[BUG] CVP-approved personal account still hit by cyber-safeguard false positives in Claude Code (Sonnet 5)

Status Open
Reported on v2.1.226
Maintainer reply None cached
Activity 3 comments · opened Aug 9, 2026

Preflight Checklist

  • [x] I have searched existing issues and this hasn't been reported yet
  • [x] This is a single bug report (please file separate reports for different bugs)
  • [x] I am using the latest version of Claude Code

What's Wrong?

I was approved for the Cyber Verification Program (CVP) on my personal Claude account, but Claude Code (Sonnet 5) continues to throw the cyber-safeguard block on legitimate personal security research/learning work (OSCP prep, HTB labs). This is the same underlying propagation gap reported in #49679 and #69220, but confirms the issue is not limited to team/enterprise org accounts — it also affects individual CVP approvals tied to a personal workspace.

Notably, the block message itself instructs the user to "Apply to the Cyber Verification Program" — as if no approval is on file — despite approval having already been granted and confirmed active on this account. This suggests either: (a) the approval isn't propagating to Claude Code's enforcement path at all for personal/individual accounts, or (b) it has propagated but the block message copy hasn't been updated to reflect approved status, which is confusing but a separate (smaller) issue worth fixing regardless.

Troubleshooting already performed, per the Claude Help Center guidance ("Real-time cyber safeguards on Claude Opus and Sonnet"):

  • Confirmed Claude Code is authenticated against the same personal account the CVP approval was granted to (not a different workspace/org) — verified via /status: Login method Claude Pro account, Organization "stuartmacdonald.uk@gmail.com's Organization", Email stuartmacdonald.uk@gmail.com.
  • Logged out and back in (/logout then /login) to rule out a stale cached session token.
  • Started fresh sessions rather than continuing flagged ones.
  • None of the above resolved the block.

There is also no thumbs-down / inline feedback option surfaced on the blocked message itself in this Claude Code version — /feedback is the only route available.

What Should Happen?

CVP approval, once granted and confirmed active on the account, should apply consistently within Claude Code (API-based), matching the behaviour already reported as working correctly on claude.ai web/desktop chat. The block message should also not tell an already-approved user to apply for CVP.

Error Messages/Logs

API Error: Sonnet 5's safeguards flagged this message. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate cybersecurity work. Apply to the Cyber Verification Program to reduce these interruptions. Send feedback with /feedback or learn more: https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude
Request ID: req_011Cds2Adh75bDAHXb4BVTaC

Steps to Reproduce

  1. Start a Claude Code session on a CVP-approved personal account.
  2. Discuss or work on legitimate offensive-security-adjacent tasks (e.g. HTB/OSCP exploit dev, exam-lab methodology).
  3. Observe the block, including on subsequent messages in the same or a new session.

Claude Model

Sonnet (default)

Is this a regression?

I don't know

Last Working Version

_No response_

Claude Code Version

2.1.226

Platform

Anthropic API

Operating System

Other Linux

Terminal/Shell

Other

Additional Information

Session ID: 14851c3a-c37b-46f4-b172-a3f0aa4942ae
Related issues: #49679, #69220, #61889 — all describe CVP approval not propagating to Claude Code's enforcement path. This report adds confirmation that the gap affects personal (non-org) CVP approvals specifically, with full account/org/login-method verification via /status ruling out a credential mismatch.

View original on GitHub ↗

3 Comments

0xROOTPLS · 19 days ago

Bumping as this is still ongoing for several months for many CVP approved users.

GamingNJncos · 6 days ago

How is this still a problem? Deny and ask for CVP, complete the CVP and get approved - SAME EXACT DENIAL and all you get is "submit a false positive and give us the entire session log".

0xROOTPLS · 3 days ago

Bumping because I finally got an update from Anthropic.

It should be mentioned I was approved for CVP in April, and covered use case expanded in May of 2026.

As with all other reports, my account was silently demoted in it's CVP status. It sat in review for ~1wk after re-requesting.
No KYC check, No Forms, it just went to "in review" after pressing apply.

Today I receive an Anthropic Safeguards email:

Hello,

Following a review of your recent account activity, we have adjusted the safeguards on your account back to the default cyber safeguards configuration.

    Anthropic Organization ID: *************************

Additionally, if you have a pending Cyber Verification Program application, that application has been denied.

I believe this is not actually regarding my account activity, and instead, a generic denial of the weird CVP reapplication. I will re-submit with the forms all filled out about my Company & use case. Will update upon results from that!