A few weeks ago I wrote about running Kimi K3 for the cheap, well-scoped execution work and keeping Claude for the thinking. We hardened the CLI, pointed it at US-hosted inference, and open-sourced the fork. The math was good.
Then some of our highly regulated customers told me plainly: even with US inference, they can't use it. Not a paperwork problem. Off the table.
So learn from my mistake if you build for regulated industries. Where a model comes from matters as much as where you run it. Ask your customers before you ask your CFO.
Opus 5.5 made the rest of the decision easy. The gap we were using Kimi to cover isn't there anymore. We're back on a full Claude stack, planning, execution and review, with no plans to switch. The hardened fork stays up for anyone who can use it.
And we're grateful to be in Anthropic's Cyber Verification Program. Our test files read like an attacker's notebook. Anthropic checked who we are and what we do, and our team gets Claude at full strength on defensive work.
Fight AI with AI. Make sure yours clears your customers' bar, not just your budget's.
Greg Anderson
CEO & Co-Founder, DefectDojo