Availability & Disaster Recovery
Multi-region architecture across separate geographies lets the platform scale rapidly if a primary location fails. Failover is tested at least annually, with frequent database backups enabling point-in-time restore.
Security & Trust
We take a comprehensive approach to data privacy and security — protecting our infrastructure, our products, and your data. A geographically diverse security team operates and continually strengthens our security and compliance programs.
Multi-region architecture across separate geographies lets the platform scale rapidly if a primary location fails. Failover is tested at least annually, with frequent database backups enabling point-in-time restore.
Rigorous interviews and background checks for every hire. Security and privacy training is required at onboarding and repeated annually thereafter.
Security is embedded across the SDLC. Every production change is peer-reviewed and approved, tested through CI, scanned for vulnerabilities, and ships with roll-back procedures.
We scan infrastructure and application code at least monthly, remediating findings in line with NIST vulnerability timelines.
A dedicated IR team follows the SANS PICERL and NIST SP 800-61 guides. Operational incidents post to our Status Page, and impacted customers are notified without undue delay.
We collect minimal PII. All customer data carries our most critical classification — encrypted in transit with TLS 1.2+ and at rest with AES-256.
Customer data never touches non-production. Dev, test, and staging are strictly separated from production, and every account is logically isolated by a unique Account ID.
Least-privilege RBAC with unique accounts per employee. SSO is enforced for critical business systems and two-factor authentication is implemented wherever possible.
We continuously collect signals from infrastructure and endpoints — access, performance, vulnerabilities, utilization — and alert security and operations teams on anomalies.
Compliance & Certifications
We’re SOC 2 compliant and ISO 27001 / 27017 / 27018 certified. Request our latest reports and explore our full security posture and controls in the Harness Trust Center.
Each year we engage an external firm to conduct a penetration test against our application and external network.
Risk assessments run at least annually and after major changes — classified by likelihood, impact, and mitigation, then reviewed with stakeholders and tracked in a risk register.
A vendor risk program continuously monitors and assesses suppliers against our security and compliance requirements — covering both business systems and technical assets.
We comply with GDPR, CCPA, and other applicable privacy laws. The Privacy Statement details what we collect; data-subject rights can be exercised via a Privacy Request.
Local auth or integration with your corporate Identity Provider, with SSO and Two-Factor Authentication enforced through Harness or your IdP.
Advanced Role-Based Access Control gives granular control over what users and service accounts can do across the platform.
A comprehensive, out-of-the-box Audit Trail at the account and organization levels captures every event and change in the platform.
The Harness Delegate runs in your environment to connect internal systems to the platform — over a secure WebSocket connection protected by TLS.
A built-in Secrets Management solution on top of GCP KMS stores the secrets used in your account, pipelines, and connectors securely and conveniently.
We build on hardened images and ship a vetted ‘safe image’ — third-party dependencies sourced from trusted resources, with relevant OS hardening applied.
Reporting Security Issues
If you believe you’ve discovered a critical security bug or vulnerability affecting our products or services, email security@harness.io. We ask that you not publicly disclose the issue until we’ve had a chance to address it.
Interested in our private bug bounty? Reach out with your preferred email address.