Harness Trust Center

Start your security review
View & download sensitive information
Ask for information
Search items
ControlK

Overview

Welcome to Harness's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

Harness partners with Very Good Security, Inc. (“VGS”) and Stripe, Inc. to capture, transfer, and store sensitive cardholder data.

VGS provides Harness and other financial institutions with managed data security services including tokenization as well as secure and compliant routing and storage of sensitive cardholder data. VGS eliminates the need for Harness to hold sensitive data by decoupling and insulating customer systems and applications from sensitive data. Data collected via VGS is segmented, aliased, and stored in secure vaults until needed.

Harness has been through rigorous vetting and inspection by VISA’s and MasterCard’s teams to ensure all data we receive is captured, transferred, and stored securely.

Risk Profile

Data Access LevelRestricted
Impact LevelLow
Recovery Time Objective24-48 hours
View more
Start your security review
View & download sensitive information
Ask for information

Harness is reviewed and trusted by

Visa-company-logoVisa
Mastercard-company-logoMastercard
Very Good Security-company-logoVery Good Security
Stripe-company-logoStripe

Documents

Other Reports
PCI DSS
Security Whitepaper
Cyber Insurance

Product Security

Data Security
Multi-Factor Authentication
Service-Level Agreement

Reports

Other Reports
PCI DSS
Security Whitepaper

Self-Assessments

We are working on our security compliance. We can provide completed questionnaires upon request.

Data Security

Access Monitoring
Backups Enabled
Encryption-at-rest
View more

App Security

We take application security seriously and are putting together a program to monitor internal apps.

Data Privacy

Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.

Access Control

Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.

Infrastructure

Amazon Web Services
BC/DR
Infrastructure Security
View more

Endpoint Security

We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request.

Network Security

Firewall
IDS/IPS
Traffic Filtering
View more

Corporate Security

Employee Training

Policies

We are currently working with experts to put together our company policies. Please contact us for more details.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

If you think you may have discovered a vulnerability, please send us a note.

Powered bySafeBase Logo