SECURITY

Trust is the whole product.

Agents are only useful with real access to real systems. Our job is making that access boring: scoped, gated, logged, and revocable in one click.

01

Isolation by default

Every agent works on its own machine with a private file system. One agent can't see another's work, one space can't see another space, and nothing sees yours.

02

Permission-gated actions

Every connector action passes a per-agent, per-action gate: Always, Ask, or Never. The gate is enforced server-side — not a prompt the model can talk its way past.

03

Auditable everything

Every run leaves a transcript: what was read, what was done, what was approved and by whom, what it cost. Delegation without an audit trail isn't delegation, it's hope.

Platform practices

  • Encryption — TLS 1.2+ for all traffic; customer data encrypted at rest.
  • Credential handling — connector credentials are stored server-side and never placed on agent machines; agents call connectors through Harby's gateway, which enforces your permission settings on every call.
  • Sandboxing — agent code runs in isolated environments with separate file systems and processes; escape attempts are treated as incidents.
  • Least-privilege access — production access is limited to the engineers who operate the system, audited, and behind hardware-key MFA.
  • Model provider boundaries — providers receive the minimum context a task needs and are contractually barred from training on your content.
  • Backups & recovery — encrypted backups with tested restores; see the privacy policy for retention windows.

Your controls

  • Per-action, per-agent permissions with an approval inbox (web and iOS).
  • One-click disconnect for any connector; revoked grants take effect immediately.
  • Full run transcripts and spend analytics for every agent, every day.
  • Export of spaces, files, and skills at any time.

Reporting a vulnerability

We welcome good-faith security research. Report suspected vulnerabilities to security@harby.app — it pages a human directly. Include steps to reproduce; we'll acknowledge within one business day, keep you informed, and won't pursue action against good-faith research that respects user data and availability. Please don't test against spaces you don't own.

Questions

Security reviews and questionnaires for Enterprise plans: security@harby.app or start with a demo call. A signed DPA is available — see DPA.