The current ecosystem of cybersecurity and enterprise software development is experiencing an important operational transition due to the emergence of Agentic AI. In the last 12 months, the use of AI coding assistants and autonomous developer agents has dramatically shortened the software release process. But as software development teams deliver software coded using artificial intelligence in machine speed, CISOs and enterprise DevSecOps engineers face a major structural problem: the code resilience challenge and alert fatigue.
While SAST and SCAs have been very good at finding vulnerabilities in isolation, they look at each one individually.
The security team is often flooded with hundreds or thousands of alerts and is forced to use countless hours going through static vulnerability queues manually.
In today’s cloud-native software development ecosystem, cyber-criminals do not target standalone vulnerable elements but combine multi-stage attacks across files, authentication layers, and cloud services to complete the system compromise.
Moreover, conducting automated and aggressive red-team exercises against real production repositories runs the risk of causing system downtime and corrupting data.
To fill the exposure gap and ensure DevSecOps for enterprises, organizations need a threat-aware, automated security framework that can safely conduct red-team testing against customer codebase, identify exploitable attack chains, and prioritize mitigation efforts based on the business impact.
Addressing this critical software security bottleneck, cloud data management and cyber resilience leader Rubrik announced on the expansion of its Project Hourglass partner alliance alongside the introduction of Rubrik Code Guardian, powered by Anthropic’s Claude (specifically leveraging the Claude Mythos 5 model).
By integrating Rubrik Code Guardian into Project Hourglass-an alliance initiative launched to operationalize Rubrik Agent Cloud for Anthropic’s Claude Code-Rubrik equips enterprise clients and technology partners with autonomous red-teaming, attack chain discovery, and codebase recovery capabilities designed to secure the modern software development lifecycle (SDLC).
Red-Teaming Air-Gapped Repositories with Frontier AI
The Rubrik Code Guardian is an innovation that leverages the advanced AI reasoning of Anthropic’s frontier directly on the clones of customer source code repositories. Unlike traditional code scanning approaches, the Rubrik Code Guardian does not require scanning the live production databases or live repositories of developers, but uses a secure air-gapped red-teaming harness to conduct simulations for finding out any complex vulnerabilities before code deployment.
The key pillars of this innovation are:
Air-Gapped Red-Teaming Harness: Conducts multi-step attacks on the clones of customer code bases and ensures protection from the friction or disruption of the live production environment due to the tests.
Vulnerability Chains through Attack Chain Discovery: Through Claude Mythos 5, finds out complex vulnerability chains which cannot be found by any human reviewer or static code scanner.
Business Impact Prioritization and Jira/GitHub Integration: Eliminates alert fatigue by scoring findings by verified exploitability and pushing confirmed critical vulnerabilities directly into developer ticketing systems like Jira and GitHub with file-level remediation guidance.
Also Read: LTM Expands Strategic Collaboration with Google Cloud to Accelerate Gemini Enterprise Adoption
Built-in Codebase Recovery Workflows: Integrates Rubrik’s core data protection capabilities, maintaining point-in-time recovery workflows so organizations can restore known-good codebases following a security event or bad build.
Project Hourglass Partner Ecosystem Expansion: Broadens the Project Hourglass alliance to include premier IT solutions integrators-including AHEAD, Trace3, and World Wide Technology (WWT)-providing joint go-to-market resources, technical certification tracks, and direct engineering access.
“Engineering teams are turning to AI models to accelerate software delivery, but speed cannot compromise security or architectural integrity,” stated Alok Agrawal, Chief Solutions Officer at Rubrik. “By incorporating Rubrik Code Guardian into Project Hourglass, we are ensuring engineering teams are able to conduct red-team analysis, prioritize business impact, and reduce risk.”
Impact on the Cybersecurity Industry
The expansion of Rubrik’s Project Hourglass and the launch of Rubrik Code Guardian highlight major structural developments across the broader Cybersecurity landscape:
1. Transitioning from “Static Vulnerability Scanners” to “Agentic Red-Teaming”
For two decades, code security relied on rule-based static analyzers that generated long, unranked lists of potential code flaws.
Deploying Anthropic’s Claude within Rubrik Code Guardian formalizes the industry transition toward Agentic Coding Security. Modern cybersecurity platforms utilize autonomous AI models that reason like human threat actors, identifying how minor, low-severity bugs across different microservices can be chained together into full administrative account takeovers.
2. Converging Code Security with Data Resilience and Recovery
Historically, Application Security (AppSec) software and Data Backup/Recovery platforms operated in completely separate enterprise silos.
Rubrik’s integration proves that Code Resilience Requires Unified Data and Identity Governance. Pairing proactive pre-deployment code auditing with Rubrik’s immutable data recovery safety net ensures that enterprises maintain operational continuity even if a faulty build or zero-day exploit bypasses initial defenses.
Overall Effects on Businesses Operating in the Sector
Key commercial advantages resonating across global enterprise adopters include:
Accelerating Secure Software Delivery: Developer teams can adopt AI coding tools like GitHub Copilot without fear of shipping invisible vulnerability chains to production.
Maximizing DevSecOps Productivity: Filtering out false positives and unexploitable bugs allows enterprise security engineers to focus exclusively on high-value architectural defenses.
Strengthening Channel Partner Ecosystems: Enterprise IT partners (such as AHEAD, Trace3, and WWT) gain pre-validated frameworks to help corporate clients secure, observe, and recover agentic AI environments.
Conclusion
Rubrik’s expansion of Project Hourglass through the introduction of Claude-powered Rubrik Code Guardian represents an important milestone in the commercial evolution of application security, agentic AI governance, and cyber resilience. By pairing Rubrik’s data protection platform with Anthropic’s state-of-the-art AI reasoning, Rubrik delivers a practical blueprint for DevSecOps in the AI era. For the global cybersecurity industry, this news confirms that staying ahead of machine-speed cyber threats requires building fast, air-gapped, and recovery-ready code defenses.























