Security

Anthropic Launches Claude Security Tool for Enterprises — Vulnerability Scanning at AI Speed

Now in public beta, Anthropic's enterprise security tool uses Claude to identify and remediate vulnerabilities in client systems — the same capability being deployed through KPMG's Digital Gateway to critical infrastructure clients.

By Patrick T ·

Anthropic Launches Claude Security Tool for Enterprises — Vulnerability Scanning at AI Speed

Anthropic has launched a public beta of its enterprise security tool — a Claude-powered system designed to identify vulnerabilities in client codebases and infrastructure configurations, then generate remediation recommendations. The tool, first disclosed in the context of the KPMG alliance, is now available directly to enterprise customers through Anthropic's API. It represents the company's first explicit move into the cybersecurity market, a sector where AI-assisted tools are rapidly displacing traditional signature-based approaches.

The tool works by ingesting code repositories, infrastructure-as-code configurations, and network topology descriptions, then applying Claude's reasoning capabilities to identify patterns associated with known vulnerability classes. Unlike traditional static analysis tools, which match code against a database of known vulnerability signatures, Claude's approach is generative — it reasons about what could go wrong in a given system, rather than pattern-matching against what has gone wrong before. That distinction matters for zero-day vulnerabilities, where signature databases are by definition empty.

The KPMG Connection

The tool's commercial launch is directly connected to the KPMG alliance announced May 19. One of the initial deployment areas for KPMG's Digital Gateway integration is vulnerability scanning: KPMG and Anthropic teams will use Claude to identify and remediate vulnerabilities in critical client systems. The public beta makes the same capability available to organisations that are not KPMG clients — effectively democratising access to a tool that was previously available only through a Big Four consulting engagement.

A security operations centre — the environment where Claude's vulnerability scanning capabilities are being deployed by enterprise security teams.
A security operations centre — the environment where Claude's vulnerability scanning capabilities are being deployed by enterprise security teams.

Early beta users report that the tool is particularly effective at identifying vulnerabilities in infrastructure-as-code configurations — Terraform files, Kubernetes manifests, and cloud formation templates — where traditional static analysis tools have historically struggled. One beta user, a security engineer at a financial services firm, described finding 23 misconfigured IAM policies in a single scan that had passed three previous security reviews. The tool also generates remediation code, not just vulnerability reports, which significantly reduces the time from detection to fix.

Competitive Landscape

Anthropic enters a crowded market. Established players include Snyk, Veracode, Checkmarx, and GitHub's Advanced Security. AI-native competitors include Semgrep, Socket, and Orca Security. What distinguishes Claude's approach is the generative reasoning capability — the ability to identify novel vulnerability patterns rather than just known ones. That is a genuine differentiator for sophisticated enterprise security teams, but it comes with a corresponding risk: generative models can also produce false positives, and a security tool that cries wolf too often will be disabled by frustrated engineers.

Server rack infrastructure — the kind of physical and virtual systems that Claude's security tool is designed to analyse for vulnerabilities.
Server rack infrastructure — the kind of physical and virtual systems that Claude's security tool is designed to analyse for vulnerabilities.

Anthropic is pricing the tool on a consumption basis, with costs tied to the volume of code and configuration analysed. Enterprise pricing is negotiated directly. The public beta is free for the first 90 days, after which standard API pricing applies. For organisations already using Claude through the API, the security tool is an add-on capability rather than a separate product — which lowers the adoption barrier significantly for the large number of enterprise customers already in Anthropic's ecosystem.

Topics: Anthropic, Cybersecurity, Claude, Enterprise Security, Vulnerability Scanning