Build1 distinct publisher3 min readUpdated
The hosted Claude Security beta bills as ordinary Claude usage with no platform fee, while Mythos 5 stays with vetted partners. What runs the Enterprise scans is not settled by the sources.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Anthropic's description of the scanner is about scope rather than cleverness: it traces data flows, reasons about how components interact, and looks for vulnerabilities whose exploitability depends on the surrounding application rather than an isolated line of code [10]. Candidates pass through multiple stages of self-verification before they appear in the product [11], and each surviving finding arrives with location, impact, reproduction steps, severity, category and a recommended remediation [12]. Then it stops being the tool's problem. The output is a recommendation for human review, and the proposed fix opens in Claude Code against a model the customer already has in their account, according to Anthropic's product documentation [13].
That handoff is where the headline number should be divided. Anthropic says Mythos Preview and roughly 50 early partners identified more than 10,000 high- or critical-severity vulnerabilities [17]. That is upwards of 200 per partner [19], and RuntimeWire's caveat is the part that carries weight: this is model-reported findings at scale, not 10,000 independently confirmed and patched bugs [18]. Two hundred candidate criticals per organisation is a triage queue, and the queue is staffed by the buyer.
The naming deserves a slow read before procurement. The hosted Enterprise service and the Claude Security plugin share a name but not a deployment model, with Enterprise scans running through Anthropic's platform while the plugin runs locally on the Claude access the customer already pays for [9]. Separately, an official Claude account post describes Mythos as the model scanning repositories, and its publication date is not established in the supplied capture [4]. The sources do not settle whether the hosted service later switched models, or whether that post describes a different deployment entirely [5].
Chronology does not rescue the reader either. The Enterprise public beta opened in late April 2026 [1], roughly six weeks before Anthropic announced Mythos 5 on June 9 as an upgrade to Mythos Preview for approved Project Glasswing partners [6][21]. A post that says "Mythos" therefore does not tell you which Mythos, or which product surface it was scanning from. The one thing the material does establish is the direction of gating: Anthropic calls Mythos 5 its most capable model for cybersecurity and biology research and restricts it to a small group of vetted partners on the grounds that the same capabilities could be used to build cyberattacks or dangerous weapons [7].
The pricing sits in a different world too. Mythos trusted-access rates start at $10 per million input tokens and $50 per million output tokens [8], a five-to-one output premium [20] that reads like a model whose expensive work is writing, not reading. Enterprise scans, by contrast, bill as direct token costs with no separate Claude Security platform fee [14]. RuntimeWire's reading is that discovery generates model usage while remediation sends the engineer into Claude Code, leaving Anthropic in possession of both ends of the workflow [15]. The honest procurement assumption is the dull one: you are buying a hosted workflow that runs some Claude model, metered as consumption, with the verification labour on your side of the line.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Anthropic says the scanner connects to GitHub repositories, traces data flows, reasons about interactions among components, and looks for vulnerabilities whose exploitability depends on the surrounding application rather than an isolated line of code.
Anthropic says each candidate finding passes through multiple stages of self-verification before appearing in the product.
Anthropic says Mythos Preview and roughly 50 early partners identified more than 10,000 high- or critical-severity vulnerabilities.
RuntimeWire notes the 10,000 figure describes model-reported findings at scale and does not equal 10,000 independently confirmed and patched vulnerabilities.
Anthropic put Claude Security, its hosted vulnerability scanner for GitHub repositories, into public beta for Claude Enterprise customers in late April 2026.
Anthropic first released the product as Claude Code Security in a limited research preview on February 20.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor-sourced product detail, one publisher
All substantive claims derive from Anthropic's own announcements, product page and documentation as relayed by a single outlet. The product mechanics and pricing are specific and internally consistent, and the source includes one quantified validation check (198 severity reviews, 89% exact / 98% within one level), but there is no independent testing, no third-party customer account, and the central question of which model runs Enterprise scans is explicitly unresolved.
Gated beta with vendor-reported partner usage
There is a real release trajectory - February research preview, late-April 2026 public beta - but availability is limited to Claude Enterprise customers, and Mythos 5 is confined to approved Project Glasswing partners. The only usage figure is Anthropic's own: roughly 50 early partners and more than 10,000 high- or critical-severity findings. No beta customer counts, scan volumes or named deployments are disclosed.
Vendor framing runs ahead of verification
The 10,000-plus high/critical figure, the 'most capable model for cybersecurity' description and repository-wide reasoning claims all rest on the vendor's own account, with only 198 reports manually severity-checked and other findings still in validation. The publisher itself flags the gap and notes scans are stochastic, which keeps the overstatement modest rather than severe; the unsettled model identity pushes the gap positive.
Strong vendor consumption incentive, disclosed
Anthropic's design directly monetizes the product it is announcing: scans bill as ordinary Claude token usage with no platform fee, and remediation routes engineers into Claude Code, so both discovery and patching drive model consumption. Trusted-access Mythos pricing at a five-to-one output-to-input ratio compounds the usage incentive. The publisher discloses this reading explicitly and also leans on its own prior Claude coverage, which is a self-referential but transparent framing.
Low-moderate: single outlet, open model question
Dates, pricing and product mechanics are stated precisely and are unlikely to be wrong as reported, but there is no corroborating publisher, no independent verification of scan quality, and the cluster's own headline uncertainty - which model runs Enterprise scans - is unresolved. Confidence is adequate for the existence and shape of the product, weak for its effectiveness.
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
invest
65,000 pulls a day, one author: the AI coding stack's unpriced dependency1 distinct publisher
invest
Three Claude agents, one task, and a malware turf war: the multi-agent bill arrives1 distinct publisher
leadership
Anthropic's own telemetry: 93% of permission prompts approved. Budget for blast radius, not reviewers1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026