Anthropic Puts Mythos 5 Behind Enterprise Code Scans
Claude Security now gives Enterprise customers access to Mythos 5 vulnerability analysis without exposing the restricted model directly.
Restricted capability through a controlled product
Anthropic has moved Claude Security’s repository scans to Claude Mythos 5 and opened the updated service as a public beta for Claude Enterprise customers. Users can point the product at a GitHub repository; the system follows data and control flow across files, reports suspected vulnerabilities with supporting evidence, and prepares proposed fixes that can be opened in Claude Code on the web.
The release does not give Enterprise customers unrestricted access to Mythos 5. Anthropic is instead placing the model behind a narrowly defined security workflow, where inputs, outputs and permitted actions can be controlled. Customers may continue using their existing generally available Claude models when reviewing or implementing the suggested patches.
Mythos 5 was introduced earlier as Anthropic’s most capable cybersecurity and biology model. It shares its underlying model with Claude Fable 5 but has fewer restrictions for approved work in sensitive domains. Direct access has consequently been limited to vetted organizations and trusted-access programs. Claude Security creates a broader delivery route for its defensive capabilities without making the underlying model generally callable.
Anthropic said the integration is one of several steps intended to expand access for defenders and that it is working with security partners on additional product integrations. Findings still require human validation: automated scanners can misjudge exploitability, overlook deployment context or recommend a patch that creates a different failure.
Why it matters
This is a notable model-access pattern for increasingly capable systems. Rather than choosing only between a fully public API and a small trusted-user roster, a laboratory can expose sensitive capability through a constrained application with logging, fixed tools and limited outputs.
If the approach works, it could become a template for distributing models with strong cyber, biological or other dual-use abilities. It may also shift enterprise security competition away from generic coding assistants toward systems that can reason across whole repositories. The central test will be whether Mythos materially improves the discovery of consequential, previously unknown flaws without producing an unmanageable volume of false positives.