Anthropic runs Claude Security scanner on Claude Mythos 5

Anthropic is now running its security scanner, Claude Security, on Claude Mythos 5, the company's most capable model. The tool scans codebases for vulnerabilities and suggests patches, and it is available in public beta for Enterprise customers. Scans count as normal token usage, so there is no separate pricing for the feature. Each finding the scanner produces includes a CWE category (the standard classification scheme for software flaws), a severity rating, and a suggested fix, but a human still has to sign off on every patch before it ships.
Anthropic is also plugging Mythos 5 into partner security products that protect hospitals, utilities, and banks. In that setup, end users of those partner products never interact with the model directly; they only see outputs such as suggested patches. Several partners already run their security tools on Claude Opus and are expected to switch to Mythos 5. Security vendors that want in can sign up for partnership access.
According to the source, Claude Mythos is Anthropic's most capable model overall and particularly strong at cyber-related tasks, which is why it is not broadly available to the public. The company frames this rollout as a way to strengthen defenders' tools without handing attackers new AI-powered capabilities of their own.
Key facts
- Anthropic now runs its Claude Security scanner on Claude Mythos 5, its most capable model.
- The tool scans codebases for vulnerabilities, flags each with a CWE category and severity rating, and suggests a fix, but a human must approve every patch.
- It is in public beta for Enterprise customers, and scans are billed as normal token usage.
- Mythos 5 is also being integrated into partner security products used by hospitals, utilities, and banks, with end users never touching the model directly.
- Partners currently on Claude Opus are expected to move to Mythos 5, and security vendors can sign up for partnership access.
Why it matters
Anthropic is putting its strongest model to work specifically on defense rather than general use, and doing so through two channels at once: a direct scanning tool for enterprises and an embedded engine inside partner security products. That dual rollout signals the company sees code-vulnerability scanning and patch suggestion as one of the clearest near-term commercial uses for its most capable model, and one it is comfortable offering through controlled channels precisely because it is defensive rather than offensive.
Who it affects
Enterprise customers get direct access to Claude Security running on Mythos 5 for scanning their own codebases. Security vendors serving hospitals, utilities, and banks get a path to embed Mythos 5 in their existing products, with the end users of those products (hospital IT staff, utility operators, bank security teams) seeing only the results (findings and suggested patches) rather than the model itself. Partners already using Claude Opus for their security tools are the most immediate group expected to migrate to Mythos 5.
How to use it
Enterprise customers can access Claude Security on Mythos 5 now, in public beta; scans are billed as ordinary token usage rather than a separate fee. Security vendors that want to embed Mythos 5 in their own products can sign up for partnership access rather than integrating it themselves from scratch. Every patch the tool suggests still requires human sign-off before it is applied, so the workflow is scan and suggest, not scan and auto-fix.
How solid is it
The source is a single article and does not cite specific figures: no count of vulnerabilities found, no number of partners or customers, no date for when the beta started, and no timeline for when Opus-based partners will finish switching to Mythos 5. The claims about the tool's mechanics (CWE categories, severity ratings, suggested fixes, human sign-off, token-based billing) are stated directly and specifically, but the broader rollout is described qualitatively rather than with metrics.
Risks and caveats
Because Mythos 5 is described as especially capable at cyber tasks, Anthropic is keeping it out of broad public release and channeling access through vetted enterprise and partner relationships rather than opening it up directly. The stated goal is to give defenders better tools without handing the same capability to attackers, but the source gives no detail on how access is vetted or what prevents misuse once a partner integrates the model into its own product.