Harness Connects API Security to AI Software Delivery
AI Changes the Software Delivery Security Model
Alan Shimel speaks with Adam Arellano of Harness during Techstrong TV’s Black Hat 2026 coverage. The discussion focuses on AI software delivery security and why security teams need to work more closely with engineering teams. Arellano explains that his path to Harness included cybersecurity work in the Marine Corps, compliance work at Salesforce and security engineering leadership at PayPal.
At PayPal, Arellano saw the value of both Harness and Traceable from the customer side. Harness helped engineering teams improve software delivery, while Traceable provided deeper visibility into APIs and application behavior. That experience shaped his view that security and delivery should not live in separate platforms. In an AI-driven world, they need to work together.
Traceable Brings API Security Into the Platform
The conversation also looks at Traceable’s role inside Harness. Traceable started as an API security company, but its discovery and visibility capabilities exposed much more about application behavior. Arellano says that insight matters because APIs now sit at the center of modern software and AI systems. If organizations do not understand their APIs, they do not fully understand their risk.
Harness brings that security context into the broader software delivery lifecycle. That matters as teams use AI to build, test and deploy faster. AI software delivery security is not only about scanning code. It is also about understanding pipelines, infrastructure as code, provisioning choices and the way applications change over time.
Security Work Is Becoming Engineering Work
Arellano says many of the actions needed to respond to new AI risks are engineering tasks. Security leaders may identify the risk, but developers and DevOps teams often make the changes that reduce it. That makes collaboration essential. If security and engineering do not work together, they will struggle to respond at the speed AI demands.
The discussion connects this shift to platform engineering. As organizations build internal platforms, security needs to be part of the workflow. Guardrails should help developers move faster without creating avoidable risk. Arellano describes a need for guidance across pipelines, infrastructure, provisioning and release processes.
Fast Releases Become a Security Capability
Alan and Arellano also discuss what happens when a zero-day vulnerability appears. The fix often requires a safe release. If an organization cannot change code and deploy quickly, it is already behind. That makes software delivery speed a security issue, not only an engineering metric.
For technology leaders, the takeaway is clear. AI is expanding what teams can build, but it is also expanding what they must understand and secure. Harness is positioning AI software delivery security as a way to connect API visibility, DevSecOps practices and platform guardrails so teams can move quickly without losing control.