Root Managed Services has joined Anthropic’s Cyber Verification Program (CVP). We’re excited about the opportunity and grateful to Anthropic for making this access available to security professionals. We will use our participation to strengthen the security of our internal systems and the products we build and maintain for our clients.
For us, this work starts with a straightforward responsibility: the technology our clients rely on should receive the same careful scrutiny as the environments we help them manage. Joining CVP gives us another way to support that responsibility through focused, defensive security work.
What is Anthropic’s Cyber Verification Program?
Anthropic describes CVP as an application-based program for professionals conducting legitimate cybersecurity work with Claude. Approved organizations can receive adjustments to safeguards that otherwise interrupt certain high-risk, dual-use tasks. The program supports authorized defensive work while restrictions on prohibited activity remain in place. Read Anthropic’s explanation of its cyber safeguards and verification program.
Our focus is practical: use this access to examine systems we own or are authorized to assess, investigate potential weaknesses, and help our engineers make informed improvements.
Why this matters for enterprise clients and sensitive data
We serve many enterprise clients that depend on a secure environment to protect protected health information (PHI), personally identifiable information (PII), and other sensitive corporate data. These organizations need confidence in the systems that support their operations, including the tools and services provided by their technology partners.
That responsibility extends beyond a single application. Administrative access, internal workflows, integrations, and product changes can all affect how information is handled. Our planned work through CVP will help us look closely at those connections and identify opportunities to reduce risk before changes reach the people who rely on them.
For healthcare teams, professional services firms, and other data-sensitive businesses, the objective is consistent: limit unnecessary access, preserve confidentiality, and maintain dependable operations. Our investment in internal security supports that objective.
How we plan to use CVP access
We will bring this access into a structured engineering review process, with priorities based on the sensitivity of the system and the potential effect on clients. Our planned areas of focus include:
- Internal systems: review configurations, access boundaries, and administrative workflows for weaknesses that could expose information or allow unintended actions.
- Product security: examine code, dependencies, and integrations for potential vulnerabilities as we develop and maintain our products.
- Threat modeling: consider how a feature or workflow could be misused, then evaluate the controls intended to prevent that misuse.
- Remediation and verification: investigate findings, prioritize fixes, and retest changes before treating an issue as resolved.
Our engineers will remain responsible for evaluating findings and approving changes. AI-assisted analysis can help surface questions and possible weaknesses; useful security improvements still require technical judgment, testing, and clear ownership.
A careful approach to security review
We intend to keep reviews scoped to the systems and questions being assessed. That includes using sanitized examples and test data wherever possible, minimizing the information needed for analysis, and considering data-handling requirements before any review involving sensitive material.
We will use the results to guide concrete engineering work: documenting a finding, assigning an owner, applying a change, and checking the outcome. This approach connects additional analysis to the ongoing maintenance and improvement of our systems.
Investing in the security behind our services
We’re grateful to Anthropic for welcoming Root Managed Services into CVP. We look forward to using this opportunity to support the internal security work behind our client services and products.
Based in Frisco, Texas, Root Managed Services supports businesses across Dallas–Fort Worth and Austin. Explore our cybersecurity services and managed IT services, or contact our team to discuss your organization’s security priorities.
Read more Root news and security guidance, including our guide to responding to unexpected MFA approval prompts.