
Security
Rubrik Introduces Code Guardian for AI Code Security
October 10, 2026
Read Original: RubrikRubrik announced an expansion of its Project Hourglass cybersecurity alliance on October 9, introducing Rubrik Code Guardian, a proposed security offering designed to help organizations assess code risks as AI-assisted software development accelerates.
The company says Code Guardian uses Anthropic's Claude Mythos 5 through a specialized security harness. Its approach is to analyze a cloned copy of a customer's code repository inside an isolated, air-gapped environment rather than experiment directly against live production systems.
Rubrik describes a red-team analysis process intended to identify multi-step attack paths across files, services, identity permissions and cloud boundaries. This is a broader goal than simply flagging individual suspicious lines of code: some vulnerabilities become dangerous only when several weaknesses are combined.
Another focus is prioritization. Development teams frequently receive large volumes of security findings, many of which may be difficult to exploit or relatively low impact. Rubrik says the system aims to verify exploitability and rank issues according to business significance so teams can focus on the most consequential problems.
Code Guardian is being introduced alongside Rubrik Agent Cloud, which provides safeguards for AI-agent workflows. The wider Project Hourglass initiative also includes recovery capabilities intended to help organizations reverse harmful or unintended changes.
Rubrik announced that AHEAD, Trace3 and World Wide Technology are joining the alliance, alongside existing partners. These companies are expected to help bring security assessments and related services to enterprise customers.
There is an important availability caveat: Rubrik says Code Guardian is in private preview with select design partners. It is not generally available, and the company cautions that unreleased capabilities may change. Businesses should therefore distinguish the announced direction from a mature, broadly deployed product.
For engineering leaders, the announcement highlights a practical question about AI-generated code. Faster code production does not eliminate the need for architectural review, independent security testing, controlled permissions and reliable recovery procedures. The emerging market for AI-assisted security tools is increasingly focused on addressing those concerns together.
Source:Rubrik