AI Frontier Post
AI News

Rubrik expands Project Hourglass with Code Guardian: a Claude Mythos 5 harness that red-teams your code

Rubrik is putting one of Anthropic's most capable models on defense. At its GSI Summit in Goa, India, on October 9, the security company expanded Project Hourglass — its partner alliance for agentic AI resilience — with Rubrik Code Guardian, a service that harnesses Anthropic's Claude Mythos 5 to red-team customer code repositories inside air-gapped environments. AHEAD, Trace3, and WWT joined the alliance, which already includes Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro.

Rubrik announced the expansion at its GSI Summit in Goa, pairing the partner-alliance news with the product: Project Hourglass will now deliver Rubrik Code Guardian alongside Rubrik Agent Cloud. The pitch is aimed squarely at the agentic coding wave — partners will proactively red-team client code repositories and secure AI workflows, with instant codebase recovery as the safety net.

What Code Guardian actually does

Code Guardian wraps a specialized security harness around Anthropic's Claude Mythos 5 and points it at a cloned, air-gapped copy of the customer's repositories — never the live production environment. Rubrik describes three capabilities: Isolated Red-Team Analysis, with the model operating inside Rubrik's harness; Attack Chain Discovery, where the engine reasons across files, services, identity roles, and cloud perimeters to surface chained vulnerabilities that conventional static scanners miss; and Business Impact Prioritization, which verifies each finding for actual exploitability and scores it by business criticality — an explicit attempt to kill alert fatigue.

“Engineering teams are turning to AI models to accelerate software delivery, but speed cannot compromise security or architectural integrity,” said Alok Agrawal, Rubrik's chief solutions officer, in the release. “By incorporating Rubrik Code Guardian into Project Hourglass, we are ensuring engineering teams are able to conduct red-team analysis, prioritize business impact and reduce risk.”

Illustration of AI-assisted red-team security analysis.
Illustration: PresentationGO.

Why now: 86% say agents will outrun their guardrails

The number Rubrik is selling against comes from its own Rubrik Zero Labs research: 86% of cybersecurity and IT leaders anticipate that the proliferation of AI agents will outpace their organization's security guardrails within the next year. Project Hourglass itself dates to June 2026, when Rubrik assembled the alliance to operationalize Rubrik Agent Cloud for Anthropic's Claude Code — runtime behavioral guardrails, prompt context protection, and an “Agent Rewind” feature that reverses unintended agent actions. Code Guardian extends that story from governing agents at runtime to stress-testing the code they produce.

The new partners each get a speaking slot in the announcement. AHEAD's Steven Sorensen, a specialty solutions engineer for cyber resiliency, frames the offer as adopting AI coding without inheriting an “AI-speed attack surface” — test and validate the code in a safe environment before it ships, with Rubrik recovery as the net. Trace3 chief marketing officer Sandy Salty notes the firm already runs Rubrik Agent Cloud internally and brings that hands-on experience to clients through its Resiliency practice and AI Risk and Governance practice. WWT's Chris Konrad, vice president of global cyber, points to the company's Advanced Technology Center, where security solutions are tested and validated before deployment.

The fine print

Code Guardian remains in private preview, accepting select design partners — and the release carries the standard safe-harbor language: it's provided as-is, may change, and may never reach general availability. The partner expansion is the concrete part of today's news; a general-availability timeline for Code Guardian is not.

Illustration of secure code review workflow.
Photo: Pexels, via red-team reporting.

Why it matters

This is the enterprise version of a pattern playing out across the industry: as agents write more of the world's code, the security conversation is shifting from “scan the repo” to “red-team the repo like an attacker would, with a frontier model doing the reasoning.” Rubrik's bet is that this gets sold and delivered through big systems integrators — not as a developer tool, but as a resilience practice. When Code Guardian was first unveiled in September, Anthropic cybersecurity lead Michael Moore called it a way to put Claude Mythos 5's cyber capabilities in defenders' hands “so they can find and validate attack paths before attackers do.” What to watch: whether Code Guardian graduates from private preview, and whether its “verified for exploitability” claim survives contact with real enterprise codebases.