Anomity Joins Claude for Startups
- On Friday, August 21, 2026, Deskfirst, the company behind Anomity, was accepted into Claude for Startups, Anthropic's program for early-stage founders and startups building with Claude.
- The program is access and community, not capital. Anthropic's own description is explicit that it provides no investment or equity funding: what it provides is Claude credits with priority rate limits for eligible venture-backed startups, live sessions and events, founder resources, and early notice of launches and model releases.
- The last item is the one with a direct line to our roadmap. Anomity's product claim is a complete list of the AI artifacts running on a fleet, and that claim expires every time a vendor ships a new kind of artifact.
- Claude Code alone added Agent Teams, background subagents, auto mode, plugins and marketplaces, skills, 31 hook events, sandbox primitives, self-hosted runners and server-delivered managed settings across 2026. Each one is a thing to discover before it is a thing to govern.
- A pattern worth noting if you are an enterprise reader: like the Cyber Verification Program, the startup credits are first-party only and do not apply on Amazon Bedrock or Google Cloud Vertex AI.
- This changes nothing about how Anomity handles your data, and it is not an endorsement of our product by Anthropic. It is lead time, and we intend to spend it on coverage.
On Friday, August 21, 2026, Deskfirst, the company behind Anomity, was accepted into Claude for Startups.
We want to be straight about what that is, because the genre of post this belongs to is usually inflated past the point of usefulness. A founder program is not a security certification, not an audit, and not a statement by Anthropic about our product. It is access and community. But one part of it bears directly on what we build and how quickly we can build it, and that part is worth explaining rather than burying under a logo.
What the program actually includes
Per Anthropic's own description of the program, Claude for Startups is three things:
- Claude credits and priority rate limits for eligible venture-backed startups. The eligibility criteria are specific: equity funding from institutional investors, founded within the last four years, and no prior Anthropic startup credits.
- Community access: hackathons, Founder Days and meetups across six cities, plus livestreams, AMAs and on-demand sessions with the team that builds Claude.
- Early product access, in the form of priority notice about launches, model releases and program perks.
Anthropic is also explicit about what the program is not. It provides no investment and no equity funding. What eligible startups receive are API credits redeemable through the Claude Console, and the program itself is open to early-stage founders and startups whether or not they have venture backing. A separate VC Partner Program lets investment firms extend credit access to founders in their portfolios, which is likewise not funding from Anthropic.
One detail enterprise readers should take from this
There is a constraint on the credits that is easy to skim past and worth reading closely: Claude startup credits apply to the first-party Claude API via the Claude Console, and cannot be used on AWS Bedrock, Google Cloud Vertex AI, or other third-party platforms.
That should look familiar if you read our post on the Cyber Verification Program, because the same boundary appears there: verification for dual-use defensive work is available on Anthropic first-party access, the AWS Claude Platform and Microsoft Foundry, and is not currently available on Amazon Bedrock or Vertex AI either.
Two unrelated programs, the same boundary, and it is not a coincidence. Programs that attach benefits, credits, or exemptions to an identity need a route where the provider actually knows who is calling. Routing model access through a cloud marketplace is often the right architecture for an enterprise, because it keeps traffic inside an existing contract, network boundary and billing relationship. It is worth going in knowing that the provider-side programs attached to that model may not follow you there. That is not a reason to change your architecture. It is a reason to check before you plan around a benefit you cannot actually receive.
Why early access matters to a discovery product
Anomity's central claim is a list: every AI artifact running across your fleet. Agents, MCP servers, extensions, plugins, skills, secrets, hooks, CLIs, local model runtimes, the AI services people use in a browser tab, the accounts they sign in with, the AI applications holding OAuth grants against your Google Workspace and GitHub.
The uncomfortable property of that claim is that it has a shelf life. A discovery tool is complete only with respect to the artifact types it knows about. The moment a vendor ships a new kind of thing that can be installed into an agent, every inventory in the industry is quietly incomplete, and stays incomplete until somebody teaches it to look. Nothing breaks. No alert fires. The dashboard still says the fleet is covered.
We think of the interval as coverage lead time: the gap between a vendor shipping a new surface and a discovery tool being able to see it. Long lead time is worse than an outage, because an outage is visible. A discovery gap presents as a clean bill of health.
Claude is one of the fastest-moving sources of new surfaces in the category, and 2026 is the evidence. We walked the full list in new Claude Code features in 2026 and their security implications; the short version is that in a single year the product added peer-to-peer Agent Teams, subagents running in the background three levels deep, an auto mode that routes permission decisions through a classifier instead of a human, plugins and plugin marketplaces including archive-sourced installs, the skills layer, 31 hook events, a sandbox with credential masking and strict network allowlists, self-hosted runners, and server-delivered managed settings.
Every item on that list is a governable artifact or a configuration fact that decides what an agent may do. Several of them did not exist as a category the year before. And the pattern continued past the release notes into how the product is now configured at all: as we covered in context engineering for Claude 5, Anthropic moved the bulk of the instruction set out of a central system prompt and into a tree of files sitting on the endpoint, which turns configuration itself into a discovery problem rather than a document you can read once.
What we intend to do with it
The honest answer is narrow, which is the point. Earlier notice of launches and model releases means the work of recognizing a new artifact type starts closer to the release than to the moment a customer asks why it is not in their inventory. Sessions with the people who build Claude mean we ask better questions about where configuration actually lives and what is authoritative, which is exactly the sort of detail that separates a detection that works from one that works on a demo machine.
That is the whole of the benefit, and it does not extend anywhere near your data. Nothing about program membership changes how Anomity operates: metadata only, never source and never prompts, secrets redacted on the endpoint before anything leaves the machine, strict tenant isolation, and SOC 2 Type II attestation behind it. No customer data is involved in the program in any way, and there is no mechanism by which it could be. The same boundary applies to our own connector, now listed as the Anomity MCP server in the Claude directory: it reads your tenant when you ask it to, and never on its own.
Two programs, two different things
This is our second Anthropic program this year, and they are worth keeping distinct, because they do genuinely different jobs.
| Cyber Verification Program | Claude for Startups | |
|---|---|---|
| What it governs | What our research organization may ask Claude models to reason about | How early we see what Anthropic ships, and how directly we can ask about it |
| Who it is for | Vetted cybersecurity organizations doing high-risk dual-use defensive work | Early-stage founders and startups building with Claude |
| What it is not | Not a licence for prohibited use, which stays blocked for everyone | Not funding, not an endorsement, not a security review |
| First-party scoped? | Yes. Not available on Bedrock or Vertex AI | Yes. Credits do not apply on Bedrock or Vertex AI |
Neither is a substitute for the actual work, and we would rather say that here than have anyone infer otherwise from a badge in a footer. Programs are inputs. What a security team can use is coverage: whether the thing that shipped last month appears in the inventory this month, and whether policy can act on it at the point where it runs.
That remains the job. An unprivileged Endpoint Sensor inventories every AI artifact on Windows, macOS and Linux endpoints. A Browser Sensor covers the AI people use in a tab, including which accounts they sign in with and what they paste or type into them. Cloud discovery surfaces the AI applications holding OAuth grants against Google Workspace and GitHub. Policy is enforced at the agent hook before a tool call runs, and every decision lands in a queryable 90-day audit trail. The list only means anything if it is current, which is the entire reason a program like this is worth writing about at all.
Frequently asked questions
What is Claude for Startups?
Claude for Startups is Anthropic's program for early-stage founders and startups building with Claude. Per Anthropic's description, it offers Claude credits with priority rate limits for eligible venture-backed startups, community access through hackathons, Founder Days and meetups plus livestreams, AMAs and on-demand sessions, and early product access in the form of priority notice about launches and model releases. The program is open to early-stage founders and startups with or without venture backing, though the credits themselves carry additional eligibility criteria.
When did Anomity join Claude for Startups?
Anomity was accepted on Friday, August 21, 2026. The membership is held by Deskfirst, the company behind Anomity.
Does Claude for Startups include funding or investment?
No. Anthropic states that the program does not provide investment or equity funding. What eligible startups can receive are Claude API credits usable through the Claude Console, alongside community access and early product notice. A separate VC Partner Program lets investment firms extend credit access to their portfolio founders, which is also not direct funding from Anthropic.
Do Claude startup credits work on Amazon Bedrock or Google Cloud Vertex AI?
No. Per Anthropic, Claude startup credits apply to the first-party Claude API via the Claude Console and cannot be used on AWS Bedrock, Google Cloud Vertex AI, or other third-party platforms. This mirrors the Cyber Verification Program, which is also unavailable on Bedrock and Vertex AI, and it is worth knowing if your organization routes Claude access through a cloud marketplace.
Is Claude for Startups an endorsement of Anomity's product by Anthropic?
No, and we would not present it as one. Acceptance into a founder program is access to sessions, events, resources and early product notice. It is not a security review, a certification, a technical audit, or a statement by Anthropic about what Anomity does. Anomity's security-relevant relationship with Anthropic is the Cyber Verification Program, which is a separate application-based program for dual-use defensive work, and it is also not a product endorsement.
Why does an AI security company care about early access to Claude releases?
Because discovery coverage is perishable. Anomity's product claim is a complete inventory of the AI artifacts running across a fleet, and that inventory is silently incomplete for as long as a newly shipped artifact type is one we do not yet recognize. The interval between a vendor shipping a new surface and a discovery tool being able to see it is coverage lead time, and it is dead space during which security teams believe they have a complete picture and do not. Early notice of launches and model releases shortens that interval.
Does this change how Anomity handles customer data?
No. Program membership has no bearing on the product's data handling, which is unchanged: Anomity is SOC 2 Type II attested, collects metadata only rather than source code or prompts, redacts secret values on the endpoint before anything leaves the machine, and enforces strict tenant isolation. No customer data is involved in the program in any way.




