# How to Get Claude Mythos Access: Project Glasswing, Vetting and Realistic Timelines | Alher Tech

> Claude Mythos is invitation-only via Project Glasswing. Who qualifies, how vetting works, what to expect, and the legitimate alternatives if Mythos is out of reach.

- Canonical page: https://alhertech.com/en/claude-mythos/access/
- Site: Alher Tech (custom software, AI agents and SEO engineering, https://alhertech.com/)
- Contact: https://alhertech.com/en/contact/

---

Claude Mythos is not a model you sign up for. It is invitation-only research preview gated behind Project Glasswing, Anthropic's $100M defensive-cybersecurity initiative. This page walks through who actually qualifies, how vetting works, what to expect on the application side, and the legitimate alternatives if Mythos is out of reach.

Updated: May 9, 2026

## Who Glasswing actually accepts

Glasswing's launch cohort had 12 founding partners: Amazon, Apple, Google, Microsoft and 8 unnamed critical-infrastructure operators. The expanded cohort sits at around 40 organisations: Tier-1 cloud providers, OS and browser vendors, financial market infrastructure operators, telecoms with national-scale networks, and the operators of the largest open-source projects (Linux kernel, Postgres, OpenSSL, BSD families). Anthropic also runs a 'Claude for Open Source' lane for critical maintainers without revenue.

## How to apply (and what gets you rejected)

Anthropic has not published a public application form. Inbound interest goes through an enterprise sales contact who routes the conversation to the Glasswing committee. Successful applications come with a concrete cybersecurity workload (large open-source codebase ownership, regulated infrastructure, government national-security mandate) and a security team with the maturity to handle the model output responsibly. Reasons reported for rejection: speculative use cases, insufficient security maturity, lack of disclosure plumbing, or wanting Mythos for general coding rather than security-specific work.

## Realistic timeline and effort

From first contact to onboarded keys, Glasswing partners report 6–14 weeks. The bottleneck is not technical; it is the vetting and contractual side: NDA negotiation, disclosure-policy alignment, security-team interviews, and Anthropic-side capacity. Expect to staff a part-time program manager and a senior security engineer through the process.

## What the contract actually allows

Inside Glasswing the contract grants you defensive use only: vulnerability discovery and patching against your own infrastructure or open-source projects under your stewardship. Findings are subject to a 135-day disclosure window. You cannot sell Mythos output as a service, you cannot run offensive engagements, and you cannot expose the model directly to end users. Violations terminate access and trigger Anthropic's Responsible Scaling Policy review.

## Alternatives when Glasswing is out of reach

For 99% of teams the right answer is Claude Opus 4.7 with a security-tuned system prompt: generally available, $5 / $25 per million tokens, and capable enough for routine vulnerability triage and patch generation on most stacks. Pair it with semgrep, CodeQL or a commercial SAST tool. For autonomous discovery on harder targets, OpenAI is reported to be preparing a comparable gated-release model ('Spud'); when it ships, treat it as a parallel option to Mythos rather than a replacement.

## Frequently asked questions

### Can I get Mythos via Bedrock or Vertex AI?

Glasswing partners can call Mythos through Anthropic API, AWS Bedrock, Google Cloud Vertex AI or Microsoft Foundry, but only with their pre-issued partner credentials. There is no public Mythos endpoint on any cloud.

### Is there an academic access program?

Anthropic runs an academic security-research lane that sits inside Glasswing. Eligible projects are usually attached to a recognised CSIRT or AISI-coordinated programme. Throughput is small: single-digit additions per quarter as of mid-2026.
