Security

Secure controls for agent spend

Harpd can block a payment without ever holding funds or private keys. Tenant isolation, signed evidence and least privilege keep the control path reviewable.

About this page

How to use this page

  • Read the six security pillars — non-custodial, encryption, SSO / RBAC, signed audit, monitoring, and SOC2.
  • Use Report an issue to email security@harpd.com with a vulnerability.
  • Open the FAQ for audit, hosting and disclosure details.

What you'll find here

  • Security control cards, a vulnerability-disclosure section, and a FAQ.

Non-custodial

We never hold funds or private keys. Compromise of Harpd can't move your money — only your metadata.

Encryption in transit & at rest

TLS 1.2+ everywhere; data encrypted at rest on Cloudflare's edge and D1 storage.

SSO & RBAC

SAML / OIDC and role-based access on Team and Enterprise. Least-privilege by default.

Signed audit trail

Every approval writes an immutable, signed entry you can export as verifiable evidence.

Continuous monitoring

Real-time anomaly detection across our own infrastructure and your payment events.

SOC2 readiness

Our control program is being prepared for an independent SOC 2 Type II audit. Audit evidence and attestations will be shared after completion.

Vulnerability disclosure

Found something? Email security@harpd.com. We acknowledge within 2 business days and keep you posted through resolution.

Frequently asked questions

Is Harpd custodial?
No. Harpd is non-custodial — it never holds funds or private keys, so a breach of Harpd cannot move your money, only your metadata.
How is my data encrypted?
All traffic uses TLS 1.2+, and data is encrypted at rest on Cloudflare's edge and D1 storage. Access is least-privilege by default.
Where is Harpd hosted?
Harpd runs on Cloudflare's global edge (Workers + D1). There are no standalone long-lived servers for attackers to target.
Has Harpd been audited?
Harpd is preparing its SOC 2 Type II control program. An independent report will be shared only after the audit is complete; we do not represent the audit as completed today.
How do I report a vulnerability?
Email security@harpd.com. We acknowledge within 2 business days and keep you updated through resolution.