Microsoft Security and Palo Alto Networks, enhances cybersecurity defenses by enabling efficient, ongoing code scanning without requiring custom API integration. Feedback from hundreds of organizations has refined its capabilities.