Harbor runs your Privateer agent in a confidential cloud — not on your laptop.
Always on and reachable from your phone or the web, designed to carry your tools, credentials, and scheduled routines with it — running inside a hardware enclave we can't read into. Included on Navigator and above.
Preview · waitlist — the hosted runtime isn't live yet
Opt-in · Navigator and above · AMD SEV-SNP confidential VM · same agent as the open-source CLI
Most people don't want to babysit a terminal. Harbor runs the same Privateer agent on our infrastructure, so it's there when you are — answer a question from your phone on the train, let a routine run at 2am, pick the thread back up on the web an hour later. You talk to it; it does the work.
What Harbor is for
The Harbor screen, the waitlist, and the attestation client are in the app now. The hosted runtime is not: no agent runs on Privateer infrastructure yet, hosted agents carry no MCP connectors during the preview, and capabilities land progressively as the confidential-VM fleet comes online. The list above is the shape of the product, not a claim about what runs today.
Harbor isn't a different product from the Privateer CLI — it's the same agent, hosted. The only real question is whose computer it runs on, and that's a trade you should make with your eyes open.
| Privateer CLI | Harbor | |
|---|---|---|
| Runs on | Your machine — macOS, Linux, Windows | Privateer infrastructure, inside a confidential VM |
| Available when your laptop is closed | No | Yes — that's the point |
| Who can read your content | Only you — nothing executes on our servers | Processed in our cloud, inside an enclave we can't read into |
| Cost | Free, MIT licensed, open source | Included on Navigator and above |
| Available now | Yes — one command to install | No — preview, waitlist only |
Everywhere else in Privateer, your content is only ever ciphertext on our servers. Harbor is the one place it gets processed in our cloud — by design, because that's what a hosted agent is. So the claim we make is narrow and checkable: we can't read into the attested enclave. Not "we can't process it." Anyone who tells you otherwise about a hosted agent is overclaiming.
A Harbor agent runs inside an AMD SEV-SNP confidential VM. Plaintext is decrypted and processed only inside that enclave — the cloud operator, meaning us, cannot read into it.
The app verifies the enclave's code measurement and identity key before it will drive the agent, and full on-device verification of AMD's certificate chain runs in the native Android app rather than trusting our server's word for it.
Between-user isolation on a shared host is Linux namespaces and rootless containers — not per-user hardware. The enclave protects you from us; a container escape would be cross-tenant exposure. It's on the risk register, not swept under it.
Harbor is off unless you turn it on, and it changes nothing about the rest of Privateer. The app and the CLI keep your content encrypted and keep agent work on your own machine.
We'd rather tell you this plainly than let a marketing page imply something that isn't running yet.
No agent runs on Privateer infrastructure today. The Harbor screen in the app lets you join the waitlist and nothing more; there is no live enclave, so there is nothing to attest yet.
When the confidential-VM fleet goes live, attestation turns on with it, and the privacy documentation flips at the same time — the in-app copy, the architecture doc, and our store review materials all move together, never ahead of the code.
In the meantime the same agent is free and running on your own machine today: install the Privateer CLI.
Straight answers, including the uncomfortable ones.
Harbor runs a Privateer agent on Privateer infrastructure instead of on your own machine, so it stays available when your laptop is closed. You talk to it from the Privateer app on Android or the web, and it's designed to carry your MCP servers, tools, credentials, and scheduled routines with it. It's included on the Navigator plan and above.
Not yet. Harbor is in preview and access is by waitlist — no agent runs on Privateer infrastructure today. The screen exists in the app so you can join the list, and capabilities land progressively as the confidential-VM fleet comes online.
Same agent, different machine. The Privateer CLI runs on your own computer — nothing executes on our servers, and you keep the terminal open. Harbor runs that agent for you in a confidential cloud so it's reachable without a laptop. If you'd rather host it yourself, the CLI is free, MIT licensed, and installs with one command.
Inside a hardware Trusted Execution Environment — an AMD SEV-SNP confidential VM — whose code measurement and identity key the app verifies before it will drive the agent. Plaintext is processed only inside that enclave, and the cloud operator (us) cannot read into it.
We state the limit plainly: Harbor is the one place where your content is processed in our cloud by design, so the honest claim is "we can't read into the attested enclave", never "we can't process it". Everywhere else in Privateer, your content is only ever ciphertext on our servers.
Between-user isolation on a shared host is software-enforced — Linux namespaces and rootless containers — not per-user hardware. The enclave protects your agent from us; it doesn't by itself protect one tenant from another, and a container escape would be cross-tenant exposure. That stays on our published risk register rather than being papered over.
That's the design: the app fetches an attestation report and checks that the enclave holding your session key is the one we claim, that the image measurement matches the published reference, that AMD's certificate chain verifies, and that the report is nonce-fresh. Full on-device verification of AMD's chain runs in the native Android app.
Today, though, Harbor is on a preview backend — there's no live enclave to attest yet. Attestation turns on when the confidential-VM fleet goes live.
Harbor is included on Navigator ($15.99/mo or $159.99/yr) and above — see pricing. Joining the waitlist is free and doesn't require a paid plan.
That's the launch design — a hosted agent that carries your MCP servers, tools, and platform credentials so it can actually do work rather than just talk. It isn't wired up yet: hosted agents hold no MCP connectors during the current preview. Treat it as the shape of the product, not a shipped capability.
Hosted routines run with a read-only safe toolset by default; anything beyond that has to be granted explicitly on the routine. The point is that an unattended run on our infrastructure shouldn't be able to take destructive action just because nobody was watching.
No. Harbor is opt-in and off unless you enable it. It changes nothing about the on-device model: the Privateer app and the CLI still keep your content encrypted and still run agent work on your own machine.
Join the waitlist and we'll tell you the moment Harbor is ready.