AI security + agentic automation

Your business on autopilot. You, still in the pilot's seat.

Haarveena is a software factory for operations. Our agentic browser and Control Center automate the repetitive work on every computer in your company, while role-based facades, Scope Guard and a human in the loop make sure no agent ever does something you didn't intend.

  • Least privilege by default
  • Every action logged and explained
  • A kill switch on every agent
control-center · Corner Grocer + Marquee 8Live
14Agents online
1,284Tasks today
0Waiting for you
    Scope Guard active · Threat Shield on · kill switch armed
    Human in the loop
    Facade: Pricing agent
    Prompt injection blocked
    What Haarveena does

    Automation you can trust with the keys to the store.

    Most automation asks you to trust the AI. Haarveena is built the way security engineers build systems: least privilege, defense in depth, and a person with the final say on anything that matters.

    Automate

    A software factory for your operations

    Turn SOPs into agents that work inside the web apps and desktop software you already use, on every computer in the business.

    How the factory works
    Supervise

    Scope Guard and a human in the loop

    Every proposed action is checked against the agent's written scope. Anything outside it stops and waits for a person, with full context.

    Meet Scope Guard

    "The model proposes. Policy decides. You approve."

    The Haarveena rule

    Deterministic code, not the model's own judgement, has the final say on what an agent may do.

    Contain

    Role-based facades for every agent

    Each agent sees a facade of your business: only the data and tools its job needs. What it can't see, it can't leak or misuse.

    Try the Facade Explorer
    Defend

    Ready for agentic attacks

    Prompt injection, poisoned documents, rogue agents and AI bot swarms are detected, contained and explained in plain English.

    Launch the Threat Shield
    Amplify

    Data Alliances with other AI companies

    Bring specialist AI in for forecasting and analytics through governed data rooms. Partners see the facade you approve; you keep the business.

    Explore Data Alliances
    Try it · Autonomy Dial

    Turn the dial. See what agents may do on their own.

    Autonomy isn't all-or-nothing. Choose a level for each agent, and Haarveena sorts every action into runs on its own, asks you first, or can never happen. Drag the needle or tap a level.

    Autonomy levelTrusted

    Action · agentTierWhat happens
    Try it · Facade Explorer

    Every agent sees a facade of your business. Never the whole thing.

    Pick an agent and watch the business reshape around what it's allowed to know. Sample business: Corner Grocer, a two-store independent grocery.

    Full viewMasked or aggregatedNot in facade
    Agentic cybersecurity

    Attackers use AI agents now. So does our defense.

    When agents read your email, browse supplier sites and touch money, the attack surface changes. Haarveena was designed by security engineers for exactly this: every input is suspect, every action is checked, every agent is contained.

    Prompt injectionHidden instructions in emails, PDFs and web pages
    Quarantined
    Rogue or hijacked agentsPrivilege escalation and tool abuse
    Contained
    AI bot swarmsScalping, credential stuffing, fake accounts
    Throttled
    Data exfiltrationAgents tricked into sending your data out
    Denied
    The software factory

    Processes go in. Supervised agents come out.

    Every agent is built on the same line, with a quality gate at each station. Nothing reaches your business without passing shadow mode, a red-team attack and your sign-off.

    SOP inYour process, in plain words
    BlueprintGoal, tools, steps
    Facade + scopeWhat it may see and do
    Shadow modeSuggests while people work
    Red teamWe attack it first
    Your sign-offNothing ships without you
    LiveSupervised in production

    Each crate is a real process from our sample businesses, moving through the line.

    Estimate

    What would your team do with the time back?

    Move the sliders to match your business. We'll estimate the hours a supervised agent fleet could return each month.

    Estimated every month
    0hours returned to your team
    $0worth of team time
    0full-time people's worth of work

    A planning estimate, not a promise. Your pilot measures the real number on your own processes.

    Measure it in a pilot
    0%of agent actions logged with the reason they happened
    0out-of-scope actions executed without a human
    0 + 1permission tiers, plus one hard line no prompt can cross
    0 clickto stop every agent, from anywhere

    Design commitments every Haarveena deployment is built to keep.

    Platform

    One platform to automate, supervise and defend your operations.

    Seven building blocks that work together: the hands (agentic browser and desktop agents), the eyes (Control Center), the conscience (Scope Guard and facades), the factory that builds them, and the shield around it all.

    01 · Agentic Browser

    Works any web app your team uses. No API required.

    Supplier portals, POS back offices, carrier sites, ticketing systems, government forms. The agentic browser reads pages like a person and acts like a careful one.

    • Secrets stay secret. Passwords are filled from your vault at the field level; the model never sees them.
    • Web pages can't give orders. Instructions found on a page are treated as data, never as commands.
    • Every click has a receipt. Sessions are recorded step by step for replay and audit.
    • Stays in its lane. Each agent may only visit the sites on its allowlist.
    portal.valleyfarms.example/orders/newAgent driving
    New purchase order · Valley Farms
    Order total $1,240.40Within the $1,500 scope
    02 · Control Center

    Every agent, on every computer, in one place.

    Desktop agents run on the front-office PC, the registers, the warehouse terminal and the manager's laptop. The Control Center shows what each one is doing and gives you a stop button for all of them. Click a computer to inspect it.

    8 computers across 3 businesses · 0 tasks finished
    Accessibility-firstDesktop agents read apps through the operating system's accessibility layer, not screenshots: faster, more precise, and nothing sensitive leaves as an image.
    Shadow modeNew agents suggest while your people work, until their track record earns more autonomy.
    Take over anytimeGrab the wheel mid-task. The agent pauses, you finish, and it learns from what you did.
    Deploy your wayOur cloud, your private cloud, or fully on-premises for sensitive sites.
    03 · Scope Guard

    Out-of-scope decisions stop and wait for you.

    Every agent has a written scope: its goal, its tools and its limits. Scope Guard checks each proposed action against that scope before anything happens, in deterministic code. The model never grades its own homework.

    • Spend caps, time windows, payee rules and data boundaries
    • A hard-coded denylist for irreversible operations
    • Confidence-gated escalation: unsure agents ask instead of guessing
    • Approve from your phone, with full context and an undo plan
    You are the human in the loop

    Approval queue

    1,284ran alone
    0approved
    0denied
    04 · Facades: RBAC for agents

    Each agent sees only a facade of the business.

    Classic role-based access control was built for people. Facades are built for agents: a filtered, masked and sometimes aggregated view of your business that contains exactly what one job needs.

    • Per-agent identities and credentials. No shared logins, ever.
    • Field-level masking and aggregation: "totals only", "last 4 digits".
    • No breadcrumbs: agents can't discover what's outside their facade.
    • Time-boxed elevation, and only with a human's approval.
    Open the Facade Explorer
    05 · Software Factory

    From a paragraph of SOP to a supervised agent.

    Describe how the work is done today. The factory drafts a blueprint: goal, tools, facade, limits and when to escalate. Your written scope becomes machine-checked policy, and the blueprint moves through shadow mode, red-teaming and your sign-off.

    • Blueprints are readable by the people who do the work
    • Versioned like code: every change reviewed and reversible
    • Logistics and operations templates to start from
    supplier-agent.blueprintSigned off
    agent: supplier-agent
    owner: store-manager@cornergrocer
    goal: "Keep produce and dairy above par"
    tools:
      - browser: valleyfarms portal
      - browser: sunrise-dairy portal
      - email: read-only
    facade: [inventory, suppliers, contracts:terms-only]
    scope:
      max_order_usd: 1500
      new_payees: never
      hours: "05:00-20:00"
    escalate_when:
      - order_total > 1500
      - confidence < 0.80   # unsure agents ask
    autonomy: trusted   # shadow → guided → trusted
    06 · Data Alliances

    Bring other AI companies in. Keep your business to yourself.

    Specialist AI for forecasting, vision or analytics can make your data far more valuable. Haarveena brokers governed data rooms: partners work against the facade you approve, every query is logged, and access is revocable in one click. It's also the safe way to integrate an AI company you partner with or acquire.

    • Aggregation and masking before anything leaves
    • Bring your own models and providers
    • Partner outputs come back through Scope Guard, like any agent
    Data room · Corner Grocer and a forecasting partner
    What the partner receives
    38 partner queries this week, all logged
    07 · Audit & Replay

    Every action comes with a receipt.

    Who did what, on which computer, with which data, and why. Replay any agent session step by step, undo reversible actions, and export evidence for your auditors.

    • Tamper-evident, append-only logs
    • A plain-English reason attached to every action
    • One-click undo for reversible changes
    • Exports for auditors, insurers and regulators
    Session replay

    Supplier agent · PO #4471

    1. Opened the Valley Farms portal on Front office PC
    2. Signed in with vault credential vf-orders (hidden from the model)
    3. Added Greek yogurt 32oz × 14 cases
    4. Scope check: $1,240.40 is under the $1,500 cap passed
    5. Payee check: known supplier, bank details unchanged passed
    6. Submitted order · confirmation PO #4471
    7. Reason logged: "Yogurt at 6 of 20 par before the weekend"
    Works where your team works

    If a person can do it on a computer, an agent can learn it.

    Any web appWindows appsmacOS appsLinux terminalsEmail and chatSpreadsheetsPOS systemsERP and accountingWarehouse systemsTicketingSupplier and carrier portalsHR and payrollREST and GraphQL APIsYour own AI models

    Haarveena Cloud

    The fastest start. Region of your choice, isolated per customer.

    Your private cloud

    Control Center and data plane inside your VPC. We never hold your data.

    On-premises

    For regulated or air-gapped sites. Agents and models run on your hardware.

    How it works

    The model proposes. Policy decides. You approve.

    From your first process map to a fleet of supervised agents: here is exactly what happens, and where you stay in control.

    process-map.mdStep 1 of 7
    01 · MAP

    We map how the work really happens.

    We sit with the people who do the work, or read your SOPs, and map each process: who does it, in which apps, with which data, and where money or customer trust is at stake.

    02 · BLUEPRINT

    The factory drafts an agent blueprint.

    Each process becomes a blueprint: the goal, the tools, the steps and a scope written in plain English. That scope compiles into machine-checked policy, so "never pay a new bank account" is enforced by code, not by hope.

    03 · FACADE

    Each agent gets its facade and its own identity.

    Least privilege by design. The agent gets exactly the data and tools its job needs, its own credentials that never enter the model's context, and an allowlist of the sites and apps it may touch.

    04 · SHADOW

    Shadow mode before the real thing.

    The agent proposes while your team keeps working. We measure how often it would have made the same call, and review every difference with you.

    05 · RED TEAM

    We attack it before anyone else can.

    Our security team throws prompt injection, poisoned invoices, payee swaps, tricky customers and rogue-agent scenarios at every blueprint. It doesn't ship until it holds.

    06 · GO LIVE

    Supervised production through the Control Center.

    Read actions run on their own, write actions come with undo, and Danger actions wait for you. Every agent has a pause button and a kill switch.

    07 · IMPROVE

    Every approval makes next week better.

    Your approvals and denials tune the policy. A weekly review shows hours returned, risks stopped and scope changes worth making, and the next process goes into the factory.

    Inside every decision

    Follow one action through Scope Guard.

    Pick something an agent wants to do. Watch it pass, or fail, each check in milliseconds, before anything touches your business.

    Proposed by
    Facade check
    Scope policy
    Risk tier
    Confidence
    Outcome
    Permission tiers

    Three tiers and one hard line.

    Every action an agent can take is sorted before it ever runs.

    Read

    Look, don't touch

    Reading reports, checking stock, pulling sales, watching queues.

    Default: runs on its own
    Write

    Change, with undo

    Drafting orders, updating schedules, sending approved templates.

    Default: runs with an undo plan, or asks, depending on the autonomy level
    Danger

    Money, access, the public

    Payments, new payees, refunds over limits, admin rights, anything customers see.

    Default: always waits for a verified human
    Out of scope

    The hard line

    Anything outside the facade, plus irreversible operations like bulk deletes.

    Default: never happens. No prompt can unlock it.
    Human in the loop

    When an agent needs you, it brings its homework.

    No cryptic alerts. Every request says what the agent wants to do, why, what it can see, how sure it is, and exactly how to undo it. Try the buttons.

    • Approve, deny, or edit and approve
    • Delegate approvals by role, amount or time of day
    • Out-of-band verification for payments: a voice note or an email is never an approval
    9:41Haarveena
    Needs you · Danger tier

    Supplier agent wants to place a $4,200 order

    Why
    Weekend promo; yogurt at 6 of 20 par
    Scope
    Cap is $1,500 per order
    Sees
    Inventory, supplier catalog, contract terms
    Confidence
    0.91
    Undo
    Cancel free until 2 PM today
    The 30-day pilot

    One month from first conversation to supervised production.

    1. Week 1

      Map and pick

      Two hours with your team. We map processes and pick the one or two that return the most time with the least risk.

    2. Week 2

      Build and attack

      Blueprints, facades and scopes. Our red team attacks every agent before it touches anything real.

    3. Week 3

      Shadow mode

      Agents propose, your team decides. We measure agreement and review every difference together.

    4. Week 4

      Go live and review

      Supervised production at the autonomy level you choose, plus a report on hours returned and risks stopped.

    Use cases

    Real businesses. Real days. Every decision accounted for.

    Pick a business and press play. Watch agents handle the routine, stop at the edge of their scope, and bring you the decisions that matter.

    Sample business

    Corner Grocer

    5:45 AM

      Sample businesses. Figures are illustrative, based on typical process times; your pilot measures real results.

      More places Haarveena fits

      If it runs on repeatable work, it runs better supervised.

      Restaurants

      Supplier orders, menu costing when prices move, reservations and review replies within your brand voice.

      Hotels

      Housekeeping boards, rate updates within your bands, guest requests routed to the right person.

      Clinics' front desks

      Scheduling, reminders and insurance pre-checks, with patient data kept inside strict facades.

      Warehouses

      Receiving, cycle counts, labels and replenishment across the WMS and the carrier portals.

      Pharmacies

      Inventory, refill reminders and supplier recall checks, with every Danger action held for a pharmacist.

      Property management

      Maintenance tickets, vendor dispatch and rent reminders, without an agent ever holding the master keys.

      AI security

      Agentic attacks are here. Haarveena was built to stop them.

      When AI agents read your email, browse supplier portals and move money, attackers stop targeting people and start targeting agents. We defend both: the agents we run for you, and the AI you already use.

      Threat Shield simulator

      Launch an attack. Watch where it dies.

      Five layers of defense sit between an attacker and your business. Pick an attack and follow it through.

      Attacker
      Input firewallInstructions in data stay data
      FacadeCan't reach what it can't see
      Scope GuardDeterministic policy
      Behavior monitorsAnomalies and model signals
      Human + kill switchVerified approvals only
      Your business
      Pick an attack on the left to begin.
      Attacks launched0Stopped0Simulation, for illustration
      The new threat model

      What we defend against.

      The OWASP Top 10 for LLM applications and MITRE ATLAS describe the landscape. This is how it shows up in a real business.

      Prompt injection

      Hidden instructions in emails, PDFs, web pages and reviews that try to steer an agent.

      Input firewall + Scope Guard

      Tool and permission abuse

      A hijacked agent tries to use its tools for something they were never meant for.

      Facade + denylist

      Data exfiltration

      An agent is talked into sending customer or financial data somewhere it shouldn't go.

      Facade + egress allowlist

      Memory and context poisoning

      Planted "facts" in documents or agent memory that bend later decisions.

      Provenance tagging

      Rogue or impersonated agents

      One agent pretends to be another, or asks a peer for credentials it shouldn't have.

      Per-agent identity

      Model and plugin supply chain

      Backdoored models, tampered plugins and poisoned fine-tuning data.

      Supply-chain scanning

      AI bot swarms

      Scalping, credential stuffing and fake accounts run by agents at machine speed.

      Behavior monitors

      Deepfake social engineering

      A cloned voice or look-alike email "from the owner" asking for an urgent payment.

      Verified human approval
      Security services

      We attack your AI before someone else does.

      Already running chatbots, copilots or agents from other vendors? Our team tests and hardens those too.

      AI red teaming

      An adversarial assessment of your LLM apps and agents.

      • Prompt injection and jailbreaks
      • Data exfiltration paths
      • Tool and permission abuse

      Agent security review

      Architecture review of agent permissions, secrets and blast radius.

      • Least-privilege redesign
      • Facade and scope proposals
      • Mapped to OWASP and ATLAS

      Continuous monitoring

      Threat Shield watching your AI systems around the clock.

      • Injection and anomaly alerts
      • Weekly risk digest
      • Kill switch integration

      AI incident response

      When an agent or model misbehaves, we help contain and explain it.

      • Containment within hours
      • Root-cause replay
      • Hardening plan
      Research

      We look inside the model, not just at what it says.

      Output filters only see the words. Our research uses interpretability, the study of what is happening inside a model, to catch trouble earlier.

      • Sycophancy. An agent that tells a manager what they want to hear is a security risk. We test for it, and flag reports that don't match the data.
      • Activation probes. For models we host, lightweight probes read internal signals that correlate with goal drift or deception.
      • Faithful reasoning. We check whether an agent's stated reasons actually drove its actions.
      Probe: goal drift
      Supplier agent · 16 layers × 7 steps
      Rising at layers 9 to 14
      layer 1layer 8layer 16
      quietstrong signal
      Trust practices

      How we protect you, and ourselves.

      Encryption everywhere

      TLS in transit and AES-256 at rest, with customer-managed keys on Enterprise.

      Secrets never meet the model

      Per-agent credentials live in a vault, are injected field by field, and rotate automatically.

      Least privilege for our staff

      No standing access to your systems. Support access is requested, approved by you, time-boxed and logged.

      Tamper-evident logs

      Append-only audit trails for every agent action and every human approval.

      Data residency

      US by default, other regions on request, or fully on-premises.

      Secure by construction

      Threat modeling for every feature, dependency and model supply-chain scanning, and independent penetration testing.

      Designed aroundOWASP Top 10 for LLM ApplicationsMITRE ATLASNIST AI Risk Management Framework
      Found a vulnerability? Email security@haarveena.com. We welcome responsible disclosure and reply within two business days.
      Plans

      Start small. Prove it. Then scale.

      Every engagement starts with a fixed-fee pilot, so you see real hours returned before you commit to anything bigger.

      Pilot
      30 days

      Fixed fee. One or two processes, fully supervised.

      • Process mapping workshop
      • Up to 2 automated processes
      • Control Center for up to 5 computers
      • Shadow mode and a red-team report
      • Weekly review with our team
      • 24/7 emergency stop line
      Book a pilot
      Most popular Business
      Per agent

      For businesses running their operations on supervised autopilot.

      • Everything in Pilot
      • Unlimited processes through the factory
      • Control Center for up to 100 computers
      • Scope Guard, facades and Threat Shield
      • Mobile approvals and delegation
      • Extended-hours support and chat
      Talk to us
      Enterprise
      Custom

      For multi-site operators and regulated industries.

      • Everything in Business
      • Private cloud or on-premises deployment
      • Data Alliances with partner AI companies
      • SSO, SCIM and customer-managed keys
      • A dedicated security engineer
      • 24/7 critical-issue response
      Contact sales
      Add-on, or on its own

      AI red team assessment

      A fixed-scope attack on the chatbots, copilots and agents you already run, with a prioritized fix list mapped to OWASP and MITRE ATLAS.

      Request an assessment

      Every plan includes

      A human on every Danger-tier action Tamper-evident audit logs A kill switch on every agent No training on your data
      Company

      We're building the safest way to hand real work to AI.

      Haarveena is an AI security and automation company based in Berkeley, California.

      Our mission is to make AI agents trustworthy enough to run real businesses, by building them the way security engineers build systems.

      The businesses that stand to gain the most from AI agents are the grocer, the neighborhood cinema, the regional freight company. They are also the ones least able to absorb an agent's mistake: one wrong payment, one leaked customer list, one hijacked inbox.

      So we started from security, not from automation. Every Haarveena agent works inside a facade, answers to a written scope, and hands the decisions that matter to a human. We attack our own agents before anyone else can, and we study what happens inside models so we can catch trouble before it reaches your business.

      The result is automation you can actually hand the keys to, because it never forgets whose keys they are.

      What we believe

      Six principles we build by.

      01

      Intent over autonomy

      An agent's job is to do what you meant, not whatever it can. When in doubt, it asks.

      02

      Least privilege, always

      Every agent, employee and partner sees only what the job needs. Including us.

      03

      Show your work

      Every action comes with a reason, a record and, wherever possible, an undo.

      04

      Attack ourselves first

      Nothing ships until our own red team has tried, and failed, to break it.

      05

      Humans hold the pen

      Payments, access and anything your customers see always carry a person's name.

      06

      Warm, plain-spoken help

      Real people who explain things simply, and a stop button that always works.

      L
      Founder

      Lokesh L K S

      Founder · Security engineering and AI safety
      M.S. Cybersecurity Analytics, Penn StateM.S. Information Technology, Anna UniversityCCNASecurity+

      Security engineer and AI-safety researcher. His research looks at how language models fail, including sycophancy and interpretability of model internals, and his background spans platform engineering and security engineering. Haarveena brings those threads together: automation that is secure by construction.

      Careers

      Help us build automation people can trust.

      We're assembling a small founding team in the Bay Area. If you've broken AI systems, built automation that survives real operations, or run the operations yourself, we'd love to hear from you.

      Our mark

      Half human, half machine. One tree.

      The left half of the crown is drawn by hand: uneven and alive, like the people we build for. The right half is one perfect arc, like the agents working beside them. Both grow from a single trunk, an H that branches into a V. Click a color to copy it.

      HaarveenaHaarveena logo on blue: a round tree crown split down a straight line, the left half a turbulent hand-drawn yellow half circle (people), the right half a perfect white half circle (AI), on a dark ink H-shaped trunk whose stems curve into a V of branches, standing on a dot-dash line.
      App icon
      Favicon
      FAQ

      Questions, answered plainly.

      Everything people usually ask before handing work to an agent. Can't find yours? Ask a human.

      Support

      Real people. Fast answers. A stop button that always works.

      Help center

      Guides, answers and best practices for scopes, facades and approvals.

      Browse answers

      Email support

      support@haarveena.com. A person replies within one business day on every plan.

      Write to us

      Emergency stop

      Something looks wrong? Stop every agent from the Control Center, the mobile app or our 24/7 line. Ask questions later.

      Support plans

      Response times you can plan around.

      FeaturePilotBusinessEnterprise
      Emergency stop line24/724/724/7
      Critical issue response4 hours1 hour30 minutes
      General questions1 business day4 business hours2 hours
      Support hoursBusiness hoursExtended, 7 days24/7
      ChannelsEmailEmail and chatEmail, chat, phone and a shared channel
      Named contactsPilot leadSuccess managerSuccess manager and a security engineer
      System status

      All systems normal.

      Live status for every Haarveena service, with incident history and alerts for your team.

      Sample status board, for illustration.

      Contact

      Tell us about your business.

      Book a pilot, ask about AI red teaming, or just ask a question. A person, not an agent, reads every message.

      We reply within one business day. No spam, ever.

      Hand off the busywork. Keep the keys.

      Start with one process, one month, and a human in the loop on every decision that matters.