Last updated: 1 June 2026
HARRIS is operated by Horizon Frame Limited and built on Cloudflare's global edge platform. This page summarises the controls we use to protect customer data, including data we receive from Google, Meta, Shopify, and the other third-party platforms users connect to HARRIS.
harrishq.ai, terminated at the Cloudflare edge. HTTP Strict Transport Security is enabled on all responses (max-age=31536000; includeSubDomains).HttpOnly; Secure; SameSite=Strict cookies. Access tokens expire after 2 hours; refresh tokens after 30 days and are path-scoped to /api/auth.X-API-Key header.X-Robots-Tag: noindex.CREDENTIAL_ENCRYPTION_KEY) is stored as a Cloudflare Worker secret, never in source control.website_id and (where applicable) organisation_id. Every query that returns user data joins through a scoping helper that enforces the caller's accessible websites.orders/create, GitHub events, Meta deauthorisation callbacks) are verified with constant-time HMAC checks against the signing secret captured at register-time, before any payload processing.X-Telegram-Bot-Api-Secret-Token) verified on every request.webhook_subscriptions; deregistration on disconnect removes them.All HTTP responses include:
Strict-Transport-Security: max-age=31536000; includeSubDomainsX-Content-Type-Options: nosniffX-Frame-Options: DENYReferrer-Policy: strict-origin-when-cross-originPermissions-Policy: camera=(), microphone=(self), geolocation=() — microphone is permitted only for same-origin Conductor voice input; camera and geolocation are denied.Content-Security-Policy that restricts scripts and connections to the same origin.AI tool calls are governed by a tiered confirmation model. Low-risk read tools execute silently; any tool that writes to a third-party platform, sends email, posts content, merges code, or moves money requires either an interactive user approval or a pre-authorised scheduled task. Generated marketing campaigns are created in a paused state by default — they cannot spend money without explicit activation.
HARRIS runs automated daily retention enforcement. The retention schedule is published in our Privacy Policy (section 6) and instructions for requesting deletion are on the Data Deletion page. Disconnecting an individual platform removes its credentials immediately; deleting an account removes all account-scoped data.
If you discover a vulnerability in HARRIS, please report it to security@harrishq.ai. We commit to acknowledging reports within two business days and to working with researchers in good faith. Please do not test against other users' data; use a HARRIS account you control.
For Google's restricted Gmail scope (gmail.modify), HARRIS undergoes the CASA security assessment required by Google's API Services User Data Policy and renews it annually. Our handling of Google user data is described in section 14 of the Privacy Policy. UK GDPR data-subject requests are handled within 30 days (see Privacy Policy section 7).