[BUG] CVP stuck "In review" 10+ days on active Max org (backend shows it as Free); Console org auto-denies instantly by plan status, not application — previously approved, support unresponsive
Preflight Checklist
- [x] I have searched existing issues and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code
What's Wrong?
I have a Claude.ai organization with an active Max subscription that was previously approved for the Cyber Verification Program (CVP). After the recent org/portal changes, CVP access stopped working and the application reverted to "In review," where it has now been stuck for 10+ days — well past the documented 2-business-day SLA. During this time Claude Code returns cyber-safeguard blocks on legitimate, authorized bug bounty / security research work.
This matches the pattern already reported in #84352 and #84689 (previously-approved CVP org reverts to "In review" and cyber blocks return; non-functional appeal path).
What Should Happen?
My org's plan status should be read correctly as Max (active), not Free, so the CVP review can proceed. The stuck CVP application on my active Max org should be reviewed. A previously-approved org with an active paid plan should not have its CVP application stuck indefinitely due to a backend plan-status mismatch.
Error Messages/Logs
Cyber-safeguard API error in Claude Code directing me to apply for CVP, despite prior CVP approval on this org.
Steps to Reproduce
- Org previously approved for CVP; after recent org/portal changes, CVP access stops working and application reverts to "In review."
- Backend/support lookup reports the org as "Free" while billing shows active Max on the same org.
- CVP application on the Max org stays "In review" indefinitely (10+ days, past the 2-business-day SLA).
- Claude Code returns cyber-safeguard blocks on authorized in-scope security work.
Note: On a separate Free (Console) org, CVP applications auto-deny within seconds regardless of KYC/proofs — decisions appear driven by plan status, not application content.
Claude Model
Opus
Is this a regression?
Yes, this worked in a previous version
Last Working Version
_No response_
Claude Code Version
2.1.219
Platform
Other
Operating System
Other Linux
Terminal/Shell
Other
Additional Information
Environment note: I run Claude Code in a Linux terminal (Kali Linux), logged in via "account with subscription" (Claude Max), not an API key.
Support ticket escalated to a human agent (Conversation ID: 215475445881209) — 10+ days, zero human response. The Fin support bot confirmed the Free/Max data mismatch but can't expedite.
Related issues with the same pattern: #84352, #84689 (CVP approved/stuck + blocks), #67305 (CVP-enrolled org still gets Opus 5 → 4.8 fallback on permitted defensive work).
On the Max org's CVP page, KYC and KYB show "Temporarily covered until February 4, 2027"; I completed the individual account-type step. Identity is not the blocker.
Org ID, account email, and billing screenshot available privately to maintainers on request — not posting them in a public issue.