HarnessRouter
HarnessRouter sells embedded infrastructure for running third-party agent harnesses - Codex, Claude Code, Hermes and others - in isolated per-task sandboxes behind a single API, so a customer product can send a task and get back finished work such as videos, games, codebases or documents. The harness and model are named in config and swappable with a one-line change, and requests go to whichever model provider and credentials the customer configures. It is offered both as a managed Cloud service and as a self-hosted Apache 2.0 Community Edition in which runtime and application state stay in the customer environment. Agent work is metered from $0.014 per active work minute with waiting for model responses unbilled, and plans start at $20 per month applied as usage. The company publishes Y Combinator backing and names Stanford Medicine as a launch partner. On the assurance questions this index scores, the published record is thin. Every session runs in its own isolated sandbox, which bounds blast radius, but no scope, spend or authority limit on the agent itself is published. The only record of agent activity is an execution trace streamed to the calling application, with no stated retention period and no tamper-evidence. No certification, carrier, cover limit or customer indemnity is named anywhere in the capture. Currency note - this page was substantially rewritten between the 2026-09-04 and 2026-09-11 captures, which added the Apache 2.0 Community Edition and dropped the per-minute rate. Eight fields, the two pricing fields among them, still cite the earlier capture and are marked as dated where the newer capture no longer carries the wording. Re-extraction against the newest capture is pending with the Researcher.
23 fields evidenced · 36 with no public information. Every value below links to the document it came from and the date we checked it.
1 of those is flagged for review: our own check found language in the cited source that may address the field. An editor has not adjudicated it yet.
8 of the evidenced values quote wording our own later capture of the same page no longer contains. Marked below, awaiting an editor.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
The vendor states every session runs in its own isolated sandbox. That is run-time execution isolation, which bounds blast radius, but no scope, spend or authority limit on the agent itself is published.
Judged Sep 7, 2026; evidence newer. We have since re-read Permission scopes, most recently on Sep 11, 2026. No one has re-scored this dimension against it — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Is there a tamper-evident record of what it actually did?
The vendor states the integrating application can receive task status, generated artifacts, errors and an execution trace for each task, which is a retrievable record of agent activity. The judged score of 0 recorded on 2026-09-07 read no record at all, which was correct for the 2026-09-04 capture it cited but went stale when the 2026-09-11 capture added this text. It scores 1 rather than higher because the trace is delivered to the caller as a product feature with no stated retention period, no tamper-evidence and no hash-chaining, and the word audit does not appear anywhere in the capture.
Counts Audit trail, each cited below.
How this gap gets closed →Are compliance obligations attached per engagement?
No public evidence found: no certification or regulatory framework is named, a notable absence for infrastructure named as used by Stanford Medicine.
Judged Sep 7, 2026; evidence newer. We have since re-read Compliance certifications and Regulatory alignment, most recently on Sep 11, 2026. No one has re-scored this dimension against them — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Does payment depend on a verified result?
The vendor bills agent work per active work minute and states waiting for model responses is free. Billing is metered to work actually performed rather than wall-clock or seats, but payment is not conditioned on a verified outcome.
Judged Sep 7, 2026; evidence newer. We have since re-read Outcome-based pricing and Settlement mechanism, most recently on Sep 11, 2026. No one has re-scored this dimension against them — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found: no carrier, cover, limit or customer indemnity is published.
Judged Sep 7, 2026; evidence newer. We have since re-read Insurance available, Insurance carriers, Coverage limits and Indemnification, most recently on Sep 11, 2026. No one has re-scored this dimension against them — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Assurance
- Insurance available
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Own liability cover
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Insurance carriers
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Coverage limits
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Indemnification
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Liability cap
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Audit trail
- Each task execution produces a trace with progress, status, artifacts and errors that the integrating application can retrieve.
“Your application can receive streamed progress and events, task status, generated files and artifacts, the final result, errors, and execution trace.”
harnessrouter.ai · checked Sep 11, 2026 - Tamper-evident log
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Explainability
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Runtime governance
- Enforces a separate isolated sandbox per agent session/run
“Every session runs in its own isolated sandbox.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Permission scopes
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Compliance certifications
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Regulatory alignment
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Outcome-based pricing
- Pricing is metered by active agent work time rather than tied to task outcomes or success; idle/waiting time is not billed.
“You pay for Agent work only; waiting is free.”
harnessrouter.ai · checked Sep 11, 2026 - Settlement mechanism
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Asset custody
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Dispute process
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- SLA terms
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Evaluation coverage
- Platform includes a built-in benchmarking/arena tool that lets customers compare harness-and-model configurations on their own tasks before choosing one for production.
“Benchmark harness × model combinations on your task, then choose the configuration you route to, all through one integration.”
harnessrouter.ai · checked Sep 11, 2026 - Self-reported performance
- Vendor claims its harness/model routing approach can reduce enterprise agent usage costs by 90% or more versus a less optimized configuration.
“Cut enterprise agent usage costs by 90% or more.”
harnessrouter.ai · checked Sep 11, 2026
Agency
- Autonomy level
- Platform autonomously provisions and manages a sandboxed execution environment for each task without manual infrastructure operation.
“HarnessRouter provisions and operates one isolated sandbox for every task, so workloads scale without infrastructure work.”
harnessrouter.ai · checked Sep 11, 2026 - Human oversight
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Goal complexity
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Action space
- A single API call returns completed artifacts: videos, games, codebases and docs
“Your app sends a task through one API and gets back finished work: videos, games, codebases, docs, and more.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Operating environment
- Runs third-party coding/agent harnesses in isolated sandboxes as embedded backend infrastructure inside a customer product
“Run Codex, Claude Code, Hermes, and more in isolated sandboxes as your product backend.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Initiative
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
Safety
- Safety evaluations
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Red teaming
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Safety policy
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Usage restrictions
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Model or system card
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Incident reporting
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Third-party evaluations
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Data handling
- In the self-hosted Community Edition, all runtime and application state remains within the customer's own environment rather than the vendor's.
“With Community Edition, the runtime and application state stay in your environment.”
harnessrouter.ai · checked Sep 11, 2026
Practicality
- Pricing model
- Metered by active agent work minute from $0.014, with idle wait for model responses unbilled, as stated in the 2026-09-04 capture. The newest capture of this page, 2026-09-11, no longer contains the figure 0.014, so treat the rate as dated rather than current.
“Agent work from $0.014 per active work minute, and agent memory. Waiting for model responses is free.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Price point
- Plans start from $20 per month applied as usage credit, as worded in the 2026-09-04 capture. The 2026-09-11 capture still carries a $20 figure but not this sentence, so the wording is dated.
“Plans from $20/month include their full price as usage.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Availability
- Self-serve signup starts at $0 and requires no payment card. The capture names no release stage, so no general-availability claim is made.
“Start at $0, no card needed.”
harnessrouter.ai · checked Sep 11, 2026 - Deployment options
- Offered both as a managed hosted Cloud service and as a self-hosted open-source Community Edition.
“Use the managed Cloud or run it yourself.”
harnessrouter.ai · checked Sep 11, 2026 - Integrations
- Harnesses can take real tool actions against GitHub, Slack, Notion, and internal APIs
“confirmations of real tool actions like GitHub, Slack, Notion, or internal APIs.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Supported regions
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Support model
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
Foundation models
- Base models
- The router lists multiple harness-and-model combinations, including gpt-5.4 and gpt-5.4-mini variants and claude-opus-4.7.
“Codex gpt-5.4-mini Claude Code claude-opus-4.7 Hermes gpt-5.4-mini Pi gpt-5.4-mini Oh My Pi gpt-5.4-mini DeepSeek Harness gpt-5.4-mini Qwen Code gpt-5.4”
harnessrouter.ai · checked Sep 11, 2026 - Model provider
- Model provider is chosen by the customer; requests are routed directly to whichever provider and credentials they configure.
“Requests to the model provider still follow the provider and credentials you choose.”
harnessrouter.ai · checked Sep 11, 2026 - Model swappable
- Harness/model is configurable and swappable via a one-line config change without altering integration code
“Your config names the harness: claude-code today, codex tomorrow, or back again, swapped anytime with one line.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Open weights
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Fine-tuning
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Context window
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
Ecosystem
- Protocols supported
- The company's Unified Harness Protocol standard explicitly covers configuring MCP servers as part of a harness, indicating Model Context Protocol support.
“It defines how a harness is discovered, selected, and configured, including its model, skills, tools, and MCP servers, and how tasks, sessions, streaming events, files, artifacts, cancellation, errors, and results flow between the two.”
harnessrouter.ai · checked Sep 11, 2026 - Tool use
- A harness (the router's core abstraction) equips the underlying model with sandboxed tools and an execution loop so it produces finished work, not just text.
“A harness gives it a sandbox, tools, and a loop, so it returns actual work.”
harnessrouter.ai · checked Sep 11, 2026 - Multi-agent
- no public information
Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences
harnessrouter.ai · checked Sep 11, 2026 - API access
- The product is integrated and controlled through a single unified API.
“One API. One console. Every agent harness.”
harnessrouter.ai · checked Sep 11, 2026 - Open source
- The self-hosted Community Edition is released under the Apache 2.0 open-source license.
“Community Edition is Apache 2.0 and runs on infrastructure you control with your own keys, state, and files.”
harnessrouter.ai · checked Sep 11, 2026 - Marketplace presence
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
Impact
- User base
- Named launch partner: Stanford Medicine
“Launch Partner: Used by Stanford Medicine”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 11, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
harnessrouter.ai · checked Sep 4, 2026 - Deployment scale
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Target sectors
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- High-risk domains
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Documented incidents
- no public informationharnessrouter.ai · checked Sep 11, 2026 · source did not state this
- Market recognition
- Company publicly discloses Y Combinator backing as a signal of investor validation.
“Backed by Y Combinator”
harnessrouter.ai · checked Sep 11, 2026
In the wire
Reporting backed by the same source documents as HarnessRouter’s own evidenced fields.