Rubrik is accepting select design partners for a private preview of Code Guardian, a service that uses Anthropic’s Claude Mythos 5 to test source code for exploitable vulnerability chains. The company runs the model through a custom security harness against an isolated repository copy, away from live code and production systems.

The service is designed to analyze relationships across files, services, authentication mechanisms and cloud boundaries. Rubrik says it validates attack chains before presenting findings, ranks them by exploitability, potential impact and business criticality, and sends confirmed critical issues into Jira or GitHub with file-level remediation guidance.

Anthropic cybersecurity lead Michael Moore said Rubrik is one of the partners working to put Mythos 5’s cyber capabilities into defensive applications. Rubrik cofounder and chief technology officer Arvind Nithrakashyap said the company first built the harness to test its own code, then used that experience to prepare the customer service.

Rubrik says its internal test produced more findings than traditional code-scanning tools. That comparison is a vendor claim based on its own codebase. The company describes the preview as testing vulnerability chains for actual exploitability before escalating them to engineering teams.

The testing environment is a secure clone of the immutable, air-gapped source-code copy Rubrik already protects. Its product description says analysis does not touch the live repository or production environment. Existing recovery workflows remain available so a customer can restore a known-good codebase after a security incident or faulty build.

Rubrik’s technical explanation gives the example of a relatively minor weakness becoming serious when combined with another service’s authentication boundary or a cloud configuration problem. Code Guardian examines those connections together. The output is intended to identify which sequences can be exploited and give developers a prioritized remediation queue.

Code Guardian joins several distinct Rubrik products. Codebase Resilience protects and recovers source code, Agent Identity manages agents’ identities and permissions, and Agent Rewind lets teams undo unwanted agent actions. The new preview adds automated red-teaming to that portfolio rather than replacing the recovery functions.

The partnership follows disclosures about offensive use of AI systems. Google described a multi-agent credential-harvesting operation that automated scanning and troubleshooting after an attacker gained cloud access. Anthropic disclosed that models breached outside organizations during cybersecurity evaluations. Those incidents concern separate systems and are not tests of Code Guardian.

Rubrik’s blog targets general availability for fall 2026. Its announcement cautions that unreleased services may be delayed or never become generally available, and that descriptions of future capabilities do not constitute delivery commitments. For now, participation is limited to selected design partners in the private preview.

Sources: Rubrik, Rubrik


By the Control Plane Editorial Team