The trust and governance layer for your AI software factory.
Make every coding agent across your org follow the standards you set, so your team ships faster and every change meets your bar for security, policy, and quality.

The operating layer for your software factory.
Consistent standards across every agent
Every agent, in every repo, inherits your standards by default. Your engineering policies, regulatory requirements, and security controls are enforced on every run and stay consistent as you scale.
GovernanceFaster time to merge
Agents run your verification gates on every change, before they open a pull request. Work reaches reviewers already verified, so review is faster and changes merge sooner.
VelocityA team that works like your best
See how your most effective engineers work with agents, then make those patterns the default for everyone.
EnablementA clear return on your AI spend
HAR HQ ties every ticket to the AI spend behind it. You can show what a budget delivered and forecast the next one.
EconomicsEvery change is verified before the PR opens.
Define the verification gates every agent must pass before it opens a pull request. Work reaches reviewers already verified, so review is faster and changes merge sooner.



Know exactly what your AI spend delivered.
Every dollar of AI spend is tied to the work that produced it, so you can prove the return and plan the next budget.



Turn your power users' habits into the team default.
See how your most effective engineers work with agents, then make those patterns the default for everyone.



Ask your software factory anything.
Ask why a pass rate dropped, where spend is going, which repos are failing, or how your team works with agents, all in plain English.
Three steps from local harness to org-wide control.
Keep the harness you have
HAR HQ reads the same .har/ contract in your repo. Nothing about how your agents run changes.
Connect your workspace
Point the harness at your org workspace. Runs, gates, proof, and cost start syncing as they happen.
Set your standards
Define required gates, budgets, roles, and alert thresholds once. Every repository and every agent inherits them by default.
Profiles and plugins for the way your team ships.
An open core you fully control.
HAR is open source under Apache-2.0 and lives in your repo. HAR HQ adds an organizational layer on top, and you keep full ownership of the harness with no vendor lock-in.
The open harness your engineers already run, on their own machines and CI.
Everything in the open core, plus the layer an organization needs to govern it.
- ✓Isolated slots and worktrees
- ✓Deterministic validation gates
- ✓Evidence trail per run
- ✓Local Mission Control
- ✓Plugins and custom stages
- +Shared org workspaces and roles
- +RoAI attribution down to the ticket
- +Proof and funnel analytics at scale
- +Budget and failure alerts
- +SSO, SAML, and audit trail
- +Self-hosted or VPC deployment
Every coding agent reads it the same way.
Your real checks, run the same way every time.
The harness stays in your repo, and you own it.
Run HAR HQ in our cloud or your own.
- ✓Fastest to start, nothing to run
- ✓Managed upgrades and backups
- ✓SSO and SAML
- ✓Runs in your own cloud account or VPC
- ✓SSO, SAML, and SCIM
- ✓Audit retention, DPA, and named support
Security, access, and audit under your control.
Deploy in your own cloud or VPC, connect your identity provider, and keep an audit trail on every run. HAR HQ meets the security, compliance, and procurement requirements large organizations set.
Keep code in your environment
Agents run on your own machines, CI, or cloud, so only run metadata reaches HQ.
Run it in your own cloud
Deploy HQ in your own cloud account or VPC, so your data lives where your policies require.
SSO and SAML
Connect your identity provider so your team signs in with accounts you already manage.
Role-based access control
Owner, Admin, and Member roles, so people see only what they should.
Audit trail on every run
Every run records who triggered it, what it checked, and the exact tree it validated.
Encryption in transit and at rest
Every connection is encrypted, and your run metadata is encrypted at rest.
Simple pricing, from small teams to enterprises.
Run the open harness at no cost. Add the HAR HQ layer when your team needs shared standards, RoAI, and governance across every repo.
Run the harness yourself, on your own machines and CI.
The hosted layer for your whole team, across every repo.
Self-hosted in your cloud, with enterprise compliance and controls.
Questions from engineering and security teams.
Does our source code leave our environment?+
That is your choice. Run agents on your own machines and CI and your source never leaves. Or run them in HAR HQ cloud sandboxes, which are isolated per run, encrypted, ephemeral, and never retained or used for training. Either way, HAR HQ stores only run metadata long-term, including stages, durations, cost, and tree hashes.
How is this different from the open-source HAR?+
HAR HQ is the team edition built on the same Apache-2.0 core. The harness, gates, and contract are identical. HQ adds org workspaces, cost attribution, analytics, roles, alerts, and SSO.
Can we self-host?+
Yes. Enterprise deployments run in your own cloud account or VPC, so your data lives where your policies require.
Which coding agents are supported?+
Any agent that reads the .har/ contract, including Claude Code, Cursor, Codex, and any MCP agent. One profile covers them all.
What do we need before we start a trial?+
A repository with a .har/ profile. Runs happen on your own machines and CI, or in HAR HQ Cloud sandboxes, so most teams connect their first workspace the same day.
How do cloud credits work?+
Pro and Team include a monthly cloud credit balance per user that covers hosted agent runs and sandbox time. If you run entirely on your own machines and CI, you may never touch them. Heavier cloud usage beyond the balance is billed as you go, and Enterprise runs in your own cloud and is billed by contract.
Where are you on compliance?+
SOC 2 Type II is in progress. Encryption in transit and at rest, RBAC, and per-run audit trails are available today, and the open core is fully auditable.
What is RoAI, and how do you attribute it?+
RoAI is the return on your AI spend. HAR HQ ties every ticket to the runs and models behind it, so you can report what a budget delivered and forecast the next one.
How does HAR HQ lower time to merge?+
Agents run your verification gates on every change, before they open a pull request, so work reaches reviewers already verified and review is faster.


