[Bug] Cyber Verification Program status unexpectedly changed to "In review" during authorized security research session
Hi Anthropic Support team,
I'm a bug bounty hunter / security researcher. I was previously approved under the Cyber Verification Program for security research use cases (pentesting, red teaming, bug bounty).
During a Claude Code session today, my Cyber Verification Program status changed from Approved to "In review" after a message was flagged mid-task by the real-time cyber safeguards system.
Context of the flagged task:
I was working through PortSwigger's Web Security Academy labs — officially licensed educational content in an authorized, isolated lab environment. Specifically, a server-side prototype pollution lab whose documented intended solution path involves triggering RCE and reading a secret file within the sandboxed lab container. This is the official PortSwigger solution, not an attack against any third-party or production system.
Requests:
Please confirm whether my previous approval remains valid, or whether this flag triggers a new review requirement.
If a new review is required, let me know what additional information I can provide to expedite it (e.g., program enrollment details, lab URLs, session logs).
If possible, please advise whether flagged-but-authorized educational lab work can be whitelisted to avoid interrupting future sessions.
Thanks for your help.
Environment Info
Platform: darwin
Terminal: iTerm.app
Version: 2.1.228
Feedback ID: dabd0561-cd3c-484b-a541-e710021709caHi Anthropic Support team,