Harvey builds its own agent security the week AWS gives it away and Goodfire cuts monitoring to $51

Harvey disclosed a policy engine on October 7 that checks every partner tool call its legal agents make, because the leaked files and the malpractice exposure belong to the law firm. The same week, AWS open-sourced an agent sandbox and Goodfire cut monitoring to $51 per 1,500 sessions from $10,000, the spread that asks whether agent governance is a market or a feature.

In this storyHarveyAnthropic
Vincent JiangVincent Jiang · 3 min read
Share
Winston Weinberg, CEO and co-founder of Harvey
1 / 6Slide 1 of 6
Winston Weinberg, Harvey's CEO and co-founder. The company disclosed its MCP policy engine on October 7.

The same day: 500 lawyers and a security disclosure

On October 7, offshore law firm Ogier ended its pilot the committed way: Harvey's$15.5B — Harvey, private, latest valuation $15.5B agents now sit in front of all 500 lawyers across 13 offices 2. The same day, Harvey's security team published a rarer artifact than a funding release: a working account of how its own agents can be turned against the firms using them 1.

The product is the attack surface

The agents that carry the revenue and the agents that can carry the breach are the same agents. Connectors reach research platforms, document systems and communication tools through the Model Context Protocol, and the post names the failure modes: tools poisoned on arrival, tools changed after approval in a rug pull, trusted tools queried just wrong enough to send client data out 1. It cites NSA guidance calling MCP "uneven and highly dependent on implementation discipline rather than protocol guarantees" 1. The fix sits outside the model: Rego rules permit, deny or pause each proposed call, and deny by default when a check cannot complete 1. The Tool Pinner, watching approved tools for later changes, "currently generates a substantial volume of alerts" 1.

The price of governing agents just collapsed

The build decision landed the week governance got cheap. AWS open-sourced Strands Box on October 7 under Apache 2.0, with a broker that mediates every MCP tool call and policies that can deny an action based on what the agent already did 3. Goodfire cut the other cost: probes reading a model's internal signals monitored 1,500 agent sessions for about $51, against roughly $233 for a cheap model and about $10,000 for a top-tier one, while catching 94% of malicious hacking sessions 4.

Watching 1,500 agent sessions fell from $10,000 to $51

$0$2,000$4,000$6,000$8,000$10,000Goodfire internal probes$51Cheap model monitor$233Top-tier model monitor$10,000
Data
Value
Goodfire internal probes$51
Cheap model monitor$233
Top-tier model monitor$10,000
Goodfire-reported test costs on the open model Kimi K3, US dollars per 1,500 monitored agent sessions, published October 8, 2026.4

Harvey builds and buys as the market decides

Harvey also buys. Its $550 million round at a $15.5 billion valuation on September 9 came with Guardrails AI, an agent-security startup and its fourth acquisition this year 5. The growth is company-claimed and fast: over $100 million of ARR added in Q3, past $400 million total, 97% gross revenue retention, 80% of the 100 highest-grossing US firms 56, more than 3,000 customers in over 70 countries 7. SailPoint, the listed identity vendor, shipped agent governance and a kill switch into IdentityIQ 9.0 the same day 8. Apps building these controls in, and clouds giving them away, is the bear case for selling them separately.

The tell is the alert queue

Anthropic$350B — Anthropic, private, latest valuation $350B, the model supplier, has sold the same workflows directly since May under Claude for Legal 9, which leaves governance as the layer this disclosure actually evidences. The number to watch is unwritten: how fast flagged tool changes outrun the humans reviewing them. A control that drowns its reviewers is a support tier, not a moat.

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio