Rubrik launches Code Guardian & expands Anthropic ties
Wed, 16th Sep 2026 (Today)
Rubrik has launched Code Guardian and added support for the Model Context Protocol to its AI security platform, extending its work with Anthropic.
The updates focus on how organisations use large language models in cyber defence. Code Guardian uses a custom setup built around Anthropic's Claude Mythos 5 to examine an air-gapped copy of a customer's source code. Rubrik MCP is designed to let AI agents connect to Rubrik's data, identity, and application intelligence through a programmable interface.
Rubrik is positioning Code Guardian as a way to test code for the kinds of chained weaknesses attackers may seek to exploit across files, services, and cloud environments. Rather than scanning a live repository, the service works on an isolated copy of source code, reducing risk to production systems.
According to Rubrik, the service is intended to identify multi-step vulnerability chains, check whether those paths are actually exploitable, and send confirmed critical issues into tools such as Jira or GitHub for remediation. The product is also linked to recovery workflows so organisations can restore a known-good codebase after a security incident or failed build.
Michael Moore, Cybersecurity Lead at Anthropic, described the partnership as a way to speed up defensive testing.
"Rubrik is one of the partners we are working with to put Claude Mythos 5's cyber capabilities in defenders' hands, so they can find and validate attack paths before attackers do," said Moore. "Rubrik will use the model to test code faster and at far greater scale, and to bring cyber resilience up to the speed of AI."
Code analysis
The launch reflects a wider shift in cybersecurity as vendors look to use generative AI not only for alert summaries and workflow assistance, but also for more technical analysis. Here, Rubrik is applying a model to source code review with the specific aim of tracing attack chains rather than flagging isolated coding issues.
Arvind Nithrakashyap, Co-Founder and Chief Technology Officer at Rubrik, said the company first used the approach internally before making it available to customers.
"Frontier models are advancing at a fast pace. In the wrong hands, these models can be used to discover, chain, and exploit vulnerabilities at machine speed," said Nithrakashyap. "To move just as fast, we are using frontier AI to scale vulnerability detection beyond our traditional code scanning tools. We took Anthropic's powerful model and built a Rubrik software harness to test our code. We are now using that experience and success to give customers access to the harness in a secure, isolated environment, which means we can analyse their code away from live repositories and production systems."
The second announcement focuses less on code review and more on how AI agents interact with security systems. Rubrik MCP adopts the Model Context Protocol, a developing standard intended to let models and agents access external tools and data sources more consistently.
For Rubrik, that means exposing the schema of its Security Cloud APIs so connected agents can query available functions and use them in operational workflows. Teams can save multi-step recovery or compliance processes as reusable tools across AI clients while maintaining access controls and permissions aligned with existing policies.
Agent access
Rubrik AI is now used by one-third of the company's global customers. Its AI agent architecture was developed with Anthropic's teams to reduce response latency and improve multi-step reasoning during incident response.
Nithrakashyap said the MCP addition is intended to connect customer-built or customer-selected AI agents to Rubrik's telemetry and governance layer.
"We are seeing rapid growth with AI, and the addition of Rubrik MCP transforms security operations by seamlessly connecting customer AI agents directly into Rubrik's rich telemetry and governance framework," said Nithrakashyap. "Cyber threats accelerate at machine speed, and we are helping our customers use AI to maintain complete visibility and control across complex enterprise environments."
The customer example cited by Rubrik focused on operational troubleshooting rather than autonomous response. Mpho Mongalo, Senior Backup Specialist at Datacentrix, said the existing AI features had reduced the manual work involved in reviewing overnight failures.
"Rubrik AI has honestly made my life so much easier. Mornings used to be a drag, spent hunting through pages of failure logs to figure out what went wrong overnight. Now, I just open Rubrik and get an instant, clear summary that explains exactly why a backup failed and how to fix it," said Mongalo.
The announcements underline a growing effort among cybersecurity suppliers to tie generative AI more closely to operational systems, moving from assistant-style interfaces towards software agents that can inspect code, query infrastructure, and help execute recovery or compliance tasks. In Rubrik's case, that push is paired with an emphasis on isolation, role-based controls, and tracked remediation workflows rather than unrestricted access to production environments.
Code Guardian is accepting select design partners in private preview, while Rubrik MCP is available in private preview for existing customers.