Cloudflare Automates Bug Bounty Triage With Sonnet
Cloudflare now uses Claude Sonnet to screen incoming bug-bounty reports for duplicates and likely validity, according to The Register's Aug. 4 reporting from a press briefing. Cloudflare CSO Grant Bourzikas said the workflow costs $58 per month, versus roughly $200,000 per month for Mythos on the same task, while warning that Cloudflare's broader build-itself approach is specific to its operating context.
Cloudflare is using Anthropic's Claude Sonnet to screen incoming bug-bounty reports, according to The Register's Aug. 4 reporting from a press briefing in Sydney. Chief security officer Grant Bourzikas said the workflow costs $58 per month.
The model checks submissions for duplicates and estimates whether a report is likely to warrant human attention. Bourzikas contrasted that expense with roughly $200,000 per month to use Anthropic's security-focused Mythos model for the same task. The figures are Cloudflare's operational estimates, not a controlled benchmark of model quality or equivalent security coverage.
A narrow model-to-task decision
The comparison illustrates model routing more than a simple cheaper-is-better result. Sonnet is handling a bounded intake task: organizing reports, filtering duplicates, and identifying likely signal. Mythos was developed for deeper vulnerability discovery and exploit analysis, a materially different capability even when applied to the same queue.
Cloudflare's own May account of its Mythos work emphasizes that candidate vulnerabilities still require triage, validation, and remediation. Anthropic's disclosure dashboard likewise describes independent human review as a rate-limiting step. Those sources support keeping a person in the decision path for severity, disclosure, and remediation even when initial screening is automated.
Cloudflare's broader security stack
Bourzikas told The Register that Cloudflare has built more than 200 autonomous agents for internal security work and replaced almost all third-party security tools with home-grown applications, some developed with AI assistance. He also warned other organizations not to copy that strategy reflexively, because Cloudflare's business and security requirements change its build-versus-buy calculation.
For security teams, the useful lesson is the separation of workloads: low-cost automation can reduce repetitive triage work, while higher-assurance decisions still depend on validation, context, and accountable human review. The reported prices do not establish how the two models compare on false negatives, severity judgments, or overall risk reduction.
Key Points
- 1Cloudflare says Claude Sonnet screens bug-bounty reports for duplicates and likely validity at a reported cost of $58 per month.
- 2The roughly $200,000 monthly Mythos comparison reflects Cloudflare's estimate for the same task, not a controlled benchmark of security quality or coverage.
- 3Cloudflare's own security research and Anthropic's disclosure process both retain human validation for vulnerability decisions and remediation.
Scoring Rationale
The report provides a concrete cost and workflow example for AI-assisted vulnerability intake, while retrieved first-party background makes the human-validation boundary clear. The operational figures are informative but do not provide reproducible accuracy or risk-reduction metrics.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
