harperOS holds none of your data.
harperOS builds the system and hands you the keys. The repository, the data, and every credential stay yours.
The system runs on your infrastructure, not ours.
The operating system runs in your own GitHub. Your data stays in your Google Workspace and your database. The agents run on your team's machines. No harperOS server, no harperOS database.
You own the system, the data, and the agents.
Everything we build is licensed to you, in your own repository, for good. You can move the whole system to another provider whenever you want. Your workspace runs on its own login and its own roster — you decide who gets in.
One agent, one person.
Every agent signs in as its owner, and reaches only what that person already can. You grant access by name and revoke it in one step. Whatever security you already run keeps applying: your single company sign-in (SSO), two-factor login (MFA), and rules that stop sensitive data leaving (DLP). We add nothing that goes around it.
The agent proposes. A person decides.
The agent can prepare anything and finish nothing on its own. It drafts the email, your team presses send. It reads from your live systems but never changes them. Every change is staged for a person to approve, and made under that person's own login. There is no all-powerful admin account for the agent to use, and none of your data trains any AI model.
You can read every line.
Every rule and every integration is plain text in your own repository. There is no hidden backend — your team, and your security reviewers, can read exactly what each agent does. Every action is logged.
Encrypted by your own cloud.
Your data is encrypted by your own cloud: scrambled while it travels over the internet (TLS 1.2+), and again while it's stored (AES-256).
SOC 2.
We are actively engaged in obtaining our SOC 2. Our security controls are monitored continuously. See where they stand in our Trust Center.
Security questions? Pierre Merzeau, CTO & Security Officer — security@harperos.ai