We are open sourcing Quest, a safety-first AI harness we built at Electric.
With Quest, anyone can deploy a familiar AI chat experience connected to your most sensitive data and tools. Its architecture guarantees that data can not leave your security perimeter without user approval, making it safe to deploy to everyone, regardless of technical experience.
We have found that AI models are most valuable when they have access to the most important context – the CEO’s emails, financial data, customer information, sensitive legal documents, etc. At Electric, we have successfully deployed Quest to help all of our teams (Finance, Legal, Investor Relations, Platform, IT/DevOps, Office Administration) with their day-to-day workflows. We believe this would not have been possible without a re-think of how we deliver AI capabilities to the entire organization.
Why did we build our own harness?
As we started exploring AI adoption within Electric, we ran into two core challenges: safety and ownership.
A lack of safety guarantees limited rollout
How do we put software whose behavior we can’t fully predict on company devices that have access to sensitive data? Claude Code and Codex are amazing products for developers who can assess what a shell command will do, but what about everyone else?
We tried several approaches that didn’t pan out. We tried training people to use Claude and Codex apps safely. We built ephemeral, network-isolated cloud containers, but users had to learn SSH and work in a terminal. We even tried a custom virtualized runtime on users’ laptops, but that meant learning confusing file and network access rules.
What about web apps like Claude and OpenAI? They avoided local deployment but lacked the controls we needed over information moving between services. If we connected Gmail or a third-party MCP server, what would stop an AI from sending sensitive data to another service or website?
Our business knowledge flowed into harnesses we didn’t own
As we observed people use AI harnesses, we saw our business knowledge accumulate inside those products. Projects, Custom GPTs, Gems, Skills, automation scripts, memories. These products capture the core of how the business works: its knowledge, decisions, and processes.
What does it mean to surrender these essential pieces of information to a system that you do not fully own and control?
We had more questions: what if a harness drops a model you depend on? What if you want to combine competing models, or run local inference for sensitive data? What if a censorship decision stops a model from performing a core function? What happened to Cursor users that depended on ChatGPT when OpenAI shut them off?
As an organization that expects to rely heavily on AI, we couldn’t hand control of such essential infrastructure to a third party. It would be like a manufacturer outsourcing its machines, factories, and process know-how. What’s left of the company?
Those two requirements shaped Quest: control over how data moves, and control over the system itself.
A safe system that everyone can understand
By default, chat sessions in Quest have limited, read-only access to approved services like Google and Slack, rather than broad internet access. Any “write” — an action whose effects might be visible to someone else — requires approval. Models also have a sandbox coding environment with similarly restricted access to upstream services.
We assume no model can be completely trusted, so we don’t rely on instruction following or model alignment to limit behavior. Quest controls which tools a model can use, and each tool has its own guardrails and approval flows. In such an environment, we know that the risk of autonomous data exfiltration is heavily mitigated. Even if the model reads an email with an injected malicious prompt, it has no way to perform a damaging action without getting human approval first.
Our human approval flows are carefully designed to be legible to all users. Quest will never ask a user whether it can run a scary shell command. It presents every potential action with clear intent, such as editing a spreadsheet or sending a Slack message. Each approval includes clear information that makes it simple to understand what is being approved.
Quest runs as a web application on your infrastructure. Users connect through a browser and grant access to services through standard OAuth and API key flows. There’s no on-device software or data for IT admins to manage. Quest inherits the data governance and access rules already set up for your users.
These design choices let us offer safe AI access to everyone in our firm. Users only need to understand one rule: whatever happens in Quest stays in Quest, unless you approve otherwise.
A modular, open system that you can fully own
AI moves extremely quickly. New AI models, providers, techniques, and integrations appear every week. Source-level control lets you adopt the best ideas quickly. But source access alone isn’t enough: the system has to be built to customize.
Building integrations for our internal users helped us establish consistent plugin interfaces and design patterns. In our experience, Fable-class models recognize those patterns and can one-shot plugins for safe access to most upstream services.
We plan to bring the same modularity for inference, with customizable models and providers and first-class support for local inference. Local models’ privacy and independence advance Quest’s core goals.
Helping companies adopt AI safely
Electric Capital is not in the business of selling harnesses. We’re in the business of helping companies move faster. We had already started sharing Quest with companies we work with, so why not share it with everyone else?
We’re excited to see whether Quest’s design resonates with other organizations that share our concerns. We hope to build a community that expands Quest’s integrations and makes it as plug-and-play as possible.
We are releasing the source code under a permissive Apache 2.0 because we think ownership and control matter to anyone building a company on AI. We welcome all contributions that benefit other users, as well as deep customizations, forks, and borrowing Quest’s ideas for your own harnesses.
Check it out on our Github!