AI and agents
What the AI can and cannot do
Harmony puts agents to work inside your IT estate, which makes this the section most security reviews spend the longest on. Everything below is a statement about the product as built, and each claim points at the control that backs it.
The AI and your data
The six questions we are asked in every review, answered the same way every time.
LLM hosted on our cloud
The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them.
No training on customer data
Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model.
Never sold, never brokered
Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our subprocessor list, strictly to deliver the service.
One workspace cannot see another
Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace.
Only the context you granted
An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant.
Storage, retention and deletion
Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at privacy@harmony.io.
Four layers between a request and a change
An agent does not reach your IT core. A request passes through these in order, and every one of them is configured by you.
- Layer 1
Guardrails
Every response is filtered by policy before it reaches the person who asked. Topics, tone and the data an agent may reveal are all set by an admin, not by the model.
- Layer 2
Human-in-the-loop
Sensitive actions wait for explicit approval. The agent gathers the context and proposes the change; a named approver decides, and the decision is recorded.
- Layer 3
Deterministic flows
The automation agent runs as code, not improvisation. A flow does the same thing on run one thousand as it did on run one, and you can read it before you ship it.
- Layer 4
Scoped access
Connections are least-privilege, with a scope ceiling per integration. An agent never gets direct access to your IT core. It calls the tools you granted it, and nothing else.
- SAML and SCIM based access
- RBAC managed by your IdP
- Approvals on every action
- Step-by-step audit log per run
How agent access is bounded
Stated once here, and enforced per integration.
- Nothing is connected until an admin connects it. There is no ambient access to a system Harmony was not given.
- Every integration has a scope ceiling set by an admin. An agent calls the tools it was granted, and nothing else.
- Anything that changes state runs as a deterministic flow you can read before you ship it, not as improvisation by a model.
- Sensitive actions wait for a named approver by default, and the decision is recorded.
- Every run produces a step-by-step audit record of what the agent did and why.
- Disconnecting an integration revokes Harmony’s access to it.
AI governance frameworks
The NIST AI Risk Management Framework and the EU AI Act are the AI-specific frameworks we build and govern against. Neither is a certification and we do not present them as one. The controls on this page are where the work behind them shows up: scoped access per integration, an approver on sensitive actions, deterministic flows for anything that changes state, and a step-by-step audit record of every agent run.
The controls behind these claims