Third Party Index

Snapshot 22314

Document
Security page
URL
https://www.harvey.ai/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
336820 bytes
SHA-256 (raw)
629d5b12214717413688fb033576519591736ebc60fdbe40efed49e09ba9eba7
SHA-256 (normalized text)
e66e76be6105b0efd23b0b38c1a34bf9706a93fd8e7c1f305b8eb13b757eba5f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Overview
A unified view of how Harvey's products work together to support your entire practice.
Agents
Purpose built agents execute complex legal work end to end.
Vault
Securely store, organize, and bulk-analyze legal documents.
Knowledge
Research complex legal, regulatory, and tax questions across domains.
Spaces
Work with legal teams across organizations in secure, shared spaces.
Command Center
Analytics, benchmarking, and agentic insights to lead their organization’s AI transformation
Contract Intelligence
Surface insights, strengthen negotiations, and accelerate reviews.
Horizon Scanning
Track, assess, and take action on regulatory changes.
Harvey Mobile
Get up to speed, capture new information, and keep work moving from anywhere.
Ecosystem
Access Harvey where you already work and ground every answer in sources you trust.
Introducing MemoryNew
Your preferences carried across Harvey so every response comes back consistent with how you work.
Innovation
Scale expertise and impact to drive firmwide transformation.
Litigation
Reduce manual effort, prioritize strategy, and drive stronger outcomes in litigation.
Transactional
Accelerate due diligence, contract analysis, and review with precision and control.
In-House
Streamline work and shift focus to strategy and speed.
Law Firms
Deliver your firm's best work on every matter, with more time for clients.
Mid-Sized Firms
Drive outsize impact with tools built for lean teams.
A New Era of Collaboration for Legal and Professional Services
Law firms and professional service networks have been using Harvey to build new service models and add value collaboratively.
Customers
Security
Blog
Product updates, insights, and behind-the-scenes from the Harvey team.
Resources Hub
The latest videos, webinars, guides, and reports from Harvey.
Press Kit
Resources for maintaining a uniform and professional presentation of the Harvey brand.
Research
Models, benchmarks, and field notes from Harvey's research on the frontier of legal AI.
ROI Calculator Law Firm
See Harvey's Impact on Your Firm.
ROI Calculator In House
See Harvey's Impact on Your Business.
Harvey Academy
Introducing Harvey Academy: on-demand training, expert workflows, and step-by-step guidance to help legal teams get the most out of Harvey.
About
Who we are and what we're building.
Careers
Join our team and help Harvey shape the future of professional services.
Newsroom
Press releases and partnership announcements.
2025 Year in Review
In 2025, we celebrated major customer wins, introduced product breakthroughs, and expanded our global presence. Most importantly, we continued to deepen our commitment to building the best AI solutions for our customers.
Request a Demo
US
EU
AU
For the Most Sensitive Matters
Harvey keeps your client data safe with world-class security and data privacy measures.
Explore Security Portal
Enterprise-Grade Protection
Purpose-Built Security
Harvey's in-house security team spans infrastructure, product, and operations, delivering 24/7 monitoring alongside enterprise-grade controls, including SAML SSO, audit logs, IP allow-listing, and data lifecycle management.
Data Sovereignty and Control
With Harvey, you retain full control over your data. Decide which data to upload, set retention policies, delete data anytime, and keep everything in-region—EU or Switzerland, US, or Australia.
No Model Training
Harvey contractually guarantees through our Platform Agreement that your data stays yours. We don’t use inputs, outputs, or uploaded documents to train underlying models.
Ethical Walls Enforcement
Harvey syncs and enforces your firm’s existing ethical wall policies, blocking restricted users from accessing or sharing walled content across Harvey. Harvey never creates, modifies, or deletes walls, ensuring that your walls provider remains the system of record.
Enforceable Commitments
Harvey’s Security Addendum includes binding terms on data protection, data access, incident response SLAs, and other controls aligned with SOC 2, ISO, GDPR and other standards. Our commitments are auditable, enforceable, and built to exceed standard vendor terms.
Independently Tested
Harvey partners with top-tier security firms, including Schellman, NCC Group and Bishop Fox, to perform in-depth audits. This offers external validation that Harvey meets the highest standards of resilience.
Enterprise-grade security and controls
Harvey is built on a non-negotiable principle: protecting the security and confidentiality of our customers' data. We've designed our platform from the ground up to safeguard the most sensitive information.
Explore Security Portal
SOC2 IIDetails
CCPADetails
GDPRDetails
AIUC-1Details
ISO 27001Details
ISO 27701Details
ISO 42001Details
Security is Fundamental to Everything We Do
We’ve built a comprehensive system that protects data at every level—from robust user authentication to vigilant network monitoring. Our approach combines cutting-edge technology with rigorous protocols, ensuring that information remains secure in an ever-changing digital landscape. We constantly test and improve our defenses, staying ahead of potential threats to maintain the trust our clients place in us.
Explore Security Portal
Harvey defines “customer data” as documents uploaded into the application by customers of Harvey. This does not include queries or responses. We define “customer content” as queries provided by a user to Harvey and corresponding responses from Harvey. This does not include the raw uploaded documents, but model responses may be derived from uploaded documents. While these are separate terms defined in Harvey’s legal contracts and service agreements, in most cases we talk about customer data and content together.
Harvey encrypts all data at rest and in transit, uses strong access controls, and, by default, never trains on customer data. Harvey undergoes annual SOC 2 Type II and ISO 27001 audits to validate these controls. Additionally, Harvey passes on these obligations and contractual security commitments to subprocessors and external model providers. Customer data for each customer is logically separated to prevent any commingling of data between customers and Harvey implements strict access controls following the principle of least privilege.
Harvey hosts its cloud environment in Microsoft Azure. For customers with requirements or preferences for data localization we offer processing in the EU and Switzerland or Australia. This applies to Harvey subprocessors as well.
Harvey enforces strict role-based access controls and logical workspace separation to ensure that only authorized users can access specific customer data. Customers can determine what data to upload to Harvey, how long it is retained, and whether that data can be shared with others within the company.
Harvey contractually prohibits model providers from training on customer data and only uses your data for processing your requests, not for model improvement. Harvey requires Zero Data Retention (ZDR) by model providers.
Yes, but only if you explicitly request it. In that case, a bespoke model is created exclusively for you, and your data is never used to train models used by other customers.
Harvey conducts automated vulnerability scans, annual third-party penetration tests, and maintains continuous security monitoring.
Secured by a World-Class Team
Security by Design: How Harvey Engineered Trust from Day One
May 29, 2025•Blog
How Harvey’s Building a Culture of Privacy
August 19, 2025•Blog