Application security teams
Investigate authentication, injection, memory-safety, and business-logic risks that depend on relationships across multiple files.
Independent tool overview
Claude Security is Anthropic's AI vulnerability-scanning product for reasoning across a codebase, validating high-severity findings, and proposing patches for human review. The hosted Mythos 5 scanner is in public beta for Claude Enterprise, while a separate local Claude Code plugin is in beta for users on paid Claude Code plans.
Visit the official Claude Security site ↗
Overview
Claude Security looks for context-dependent vulnerabilities by mapping how components interact, tracing data flows, reading Git history and business logic, and independently challenging potential findings before surfacing them. Results include severity, confidence, impact, reproduction guidance, and a proposed remediation path.
There are two distinct products. The managed Claude.ai application connects to GitHub repositories, supports scheduled and parallel scans, uses Claude Mythos 5, and can send findings to audit and ticketing workflows. The Claude Code plugin runs inside a local session with the models available to that account and can scan GitHub, GitLab, Bitbucket, an unversioned folder, or a specific diff.
Neither path replaces deterministic static analysis, dependency scanning, secret scanning, penetration testing, or accountable engineering review. Anthropic explicitly says proposed patches can be wrong and require human approval.
Use cases
The strongest fit depends on the job you need the product to complete, not the size of its feature list.
Investigate authentication, injection, memory-safety, and business-logic risks that depend on relationships across multiple files.
Turn validated findings into focused patches and pull requests without losing repository context.
Schedule hosted scans and route results into existing triage, audit, Slack, Jira, or webhook processes.
Use the Claude Code plugin when code is hosted outside GitHub or must remain inside the developer's environment.
Capabilities
Reasons about architecture, data flows, Git history, and business logic rather than relying only on known code patterns.
Independent verifier passes challenge each candidate vulnerability before it appears in the final report.
Each managed finding includes vulnerability detail, affected location, severity, confidence, likely impact, and reproduction information.
Creates targeted remediation guidance or patch files for a developer to inspect, test, and apply manually.
Managed scans can focus on a directory or branch and run on a recurring schedule for ongoing coverage.
Export CSV or Markdown, retain documented dismissals, and send findings to Slack, Jira, or other systems through webhooks.
The Claude Code plugin can scan a full repository, branch diff, pull-request diff, or commit and produce Markdown, JSONL, and SARIF reports.
Process
Step 1
Use the Enterprise application for hosted Mythos 5 monitoring, or the paid Claude Code plugin for an on-demand scan in the local environment.
Step 2
Select a repository, branch, diff, directory, or high-risk module; smaller scopes improve determinism and make review more actionable.
Step 3
Review exploitability, severity, confidence, affected paths, coverage, and evidence before accepting or dismissing a result.
Step 4
Generate a remediation for one accepted finding, run the project's tests and security checks, and review the diff in its own pull request.
Step 5
Record disposition and ownership in the system of record, schedule follow-up scans, and retain exports or revision stamps for audit history.
Cost
The managed Claude Security application requires Claude Enterprise, a Premium seat, Claude Code on the Web, and Extra Usage consumption billing. Enterprise is listed at $20 per seat plus usage at API rates; scan costs scale with repository size and scan count, and Anthropic does not publish a flat per-scan price. The local plugin requires a paid Claude Code plan and counts against that plan's usage limits.
Enterprise: $20/seat + usage
Hosted scanning with Mythos 5 for eligible Enterprise users.
Included with paid Claude Code access
Local, on-demand multi-agent scans using the models available in the user's Claude Code account.
Contact sales
For organizations requiring negotiated deployment, usage, support, and commercial terms.
Pricing checked . Check current pricing at the source ↗
Assessment
Compare
The right alternative depends on the specific output, workflow, controls and budget your project requires.
Agents
OpenAI's repository security agent for teams evaluating another frontier-model approach to finding and patching vulnerabilities.
Explore Codex Security →Coding
A code-security platform focused on contextual review integrated with developer workflows.
Explore DryRun Security →Coding
Anthropic's pull-request review product for broader correctness and security checks at merge time rather than deep scheduled vulnerability scans.
Explore Claude Code Review →Questions
It is Anthropic's AI application-security scanner for finding context-dependent vulnerabilities, validating findings, and proposing patches that developers review and apply.
The hosted Mythos 5 application is in public beta for eligible Claude Enterprise users with Premium seats. The separate local Claude Code plugin is in beta for users with paid Claude Code access.
The managed product requires Enterprise, listed at $20 per seat plus usage at API rates, along with a Premium seat and Extra Usage enabled. Anthropic does not publish a flat per-scan price; cost scales with scan size and frequency.
No. It proposes patches, but patches are never applied automatically. A developer must review, test, and explicitly apply each change.
The hosted product currently supports GitHub.com and GitHub Enterprise Server. The local Claude Code plugin can scan repositories from GitLab, Bitbucket, or other local sources because it runs inside the user's environment.
No. Anthropic positions it as a deep reasoning layer alongside deterministic static analysis, dependency scanning, secret scanning, code review, and other defense-in-depth controls.
Bottom line
Claude Security is promising for deep, context-aware review of complex application vulnerabilities, especially where conventional scanners struggle with business logic. The managed product is still an Enterprise beta with variable usage cost, so teams should pilot it on a scoped repository, measure validated findings and time-to-fix, and keep established security controls in place.
Visit Claude Security website ↗
Qwen3.6-27B - Alibaba's open-source 27B model that beats its 397B predecessor on coding benchmarks

Composer 2.5 - Cursor's upgraded in-house coding model for longer agent sessions and more reliable behavior

Windsurf 2.0 - Windsurf's updated agentic IDE with a new command center and embedded Devin cloud agent

Antigravity 2.0 - Google's standalone desktop app for orchestrating parallel agents

Get access to all our AI courses, hundreds of real-world AI use cases, live expert-led workshops, an exclusive network of AI early adopters, and more.
Get unlimited access to all of our current & upcoming industry-specific AI courses for the duration of your subscription.
To keep up with the rapid pace of AI, our team publishes AI implementation guides daily. Our library contains 300+ practical use cases to automate real-world work.
Join weekly, live, interactive sessions with industry leaders who are at the forefront of AI for hands-on implementation guidance and exclusive insights.
Network with an exclusive community of AI-first professionals who are working smarter with AI. Learn how early adopters are using AI in their work and businesses.