Security & Trust

Security and Trust at Harness

We take a comprehensive approach to data privacy and security — protecting our infrastructure, our products, and your data. A geographically diverse security team operates and continually strengthens our security and compliance programs.

Compliance posture
SOC 2 ISO 27001 ISO 27017 ISO 27018 GDPR & CCPA
01

Security

Availability & Disaster Recovery

Multi-region architecture across separate geographies lets the platform scale rapidly if a primary location fails. Failover is tested at least annually, with frequent database backups enabling point-in-time restore.

Personnel Security

Rigorous interviews and background checks for every hire. Security and privacy training is required at onboarding and repeated annually thereafter.

Secure Software Development

Security is embedded across the SDLC. Every production change is peer-reviewed and approved, tested through CI, scanned for vulnerabilities, and ships with roll-back procedures.

Vulnerability Management

We scan infrastructure and application code at least monthly, remediating findings in line with NIST vulnerability timelines.

Incident Response

A dedicated IR team follows the SANS PICERL and NIST SP 800-61 guides. Operational incidents post to our Status Page, and impacted customers are notified without undue delay.

02

Data Security

Customer Data Protection

We collect minimal PII. All customer data carries our most critical classification — encrypted in transit with TLS 1.2+ and at rest with AES-256.

Data Isolation

Customer data never touches non-production. Dev, test, and staging are strictly separated from production, and every account is logically isolated by a unique Account ID.

Identity & Access Management

Least-privilege RBAC with unique accounts per employee. SSO is enforced for critical business systems and two-factor authentication is implemented wherever possible.

System Monitoring

We continuously collect signals from infrastructure and endpoints — access, performance, vulnerabilities, utilization — and alert security and operations teams on anomalies.

Compliance & Certifications

Independently audited, continuously certified

We’re SOC 2 compliant and ISO 27001 / 27017 / 27018 certified. Request our latest reports and explore our full security posture and controls in the Harness Trust Center.

SOC 2
Service Orgs
ISO 27001
Certified
ISO 27017
Cloud Security
ISO 27018
PII in Cloud
03

Assessments, Audits & Compliance

Penetration Testing

Each year we engage an external firm to conduct a penetration test against our application and external network.

Risk Management

Risk assessments run at least annually and after major changes — classified by likelihood, impact, and mitigation, then reviewed with stakeholders and tracked in a risk register.

Vendor Management

A vendor risk program continuously monitors and assesses suppliers against our security and compliance requirements — covering both business systems and technical assets.

Laws & Regulations

We comply with GDPR, CCPA, and other applicable privacy laws. The Privacy Statement details what we collect; data-subject rights can be exercised via a Privacy Request.

04

Product Security

Authentication & Authorization

Local auth or integration with your corporate Identity Provider, with SSO and Two-Factor Authentication enforced through Harness or your IdP.

Access Management

Advanced Role-Based Access Control gives granular control over what users and service accounts can do across the platform.

Auditing

A comprehensive, out-of-the-box Audit Trail at the account and organization levels captures every event and change in the platform.

Delegate Security

The Harness Delegate runs in your environment to connect internal systems to the platform — over a secure WebSocket connection protected by TLS.

Secret Management

A built-in Secrets Management solution on top of GCP KMS stores the secrets used in your account, pipelines, and connectors securely and conveniently.

Container Hardening

We build on hardened images and ship a vetted ‘safe image’ — third-party dependencies sourced from trusted resources, with relevant OS hardening applied.

Reporting Security Issues

Found a vulnerability? Tell us.

If you believe you’ve discovered a critical security bug or vulnerability affecting our products or services, email security@harness.io. We ask that you not publicly disclose the issue until we’ve had a chance to address it.

Interested in our private bug bounty? Reach out with your preferred email address.

We respond within 24 hours