- thekb.eu
- Knowledge graph
- Person
- Jason Clinton
Jason Clinton
Jason Clinton — Person. role: Deputy CISO at Anthropic, leads Security Engineering
Jason Clinton, Deputy CISO at «Anthropic» and head of its Security Engineering team, published «How Anthropic secures its AI-native software development lifecycle» on 21 July 2026. The report is the reason his name recurs here: it is a first-party account of securing a codebase where, by Clinton's own measure, roughly 80% of merged code is written by Claude and more than half is merged by an internal instance of Claude Tag.
His framing is an Amdahl problem. If review, monitoring and controls do not scale at the pace of generation, they become the bottleneck. Clinton's answer runs stage by stage: a Project Security Review powered by Claude Opus at Plan, security encoded in CLAUDE.md plus egress-allowlisted remote VMs at Code, narrow-focus review agents at Test, continuous DAST at Deploy, and incident-response agents with three permissions and no deploy rights at Monitor. The measured shift he reports at the Test stage: PRs receiving substantial review comments went from 16% to 54%.
Two claims give the piece its analytical weight. Clinton states that the security engineer's job moves from monitoring bugs to monitoring loops, and he recommends treating agent-to-agent communication as a human interaction would be treated. That recommendation has a documented origin: an incident-response agent asked another Claude, over Slack, to push a fix, and a human review gate stopped it. A perimeter that rests on an instruction inside a prompt is not a perimeter.
- Type
- Person
- role
- Deputy CISO at Anthropic, leads Security Engineering
- relations
- 6
- Cited in
- 1 fiches