SECURITY
Hunting through pages of failure logs to figure out what went wrong with backups overnight is a tedious manual chore that Rubrik has fixed by giving AI agents a route into its telemetry by adding MCP support. It's also added a Code Guardian feature to detect code weaknesses.
MCP (Model Context Protocol) provides secure, bi-directional API-level communication between AI large language models (LLMs) and agents, and external data sources or tools. Rubrik MCP exposes the Rubrik Security Cloud API schema directly, granting connected agents instant access to any available capability. Teams can save their multi-step recovery or compliance workflows to make them reusable, deterministic tools across any AI client. Rubrik keeps security fully intact through role-based access control parity, configurable permissions, and OWASP MCP.
Rubrik CTO and co-founder Arvind Nithrakashyap said: “We are seeing rapid growth with AI, and the addition of Rubrik MCP transforms security operations by seamlessly connecting customer AI agents directly into Rubrik's rich telemetry and governance framework. Cyber threats accelerate at machine speed, and we are helping our customers use AI to maintain complete visibility and control across complex enterprise environments.”
Rubrik MCP expands on the company’s recent announcement of Rubrik becoming available as an AI Agent.
Support for MCP expands Rubrik AI, which combines Anthropic’s frontier models with Rubrik’s domain expertise and security features to deliver a multi-step reasoning agent engineered for critical incident response.
Rubrik AI enables direct interaction with Rubrik Security Cloud intelligence and Agent Cloud governance, functioning as an autonomous execution engine that operates across data, identity, and applications. On third of Rubrik’s customers are now using Rubrik AI.
Before MCP, Rubrik AI was mainly Rubrik acting as an agent on its own platform. With MCP, Rubrik AI becomes a shared intelligence and execution layer: first-party and third-party agents can reason over the same cyber-resilience data and run recovery/compliance workflows under the same identity and policy controls.
MCP makes Rubrik AI usable by other agents and is meant to go beyond getting Rubrik AI to get information from the dashboard to enabling managed agent execution while obeying existing access rules. Rubrik AI was already an agent across Security Cloud and Agent Cloud. MCP now allows a customer's agents (Claude, Copilot, custom agents, etc.) query Rubrik telemetry and act on recovery, identity, and application context through the same protocol.
Code Guardian
Rubrik has also launched Code Guardian, a custom Claude Mythos 5 harness that embeds and harnesses Anthropic’s Claude Mythos 5 into a service that operates directly on air-gapped copies of source code, enabling frontier model level vulnerability analysis while minimizing risk and impact on production environments.
It says Code Guardian uncovers and prioritizes the multi-step vulnerability chains an attacker would actually exploit, validates each for exploitability, and turns confirmed critical issues into tracked remediation. This makes, Rubrik claims, critical enterprise systems more resilient to even the most advanced frontier AI-powered attacks.
Nithrakashyap said: "Frontier models are advancing at a fast pace. In the wrong hands, these models can be used to discover, chain, and exploit vulnerabilities at machine speed,” said Arvind Nithrakashyap, Co-Founder and Chief Technology Officer at Rubrik. “To move just as fast, we are using frontier AI to scale vulnerability detection faster than our traditional code scanning tools. We took Anthropic’s powerful model and built a Rubrik software harness to test on our code. We are using that experience and success now to give customers access to the harness, with a secure, isolated environment, which means we can run analysis of their code away from live repository and production systems.”
Code Guardian features:
- Red-Team Customer Code: Runs Claude Mythos 5 through Rubrik’s custom security harness against a secure clone of the immutable, air-gapped copy, never against the live repository or production environment.
- Attack Chains: Reasons across files, services, authentication patterns, and cloud boundaries to surface previously undetectable vulnerabilities, even “chained vulnerabilities” that advanced AI attacks now exploit.
- Validated Findings, Prioritized by Business Criticality: Validates attack chains for real exploitability before surfacing them and prioritizes findings by exploitability, blast radius, and business criticality.
- Accelerated Remediation: Pushes confirmed critical issues into developer workflows through Jira or GitHub issues with file-level remediation guidance.
- Built-In Code Resilience: Maintains recovery workflows so organizations can restore a known-good codebase if a security event or bad build occurs.
Rubrik Code Guardian is currently accepting select design partners for private preview.
Rubrik MCP is currently available in private preview for existing Rubrik customers, with general availability targeted for October 2026.
Bootnote
OWASP is the Open Worldwide Application Security Project (formerly Open Web Application Security Project). It is a nonprofit foundation that works to improve software security through free, vendor-neutral tools, standards, research, and education.
Rubrik competitor Druva added MCP support in July, Cohesity in June, while Commvault added it in April.