Compliance & data residency

What your compliance team will ask about Endpoint AI, answered in one place: where model traffic goes, what passes through Harriet, which contractual documents exist, and how the audit trail supports a review.

EU data residency

Harriet can lock Claude traffic to the EU. When the option is enabled, the gateway routes conversations to Anthropic models served from Amazon Bedrock in AWS's eu-west-1 (Ireland) region — the model runs on EU soil, and the model catalog on affected devices shows the EU variants (for example Opus 4.7 EU and Haiku 4.5 EU) grouped as Anthropic (EU). EU models are supplied through Harriet's managed credits and require Endpoint AI Business or higher. Details and setup: EU data residency.

Admins can go further and restrict which models are available at all, per organization or per device, so a finance team can be EU-only while engineering keeps the full catalog. See Available models.

What flows through Harriet, and what doesn't

You choose the transport per connector. A proxied connector sends its tool calls through Harriet's gateway, which is what makes them appear in the audit log; a direct connector lets the desktop talk to the service without Harriet in the path. The choice is made in each profile's transport settings — see Transport.

The same logic applies to model traffic. With the LLM proxy enabled, requests to OpenAI, Anthropic, and Google go through Harriet, which records usage and cost per person, team, and device. With it off, the desktop calls providers directly and Harriet sees none of that content. Data residency routing (above) requires the proxy, since Harriet has to be in the path to pin the region.

Contracts and documentation

The legal documents a procurement or DPIA review needs are published on the Harriet website:

💡

This page describes what exists; it is not legal advice. Have your counsel review the documents above, and send contract questions to legal@harriethq.com.

Isolation and the audit trail

Every record in Harriet is scoped to one customer organization, and the gateway independently verifies that the person behind each call belongs to the same organization as the skill being used; see Device security for the full model.

For the review itself, the audit log is the compliance artifact: an append-only record of who called which tool, from which connector, and whether it succeeded, filterable by person and date range, with deep links to individual entries. Organizations that need a bounded data window can set a log retention period so older entries are removed from the console on a nightly schedule.