An Agent That Never Sleeps

Harbor runs your Privateer agent in a confidential cloud — not on your laptop.

Always on and reachable from your phone or the web, designed to carry your tools, credentials, and scheduled routines with it — running inside a hardware enclave we can't read into. Included on Navigator and above.

Preview · waitlist — the hosted runtime isn't live yet

Opt-in · Navigator and above · AMD SEV-SNP confidential VM · same agent as the open-source CLI

Close the Laptop. The Agent Keeps Working.

Most people don't want to babysit a terminal. Harbor runs the same Privateer agent on our infrastructure, so it's there when you are — answer a question from your phone on the train, let a routine run at 2am, pick the thread back up on the web an hour later. You talk to it; it does the work.

# from the Privateer app on your phone — no terminal open anywhere
> check whether last night's deploy is still healthy
harbor · running · ⛉ attested enclave
reading logs · checking error rate
healthy — error rate 0.02%, no restarts since 02:14
# and it keeps the schedule you gave it
next routine: "morning-digest" · 07:00 daily

What Harbor is for

Always on — no laptop Talk from phone or web Routines & schedules Your MCPs & tools Your API keys & credentials Runs in an attested enclave Zero data retention

What's actually built today

The Harbor screen, the waitlist, and the attestation client are in the app now. The hosted runtime is not: no agent runs on Privateer infrastructure yet, hosted agents carry no MCP connectors during the preview, and capabilities land progressively as the confidential-VM fleet comes online. The list above is the shape of the product, not a claim about what runs today.

Same Agent. Your Machine or Ours.

Harbor isn't a different product from the Privateer CLI — it's the same agent, hosted. The only real question is whose computer it runs on, and that's a trade you should make with your eyes open.

Privateer CLI Harbor
Runs on Your machine — macOS, Linux, Windows Privateer infrastructure, inside a confidential VM
Available when your laptop is closed No Yes — that's the point
Who can read your content Only you — nothing executes on our servers Processed in our cloud, inside an enclave we can't read into
Cost Free, MIT licensed, open source Included on Navigator and above
Available now Yes — one command to install No — preview, waitlist only

The Honest Version of "Confidential Cloud"

Everywhere else in Privateer, your content is only ever ciphertext on our servers. Harbor is the one place it gets processed in our cloud — by design, because that's what a hosted agent is. So the claim we make is narrow and checkable: we can't read into the attested enclave. Not "we can't process it." Anyone who tells you otherwise about a hosted agent is overclaiming.

# what the app checks before it will drive a hosted agent
attested key matches this agent
image measurement matches the published reference
AMD certificate chain verified on-device
report is fresh (nonce matches)
# today, on the preview backend:
▸ no live enclave to attest yet — turns on with the CVM fleet

⛉ Hardware enclave

A Harbor agent runs inside an AMD SEV-SNP confidential VM. Plaintext is decrypted and processed only inside that enclave — the cloud operator, meaning us, cannot read into it.

⛉ Attested, not asserted

The app verifies the enclave's code measurement and identity key before it will drive the agent, and full on-device verification of AMD's certificate chain runs in the native Android app rather than trusting our server's word for it.

Tenant isolation is software

Between-user isolation on a shared host is Linux namespaces and rootless containers — not per-user hardware. The enclave protects you from us; a container escape would be cross-tenant exposure. It's on the risk register, not swept under it.

Opt-in, and only here

Harbor is off unless you turn it on, and it changes nothing about the rest of Privateer. The app and the CLI keep your content encrypted and keep agent work on your own machine.

Where Harbor Actually Is

We'd rather tell you this plainly than let a marketing page imply something that isn't running yet.

Preview · waitlist

No agent runs on Privateer infrastructure today. The Harbor screen in the app lets you join the waitlist and nothing more; there is no live enclave, so there is nothing to attest yet.

When the confidential-VM fleet goes live, attestation turns on with it, and the privacy documentation flips at the same time — the in-app copy, the architecture doc, and our store review materials all move together, never ahead of the code.

In the meantime the same agent is free and running on your own machine today: install the Privateer CLI.

Questions, Answered

Straight answers, including the uncomfortable ones.

What is Privateer Harbor?

Harbor runs a Privateer agent on Privateer infrastructure instead of on your own machine, so it stays available when your laptop is closed. You talk to it from the Privateer app on Android or the web, and it's designed to carry your MCP servers, tools, credentials, and scheduled routines with it. It's included on the Navigator plan and above.

Is Harbor available yet?

Not yet. Harbor is in preview and access is by waitlist — no agent runs on Privateer infrastructure today. The screen exists in the app so you can join the list, and capabilities land progressively as the confidential-VM fleet comes online.

How is Harbor different from the Privateer CLI?

Same agent, different machine. The Privateer CLI runs on your own computer — nothing executes on our servers, and you keep the terminal open. Harbor runs that agent for you in a confidential cloud so it's reachable without a laptop. If you'd rather host it yourself, the CLI is free, MIT licensed, and installs with one command.

Where does a Harbor agent run, and who can read it?

Inside a hardware Trusted Execution Environment — an AMD SEV-SNP confidential VM — whose code measurement and identity key the app verifies before it will drive the agent. Plaintext is processed only inside that enclave, and the cloud operator (us) cannot read into it.

We state the limit plainly: Harbor is the one place where your content is processed in our cloud by design, so the honest claim is "we can't read into the attested enclave", never "we can't process it". Everywhere else in Privateer, your content is only ever ciphertext on our servers.

Are Harbor tenants isolated from each other?

Between-user isolation on a shared host is software-enforced — Linux namespaces and rootless containers — not per-user hardware. The enclave protects your agent from us; it doesn't by itself protect one tenant from another, and a container escape would be cross-tenant exposure. That stays on our published risk register rather than being papered over.

Can I verify the enclave myself?

That's the design: the app fetches an attestation report and checks that the enclave holding your session key is the one we claim, that the image measurement matches the published reference, that AMD's certificate chain verifies, and that the report is nonce-fresh. Full on-device verification of AMD's chain runs in the native Android app.

Today, though, Harbor is on a preview backend — there's no live enclave to attest yet. Attestation turns on when the confidential-VM fleet goes live.

What plan do I need for Harbor?

Harbor is included on Navigator ($15.99/mo or $159.99/yr) and above — see pricing. Joining the waitlist is free and doesn't require a paid plan.

Will Harbor use my MCP servers and API keys?

That's the launch design — a hosted agent that carries your MCP servers, tools, and platform credentials so it can actually do work rather than just talk. It isn't wired up yet: hosted agents hold no MCP connectors during the current preview. Treat it as the shape of the product, not a shipped capability.

What can a scheduled routine do on a hosted agent?

Hosted routines run with a read-only safe toolset by default; anything beyond that has to be granted explicitly on the routine. The point is that an unattended run on our infrastructure shouldn't be able to take destructive action just because nobody was watching.

Do I have to use Harbor?

No. Harbor is opt-in and off unless you enable it. It changes nothing about the on-device model: the Privateer app and the CLI still keep your content encrypted and still run agent work on your own machine.

Drop anchor.

Join the waitlist and we'll tell you the moment Harbor is ready.