News

Harvey introduces the MCP Policy Engine to strengthen AI security for legal workflows, addressing risks like tool poisoning and data vulnerabilities.

Harvey Develops MCP Policy Engine to Enhance AI Security

Harvey, an AI company specializing in legal and professional services workflows, has announced the development of its Model Context Protocol (MCP) Policy Engine. This innovation aims to enhance security across its platform by addressing vulnerabilities and risks in tool integration and information flow management.

Evidence and context

According to a blog post published by Harvey on October 7, 2026, the MCP Policy Engine introduces runtime controls to manage tool access, information flow, and agent actions. This builds on Harvey’s existing security measures and responds to threats such as prompt injection and tool poisoning attacks. The company states that these risks are significant for its user base, which spans over 3,000 customers in 70+ countries.

MCP, a reusable standard for tool discovery and interaction, increases the capabilities of AI agents but also expands the attack surface. Specific threats include malicious tool definitions or changes introduced post-approval—a scenario referred to as a “rug-pull attack.” Harvey’s policy engine mitigates these risks through defense-in-depth strategies, including least privilege restrictions, complete mediation of tool actions, and secure information flow controls.

The company’s proactive approach to security includes rigorous reviews of partner MCP integrations, detailed assessments of tool capabilities and risks, and runtime enforcement of security policies. For example, the MCP Policy Engine’s “Tool Pinner” tracks and flags changes to approved tools, enabling real-time monitoring for potential vulnerabilities. Additionally, the engine incorporates a “Sanitizer” feature to remove hidden characters or potentially malicious instructions embedded in tool results.

Why it matters

Harvey’s security initiatives are critical to its role as a provider of AI solutions for sensitive legal workflows, including contract analysis, due diligence, and compliance. The MCP Policy Engine reflects the company’s broader commitment to addressing sophisticated security challenges in AI, as highlighted in its recent $550 million funding round at a $15.5 billion valuation on September 9, 2026. This valuation underscores investor confidence in Harvey’s ability to innovate and secure its platform amid growing demand for AI tools in the legal sector.

Harvey’s ongoing efforts to refine and test its security measures include exploring automated improvements to policy creation, program analysis of agent behavior, and formalized controls. The company has indicated that it will continue to adapt its defenses in response to evolving threats, leveraging both internal research and external guidance.

Source

LEAVE A REPLY

Please enter your comment!
Please enter your name here