Topics / security review process

Attributed viewpoint

Security review precedes launch and covers core threat scenarios

Before a connector launches, Harvey's security team reviews it against threat scenarios including prompt injection, misuse of write capabilities, credential compromise, cross-tenant leakage, and supply-chain risk; at runtime, each tool call must still pass permission and policy checks.

Behind the viewpoint

Translations are for reading; original excerpts remain the evidence.

How We Built Harvey’s Connector Library

Original excerpt

Connector security starts before a tool reaches users and continues when the agent calls it. Before launch, our security team reviews threats such as prompt injection, misuse of write capabilities, credential compromise, cross-tenant leakage, and supply-chain risk. At runtime, each call must still pass the applicable permission and policy checks.