ChannelLife Australia - Industry insider news for technology resellers
Australia
Delinea joins Anthropic project to test identity security

Delinea joins Anthropic project to test identity security

Fri, 18th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Delinea has joined Anthropic's Project Glasswing and will use Claude Mythos 5.1 to examine its own identity security software.

The move places Delinea among organisations whose software is considered important to critical infrastructure, where identity security flaws can affect every system under their control.

The company is applying the AI model to internal code used for vaulting, secrets management and session brokering. The work focuses on software that stores, brokers and rotates privileged credentials, with the aim of identifying weaknesses before attackers do.

Its software already undergoes security review and adversarial testing. Project Glasswing adds an AI model to that process, directed at Delinea's own code rather than customer environments.

Areas under review include credential and secrets handling, including vaulting logic, secret storage and rotation, key management and cryptographic implementation. Delinea is also examining session brokering and privileged access paths, including connection, injection and proxy code that sits between a user or agent and a target system.

Another focus is authorisation enforcement, including policy evaluation and just-in-time authorisation paths, where a logic flaw can carry consequences similar to a memory-safety vulnerability.

Security process

Findings from the AI-assisted reviews will move through Delinea's existing software development and product security processes, including triage and remediation. Repeated issues will be turned into secure coding standards, pre-merge checks and additional test coverage.

Validated findings and remediation patterns will also be shared with other members of the Glasswing group. Issues affecting third-party or open-source components will follow coordinated vulnerability disclosure timelines.

Art Gilliland, Chief Executive Officer at Delinea, linked the decision to broader changes in software security caused by AI-assisted research.

"AI is making it much easier to find weaknesses in software, and that changes what customers should expect from security companies," said Art Gilliland, Chief Executive Officer at Delinea.

"We joined Project Glasswing to use the best tools available to attack our own assumptions and find problems before someone else does," Gilliland said.

Scoped access

Delinea is handling the AI model as it would any other privileged identity in a security programme. Access is limited, temporary and recorded, and the model runs in an isolated environment.

Customer data is not included in the testing scope. Any issue identified by the model will enter the same product security and disclosure process used for vulnerabilities reported by human researchers.

"We're treating Mythos like any other privileged identity: its access is scoped, temporary and logged," said Pierre Mouallem, Chief Information Security Officer at Delinea.

"It runs against our code in an isolated environment with no customer data in scope. Anything it finds enters the same product security and disclosure process as a human-reported vulnerability," Mouallem said.

Anthropic's Project Glasswing is aimed at securing critical software with frontier AI systems. Delinea's participation reflects a growing pattern in cybersecurity, with companies turning AI tools inward to test the resilience of their own code bases, especially in products that govern access to sensitive systems and credentials.

For Delinea, that means concentrating on software that determines what users, machines and AI agents can do after they have gained access. In practice, weaknesses in such systems can create a route into a much wider set of corporate and infrastructure assets.

Vulnerabilities affecting Delinea's own products will be disclosed through its security advisories process.