Stays on the machine you control
Your files, credentials, secrets and the full audit history live on the Windows PC you run Harness on. They are not uploaded to us, and there is no cloud copy.
The answer to “will it do something we can’t undo?” isn’t the word secure. It’s a model you can check: what it may do, what stays on your machine, and where anything ever leaves.
The boundary
Your files, credentials, secrets and the full audit history live on the Windows PC you run Harness on. They are not uploaded to us, and there is no cloud copy.
Task content is shared with an external AI provider or a business system only when you explicitly connect one for a job. You choose which, per capability — nothing is connected by default.
The control model
Out of the box the agent can do nothing. Each capability is a switch you turn on. If it’s off, that ability doesn’t exist for the agent — there is nothing to jailbreak into.
Irreversible or outbound actions — sending, spending, deleting, signing — pause in a queue and wait for a person. This holds even when the routine runs overnight.
The agent signs in through a broker, by name. Your real passwords and API keys are unlocked at the last moment and never placed in the model’s context or shown to it.
The receipt
Every task records what the agent read, which tools it used, which actions it took and which it queued for approval — in plain, reviewable language, kept on your machine. If an auditor, a manager or you six months later asks “what exactly happened here?”, the answer is one place, not a guess. The agent also restates a task before starting, so you can see what it understood before any work begins.
The honest part
Harness is the supervision layer, not the AI model. For the reasoning, you connect an AI provider — for example Claude or GPT — using your own account or key. When a task needs the model, the relevant task content is sent to that provider under their terms, and you pay them directly. That is the one place task content leaves your machine, and you decide when it does.
So we don’t say “fully local” or “nothing ever leaves”. We say what is true: operational data, credentials and audit history stay on the computer you control, and task content is shared only with the providers and systems you explicitly connect.
Where it runs
The flow is deliberately small and inspectable:
See it for yourself
In a private demo we show the default-deny switches, the approval queue and the audit trail on a routine you actually run — before anything is connected for real.