Rubrik Expands Project Hourglass with Code Guardian

Rubrik Expands Project Hourglass with Code Guardian

Rubrik is attempting to solve the growing security gap between rapid AI-driven software development and traditional defensive guardrails. By expanding its Project Hourglass initiative, the company is integrating Rubrik Code Guardian to provide partners with tools for proactive red-teaming of code repositories. This strategic move addresses a specific anxiety identified by Rubrik Zero Labs, which reports that 86% of cybersecurity and IT leaders expect the proliferation of AI agents to outpace organizational security measures within the next year. The expansion brings new partners, including AHEAD, Trace3, and WWT, into an alliance designed to secure agentic AI workflows and maintain codebase recovery capabilities through specialized, air-gapped testing environments.

Rubrik Code Guardian and the Project Hourglass Expansion

The introduction of Rubrik Code Guardian marks a shift toward securing the entire lifecycle of AI-augmented engineering. While Project Hourglass originally focused on operationalizing Rubrik Agent Cloud for Anthropic's Claude Code—providing runtime behavioral guardrails and "Agent Rewind" capabilities—the addition of Code Guardian aims to secure the underlying source code. Rubrik is positioning this as an end-to-end security architecture that addresses both the runtime behavior of AI agents and the integrity of the code they produce or utilize.

To achieve this, Rubrik Code Guardian utilizes Anthropic's Claude Mythos 5 within a specialized security harness. The system is designed to operate on cloned, air-gapped copies of customer repositories rather than live production environments, mitigating the risk of accidental disruption during testing. The engine is intended to reason across files, services, identity roles, and cloud perimeters to identify chained vulnerabilities that static analysis tools might overlook. Furthermore, the company aims to reduce alert fatigue by verifying the actual exploitability of findings and scoring them based on business criticality. This expansion also includes new partners AHEAD, Trace3, and WWT, joining existing members such as Cognizant, Deloitte, HCLTech, NTT DATA, and Wipro to accelerate client deployments through dedicated technical certification tracks and direct engineering access.

Securing Agentic AI Workflows via Air-Gapped Red-Teaming

The technical core of this expansion rests on the ability to simulate sophisticated, multi-step threat scenarios without exposing sensitive production assets. By leveraging Claude Mythos 5 inside an isolated harness, Rubrik is offering a method for "isolated red-team analysis." This approach allows engineering teams to test how AI-generated or AI-assisted code might behave under attack before it is deployed into a live environment. The goal is to allow for increased development speed without compromising architectural integrity or security.

For enterprise partners, the integration of Code Guardian into Project Hourglass provides a framework for "agentic cyber resilience." This involves not just protecting the code, but also managing the risks associated with autonomous AI agents. The architecture seeks to provide a safety net where, if an AI agent performs an unintended action, capabilities like Agent Rewind can reverse the event. By combining codebase protection with runtime guardrails, Rubrik is attempting to build a defensive layer that scales alongside the increasing autonomy of enterprise AI tools. Currently, Rubrik Code Guardian is in private preview and is not yet generally available, with the company noting that features and performance are not guaranteed.

Key Takeaways

  • Rubrik is expanding its Project Hourglass alliance to include partners AHEAD, Trace3, and WWT to deliver Rubrik Code Guardian.
  • Rubrik Code Guardian utilizes Anthropic's Claude Mythos 5 to perform red-team analysis on cloned, air-gapped copies of customer code repositories.
  • Rubrik Zero Labs reports that 86% of cybersecurity and IT leaders anticipate AI agent proliferation will outpace security guardrails within one year.

TechInsyte's Take

In our view, Rubrik is making a calculated bet that the primary friction point for enterprise AI adoption will not be the models themselves, but the security debt incurred by AI-accelerated development. By linking Code Guardian with Agent Cloud, Rubrik is moving beyond simple data backup into the realm of "agentic resilience." This is a sophisticated attempt to capture the security layer of the AI lifecycle—protecting both the code being written and the agents doing the writing. The reliance on Anthropic's Claude Mythos 5 suggests that Rubrik recognizes that defending against AI-driven attacks requires an equally sophisticated AI-driven defense. However, the success of this strategy depends on whether enterprises trust air-gapped, cloned environments to provide a truly representative test of their complex, interconnected production perimeters.

Questions & Answers

How does Rubrik Code Guardian protect production environments during testing?

Rubrik Code Guardian avoids live production environments by testing a cloned, air-gapped copy of customer repositories. This allows the Claude Mythos 5 engine to conduct red-team analysis and discover attack chains within a specialized security harness without risking the integrity of active services.

What specific problem is Project Hourglass attempting to solve for enterprise engineering teams?

Project Hourglass aims to address the tension between the speed of AI-driven software delivery and the need for security. It provides an architecture that includes runtime behavioral guardrails for AI agents and proactive red-teaming for code repositories to ensure that rapid development does not compromise architectural integrity.

What is the strategic significance of the new partners joining Project Hourglass?

The addition of AHEAD, Trace3, and WWT to the existing alliance of partners like Deloitte and Wipro provides Rubrik with broader deployment capabilities. These partners are intended to help clients bridge the gap between AI adoption and security, offering specialized expertise in architecture, deployment, and resiliency.

What are the primary functional capabilities of the Rubrik Code Guardian engine?

The engine is designed to perform isolated red-team analysis, discover complex attack chains by reasoning across files and identity roles, and prioritize findings based on business impact and actual exploitability to minimize alert fatigue.

Source: Rubrik

TechInsyte | Technology Intelligence technology intelligence workspace

About TechInsyte | Technology Intelligence

TechInsyte is a B2B technology news and intelligence platform covering major developments across AI, cloud, cybersecurity, enterprise software, semiconductors, startups, policy, and markets. We focus on the signals that matter for decision-makers.

The idea behind TechInsyte is simple. Technology moves fast, and professionals need clear information without unnecessary noise. New platforms emerge, security risks evolve, enterprise software changes, and the AI shift continues to reshape how companies operate. We help readers understand those developments in a practical and business-focused way.

Our coverage focuses on meaningful technology updates, product launches, enterprise strategy, funding activity, regulatory change, infrastructure trends, and the broader forces shaping the technology industry. The goal is to keep every article clear, relevant, and useful for professionals who need to know what happened, why it matters, and what it could mean next.

TechInsyte is built for readers who want sharper context, cleaner coverage, and a more focused view of technology without the clutter.