Security

Last updated: 1 June 2026

HARRIS is operated by Horizon Frame Limited and built on Cloudflare's global edge platform. This page summarises the controls we use to protect customer data, including data we receive from Google, Meta, Shopify, and the other third-party platforms users connect to HARRIS.

1. Infrastructure

2. Authentication and session security

3. Credential and secret handling

4. Multi-tenant isolation

5. Webhook verification

6. AI providers and PII handling

7. Response security headers

All HTTP responses include:

8. Action tiering

AI tool calls are governed by a tiered confirmation model. Low-risk read tools execute silently; any tool that writes to a third-party platform, sends email, posts content, merges code, or moves money requires either an interactive user approval or a pre-authorised scheduled task. Generated marketing campaigns are created in a paused state by default — they cannot spend money without explicit activation.

9. Data retention and deletion

HARRIS runs automated daily retention enforcement. The retention schedule is published in our Privacy Policy (section 6) and instructions for requesting deletion are on the Data Deletion page. Disconnecting an individual platform removes its credentials immediately; deleting an account removes all account-scoped data.

10. Vulnerability reporting

If you discover a vulnerability in HARRIS, please report it to security@harrishq.ai. We commit to acknowledging reports within two business days and to working with researchers in good faith. Please do not test against other users' data; use a HARRIS account you control.

11. Compliance and assessments

For Google's restricted Gmail scope (gmail.modify), HARRIS undergoes the CASA security assessment required by Google's API Services User Data Policy and renews it annually. Our handling of Google user data is described in section 14 of the Privacy Policy. UK GDPR data-subject requests are handled within 30 days (see Privacy Policy section 7).

12. Contact