Harness Connects API Security to AI Software Delivery
AI Changes the Software Delivery Security Model
Alan Shimel speaks with Adam Arellano of Harness during Techstrong TV’s Black Hat 2026 coverage. The discussion focuses on AI software delivery security and why security teams need to work more closely with engineering teams. Arellano explains that his path to Harness included cybersecurity work in the Marine Corps, compliance work at Salesforce and security engineering leadership at PayPal.
At PayPal, Arellano saw the value of both Harness and Traceable from the customer side. Harness helped engineering teams improve software delivery, while Traceable provided deeper visibility into APIs and application behavior. That experience shaped his view that security and delivery should not live in separate platforms. In an AI-driven world, they need to work together.
Traceable Brings API Security Into the Platform
The conversation also looks at Traceable’s role inside Harness. Traceable started as an API security company, but its discovery and visibility capabilities exposed much more about application behavior. Arellano says that insight matters because APIs now sit at the center of modern software and AI systems. If organizations do not understand their APIs, they do not fully understand their risk.
Harness brings that security context into the broader software delivery lifecycle. That matters as teams use AI to build, test and deploy faster. AI software delivery security is not only about scanning code. It is also about understanding pipelines, infrastructure as code, provisioning choices and the way applications change over time.
Security Work Is Becoming Engineering Work
Arellano says many of the actions needed to respond to new AI risks are engineering tasks. Security leaders may identify the risk, but developers and DevOps teams often make the changes that reduce it. That makes collaboration essential. If security and engineering do not work together, they will struggle to respond at the speed AI demands.
The discussion connects this shift to platform engineering. As organizations build internal platforms, security needs to be part of the workflow. Guardrails should help developers move faster without creating avoidable risk. Arellano describes a need for guidance across pipelines, infrastructure, provisioning and release processes.
Fast Releases Become a Security Capability
Alan and Arellano also discuss what happens when a zero-day vulnerability appears. The fix often requires a safe release. If an organization cannot change code and deploy quickly, it is already behind. That makes software delivery speed a security issue, not only an engineering metric.
For technology leaders, the takeaway is clear. AI is expanding what teams can build, but it is also expanding what they must understand and secure. Harness is positioning AI software delivery security as a way to connect API visibility, DevSecOps practices and platform guardrails so teams can move quickly without losing control.
Transcript
Hey, we're back here at our Black Hat coverage continuing. My next guest is Adam Arellano. Adam is with Harness and, well, I'm going to let him tell his story, not me tell his story.
Adam, welcome to Techstrong TV. It's great to be here. It's great to be sitting next to you in particular.
Oh, man. You're a minor celebrity in our world, just so you know. A very minor, like Pluto's not a planet, right?
Yeah. But it's close, right? It's close.
It's better than being a moon. Exactly. But anyway.
Hey, I appreciate that, though. But Adam, give people a sense of kind of, we were talking off camera, I understand how you came to Harness, but give people a sense of your journey. Yeah, sure.
So, real weird path. I was a Marine for a long time, did cybersecurity for the Marine Corps. Went to Salesforce doing compliance.
Eventually, after a couple startups, ended up at PayPal, and we were customers of both Harness and Traceable. And so I was in charge of security engineering, so I had Traceable. And looking at the capabilities of the tool, I was shocked at how much insight we could get from it.
Yeah. " And I said, "I believe in your tool, I believe in your leadership, and I believe in where this is going. " Right.
And that's why I joined about two years ago, was to- Very cool ... accomplish that. And of course, AI is here now.
Yes. So you didn't work on NMCI in the Marine Corps, did you? I did, unfortunately, work on NMCI.
So did I. Before I was doing media, I founded a couple companies, one of which we had what they call a NAC product. Mm.
You know, access control? Yep. And so we were the NAC for NMCI.
Yeah. What a frigging, excuse my language, but what an education. Yeah.
First of all, trying to get the Marines and the Navy- Oh, no ... that was such a marriage made in hell. Bad idea.
Yeah. Man. Whose idea was it to give them one network?
Yeah, or give us to-- They shouldn't have taken away our crayons and just let us use those. Exactly. Right.
But the Chinese nationals that had accounts in NMCI actually got a lot of work done. Yes, they did. Because we used to...
Now is not the place to talk about that, but we can talk about it over- Yeah, yeah ... there or something someday, but it was crazy. Yeah.
ai, right? They had a founder in common, funding in common, Jodi Mansigh. Mm-hmm.
Mansigh. Traceable started life as sort of an API security company. Right.
But as you said, on the way to doing API security, their discovery tools and everything else turned up- Yeah ... amazing things that you want to know to help- Yeah ... you with what you're doing.
At the same time, look, as I told you, we've covered Harness since the day it launched. They made that transition from DevOps to DevSecOps- Yeah ... probably earlier than a lot of the other DevOps- Correct ...
sort of platforms. com and Security Boulevard, it was a no-brainer. Yeah.
But it took a little while, but it did happen. And so Traceable was folded into Harness. Harness got a ton of security DNA- Yes ...
security talent. Right. Including you, I guess, it sounds like, right?
Yeah. As part of that deal. Correct.
And it's been a great marriage and, again, Jodi's vision- Yeah ... is dead on with this stuff. Let's talk, though, a lot of people out here are saying to themselves, "That's great, Adam, but why the hell are you guys at Black Hat?
" Yeah. We get to talk about that in a minute. Yeah.
But what are you doing here at Black Hat? It's interesting that the majority of the conversations we've been having with security leaders has been about their engineering teams. Because really, the work that's, so for example, when Mythos was released and Anthropic released their manifesto of this is how you need to address this, all the actions that Anthropic actually listed were engineering tasks, not security tasks.
Yep. And so what we've been doing is trying to educate the security people that everything that you need to accomplish to protect yourself against this new threat actually needs to happen in your DevOps platform with your DevOps people. Absolutely.
And if you don't work together, you're going to die apart. And so that's why we're here. I agree with you.
So look, I run the DevSecOps thing at RSA every year on Monday. Mm-hmm. That's how that started.
Yeah. Trying to bring the DevOps tribe into the security community. The first year or two, we had to bring bandages.
Yeah. It got a little out of control. Because it was so funny that the security people, as always security people do, said, "Those people don't give a crap about security.
" They cry while they yell- Yeah ... about the idea. A little bit of both.
And then the DevOps people say, "Those people are just the people who say no, man. " Yeah. " But the funny thing is, is they want that anchor because they know they need that anchor.
Yes. But anyway, it's come a long way since then, certainly, and in many ways, Harness is the living embodiment- Yeah, agreed ... of that.
But we mentioned AI. Yes. Can have these conversations.
Yeah. Actually, I saw Jodi sign the, was it the OpenAI? Correct.
Not OpenAI ChatGPT. No, yeah. The OpenAI letter that AI should be more open- Correct ...
and stuff like this. And Harness has been on a bit of its own kind of agentic product pattern. Why don't you give us a little background on that?
Yeah, and it's not just that we're providing that to our customers. We've been using it internally. We have done a lot of work.
There's been times where the agents we've been working on haven't performed like we want to, so we're using our own product. But really what we found is that limited use case agents that are very well guardrailed, that are very specifically tasked, are actually super helpful and enable people to do work better. It's not that anybody's going to be replaced, it's they're going to be more capable.
Exactly. And honestly, my degree is actually in social work, which is a weird thing for a Marine. Really?
My wife has a master's in social work. Was it because of you, or did she- Well, I am her best patient, but yeah. We can talk about that another time, too.
It's the perfect thing for a Marine and a cybersecurity person, to have a degree in social work. A little empathy. Yeah, exactly.
And what we're trying to do is help people who are doing these difficult jobs, who are facing the wave of AI attacks, do their job more quickly and more with better skill using agents, not just throwing a random agent out there to do everything. Because the world needs another random agent. Yeah.
Very specifically designed agents that will do specific parts of the SDLC process. All right. And we call it the AIDLC now, because that's really what it is, is an agentic- I agree with you ...
agentic pipelines. It really is. But Harness is developing their own agents.
Correct. I've seen some of the announcements. We might even have interviewed someone from Harness.
Not here at Black Hat. Mm-hmm. On regular Techstrong TV.
What's the deal there? So what we're making is not just an ability to put guardrails on your pipelines, but also somebody to guide you through that. Because there are good decisions that can be made, and there's bad decisions that can be made in that process, and that's anywhere from your infrastructure as code, it can be the way that you provision things, the way your pipeline's designed.
We've been building agents for each part of that journey, and then having them coordinated so that they can help you throughout the whole entire process. Because what we're seeing is that as people are using AI and agents, not that their skill level is dropping, it's that their understanding of what they're creating is going beyond their ability to really see all of it, and they need help being able to interpret it in an appropriate- I agree with you. I was writing an article the other day for "Techstrong Semi" about advanced packaging and silicon.
Mm. And I wrote this article using the AI with me, because back and forth, and I read the article, I said, "This isn't me. I don't even know half of this stuff.
" Yeah. And I realized that this is the issue. It's one thing if you're using it to help in your wheelhouse.
Yeah. And it's a great tool to learn about stuff like this. But the problem is, I think you can get out in front of your skis.
Yes. Right? And now you're in deep water, and not easy.
And the solution to that isn't to stop doing it. No, not at all. It's to put the proper guardrails in place, make sure that the fundamentals are there and by policy immutable, and that's why you can go faster.
" Mm-hmm. He's talking about the downforce of an F1 car. The wing on the back- Sure ...
pushes it into the road so that it can turn faster than physics should allow it to. Mm-hmm. That's what guardrails do.
I thought it was just to make it look cool. It does. No, it really does.
Yeah. So I leave a book. We have a lot of fancy cars.
So I love the Porsche ones, the Carrera ones. Those are for looks, for sure. I know they are, but it looks hot as hell, man.
Yeah. And it's not like I drive a bit, or I don't want to get into it. But I have a nice little car I drive.
Yeah. " Yeah, maybe I trade this for that. But yeah, I'm happy with what I have.
Anyway, let's come back to security though, Adam. Sure. A big thing on DevOps is platform engineering.
Yeah. Right? And I don't think they're mutually exclusive.
I think one begets the other. But security is the bridge. Yeah.
Right? As we're building these platforms that allow our DevOps engineers and our developers to go faster, AI scale. Yeah.
Not just fast, but wider. Yeah. This whole AI thing, platform engineers have to be AI platform engineers.
Correct. As you said, DevOps engineers have to be AI DevOps engineers. We have to have an AI software life cycle.
Correct. You can't have one without the other. This is right across.
And they're fundamentally different from the way that we used to think about them. Yep. And not designing for that is asking for trouble, and that's what we're seeing.
It's fatal at this point. Yeah. In our customer base, those that are most successful are the ones that are thinking about it in new ways and actually trying to pay attention to the ways that it's different.
While there's a lot of principles that still apply, there's a lot of new stuff out there that has to be accounted for. I agree, man. I agree 100%.
Let me ask you another question. People out here are inundated with agentics, and this agent, and that one broke containment, and this one, and we found these vulnerabilities. Mm-hmm.
What's the best way for someone out here to stay on top of the game? This is a hard answer. I know.
If it was an easy one, I'd be retired. Yeah. I think the big mistake that everybody downstairs is making is they are selling and solutioning for the zero day, for day one.
Right. And they're not solutioning for everything that comes before that. The most important thing, and it doesn't matter where the threats go, it doesn't matter where anything else happens, if you get the fundamentals real tight, can you release at speed?
Can you know that your code is safe? Can you make changes to your environment at speed? That is first.
Then you need somebody to help you when the zero day comes. But if you don't have this part, then zero day hits, you can't release quickly, you can't release safely, then what are you going to do? The only way you can fix these problems is releasing.
Right. And if you can't do it safely, then you're already behind the eight ball. And this is, again, an engineering problem, not a security problem.
No. Yeah. Again, a security risk.
The problem is, though, it's not just you're behind a snowball. Yes. Because every second, minute, hour- Yeah ...
it just keeps going. Yeah. That was the conversation that we had about two years ago.
What's next? And we didn't know the name of Mythos, we didn't know when it was going to happen, but we knew that it was coming. Some people did.
Yeah. Yes. Like Dotty Everett and the- Yeah ...
Heather from Google. They almost predicted it to the week, right? Yes.
Yeah. And we've been talking about it for a while, but that's what we've been building towards. We were talking about it when I had my security company 20 years ago.
Yeah. But in any event, hey man, keep up the great work, Adam. Yeah.
I watch what you guys do at Harness. I appreciate it. Yeah.
I appreciate the security focus, and keep it up. Now I get to brag to my friends that I got to talk to Mr. DevOps.
You're Mr. DevOps. I'm selling e-books.
Talk to TV. Hey, we're going to take a break. We'll be right back.