Beta trust baseline

Security, data handling, and AI routing

Harbour is in beta, but the product already handles sensitive infrastructure metadata. This page documents what we store, how credentials are protected, and which limits still apply before enterprise certification.

Credential handling

Cloud credentials are encrypted before storage and decrypted only server-side when Harbour needs to probe, refresh inventory, or fetch costs. Credentials are never returned to the browser after save.

  • Use dedicated read-only provider credentials where possible.
  • Rotate credentials from the provider console at any time.
  • Audit events record environment creation and other mutating actions.

AI routing

Organisation workspaces can configure their AI provider, model, endpoint, region, and jurisdiction. Harbour routes architecture design, SRE chat, migration chat, and marketplace rationale through that control plane.

  • Workspace providers take precedence over environment fallback settings.
  • EU-only and external-provider policy modes are available in Account - Configuration.
  • AI usage events store metadata and estimated tokens, not full secret values.

Beta limitations

Harbour is not yet SOC 2 certified and should not be treated as an air-gapped enterprise product in beta. Regulated design partners should use scoped credentials and avoid pasting secrets into AI chat prompts.

  • SOC 2 Type I preparation is tracked for the enterprise pipeline.
  • Offline license mode exists, but local email/password auth and full air-gapped packaging are not GA.
  • Sentry/Better Stack production incident routing remains on the roadmap.

Data stored by Harbour

IdentityEmail, OAuth profile, workspace membership, role
Infrastructure metadataProvider, region, resource names, service counts, compliance scan results
CredentialsEncrypted provider credentials needed for live inventory and cost refresh
AI usageProvider, model, feature, status, approximate token counts, estimated cost
Operational logsAudit events for mutating actions and product security investigations

Current subprocessors

VercelApplication hosting and environment variables
NeonPostgreSQL database
ResendTransactional email and product onboarding email
StripeSubscription billing and customer portal
PostHogProduct analytics and funnel events
Anthropic / OpenAI / MistralOptional AI providers configured by Harbour or the workspace