Harbor
In productionAgent runtime
A self-hosted runtime for agents that are allowed to touch real systems.
Harbor runs agent workloads inside a sandbox with explicit tool permissions, full request tracing and an immutable audit log. It is what we deploy when a client needs an agent inside their own network and their security team needs to read every action it took.
- Per-tool permission grants with human approval steps
- Immutable audit log for every tool call and model response
- Deploys into a client VPC with no outbound data path by default
