Controls
The controls we operate
What we do, and where the control itself makes it explicit, how it is checked. Each control has its own page, so you can link a colleague at the one they asked about.
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Information Security Management
8 controlsWho owns security at Harmony, the policies they maintain, and what every employee is held to.
- Security LeadershipThe Harmony leadership team and Data Privacy Officer (DPO) are responsible for determining and updating information security measures at Harmony.
- ISO 27001 A.5.2 (roles and responsibilities)
- GDPR Art. 37 (data protection officer)
- Information Security Policies and ProceduresHarmony maintains established information security policies and procedures for all employees and contractors, covering a range of topics. Policies and procedures are approved by management, reviewed at least annually, updated as needed, and made available to all employees via our intranet.How it is checked: Approved by management and reviewed at least annually.
- ISO 27001 A.5.1 (policies for information security)
- SOC 2 Common Criteria - Control Environment
- Background ChecksHarmony performs background checks on all new employees in accordance with local laws.How it is checked: Pre-employment screening, to the extent local law permits.
- ISO 27001 A.6.1 (screening)
- Employee ConfidentialityAll employee contracts include a confidentiality agreement.
- ISO 27001 A.6.6 (confidentiality agreements)
- Mandatory Security Awareness TrainingAll employees undergo mandatory security awareness training on an annual basis. Certain higher risk roles go through additional training specific for their role and its associated risks, annually.How it is checked: Annually for everyone, with extra role-specific training for higher-risk roles.
- ISO 27001 A.6.3 (awareness, education and training)
- Access Provisioning and OffboardingAccess is granted by role from a documented baseline once onboarding is complete, and requires approval from the system owner for anything touching production. On a role change, access is reviewed and anything no longer needed is removed. On termination, a documented clearance process revokes system and premises access and recovers company property, and corporate accounts are disabled the same business day. Access permissions are recertified on a regular cycle.How it is checked: A documented termination clearance process tracked in our internal IT ticket system, and periodic recertification of access permissions.
- ISO 27001 A.5.18 (access rights)
- ISO 27001 A.6.5 (responsibilities after termination or change of employment)
- SOC 2 Common Criteria - Logical Access
- Risk AssessmentHarmony operates a formal information security risk assessment process as part of its ISO 27001 certified ISMS. Risks to the confidentiality, integrity and availability of customer data are identified, assessed against defined criteria, assigned an owner and a treatment, and reviewed at least annually and on material change to the environment.How it is checked: Reviewed at least annually and on material change, within the certified ISMS.
- ISO 27001 Clause 6.1.2 (information security risk assessment)
- ISO 27001 Clause 8.2 (risk assessment performance)
- SOC 2 Common Criteria - Risk Assessment
- Vendor Risk AssessmentsWe formally assess the security posture of all third-party vendors, with a higher bar for those which handle sensitive data or have access to critical systems.How it is checked: Formal assessment before onboarding, with a higher bar for vendors that handle sensitive data.
- ISO 27001 A.5.19 (security in supplier relationships)
- SOC 2 Common Criteria - Risk Assessment
Network and Infrastructure Security
7 controlsHow the platform is run on AWS: availability, logging, recovery, and who can reach production.
- Multi-Factor AuthenticationMFA is enforced on all access to production. Access to the production environment, the deployment pipeline and the source control system each require multi-factor authentication and are restricted to authorised personnel. Corporate accounts authenticate through our identity provider with MFA enforced, and privileged accounts are separate from day-to-day accounts.How it is checked: Tested in our SOC 2 Type II examination against production, deployment and source control access, with no deviations noted.
- ISO 27001 A.5.17 (authentication information)
- ISO 27001 A.8.5 (secure authentication)
- SOC 2 Common Criteria - Logical Access
- Network Segmentation and Perimeter ProtectionProduction runs in a segmented AWS VPC with security groups and network ACLs enforcing least-privilege traffic flows. Public endpoints sit behind a web application firewall with DDoS protection at the edge, and firewall rules are configured to permit only approved services. Administrative access to production is not exposed to the public internet and is further restricted by source IP.How it is checked: Firewall configuration and the restricted administrator list were inspected in our SOC 2 Type II examination, with no deviations noted.
- ISO 27001 A.8.20 (networks security)
- ISO 27001 A.8.22 (segregation of networks)
- ISO 27001 A.8.23 (web filtering)
- Auto ScalingOur infrastructure auto-scales to maintain high availability and support demand.
- ISO 27001 A.8.6 (capacity management)
- SOC 2 Availability
- Audit Logging and MonitoringOn an application level, we produce audit logs for all activity and ship logs to a centralised logging system for analysis. All actions taken on production consoles or in the Harmony application are logged.How it is checked: Logs are shipped off the producing system to a central platform for analysis.
- ISO 27001 A.8.15 (logging)
- ISO 27001 A.8.16 (monitoring activities)
- SOC 2 Common Criteria - Monitoring
- Disaster RecoveryHarmony was built with disaster recovery in mind. All of our infrastructure and data are spread across different availability zones and will continue to work should any one of those data centers fail.
- ISO 27001 A.5.29 (information security during disruption)
- SOC 2 Availability
- Backups and Restore TestingProduction data is backed up on a defined schedule under our backup policy, with point-in-time recovery for critical data. Backups are encrypted and held in a separate, access-controlled location from production, and for critical data in a geographically separate region. The restore process is performed and documented at least annually against our recovery objectives.How it is checked: Restore is performed and documented annually, and the Disaster Recovery Plan is tested annually.
- ISO 27001 A.8.13 (information backup)
- ISO 27001 A.5.30 (ICT readiness for business continuity)
- SOC 2 Availability
- Least PrivilegeAWS Security Groups employed for our infrastructure are baselined regularly to maintain least privilege. Access granted to team members for our AWS production environment is baselined on a regular basis to maintain least privilege.How it is checked: Security groups and production access are baselined on a regular basis.
- ISO 27001 A.8.2 (privileged access rights)
- ISO 27001 A.5.18 (access rights)
Data Privacy and Protection
4 controlsEncryption, retention and deletion for the data you put into Harmony.
- Encryption at RestWe encrypt data at rest using an industry-standard AES-256 encryption algorithm.
- ISO 27001 A.8.24 (use of cryptography)
- SOC 2 Confidentiality
- Encryption in TransitHarmony is served 100% over HTTPS. All data sent to or from Harmony is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only.
- ISO 27001 A.8.24 (use of cryptography)
- SOC 2 Confidentiality
- Data Retention and Disposal PoliciesWorkspace data is deleted within 30 days of a workspace being electively deleted by its teammates. You can request deletion of your data at any time.How it is checked: Workspace data is deleted within 30 days of the workspace being deleted.
- ISO 27001 A.8.10 (information deletion)
- GDPR Art. 5(1)(e) (storage limitation)
- Key and Secrets ManagementEncryption keys are managed in AWS Key Management Service within our own account, with access restricted to the production role that needs it. Application secrets and credentials are held in a managed secret store, never in source code, and source repositories are scanned to enforce this.
- ISO 27001 A.8.24 (use of cryptography)
- ISO 27001 A.5.17 (authentication information)
Product Security
12 controlsWhat the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing.
- Multi-tenancy Data ProtectionsSafeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace.
- SOC 2 Confidentiality
- ISO 27001 A.8.4 (access to source code and data)
- SSOYou can configure Harmony with SAML Single Sign-on (SSO) using Okta, Microsoft Entra ID or another SAML 2.0 identity provider.
- ISO 27001 A.5.16 (identity management)
- ISO 27001 A.5.17 (authentication information)
- Multi-Factor AuthenticationWorkspaces that do not federate through SAML can require multi-factor authentication for their users. Where you use your own identity provider, your MFA policy applies and Harmony enforces it through the SSO session.
- ISO 27001 A.5.17 (authentication information)
- ISO 27001 A.8.5 (secure authentication)
- SCIM ProvisioningHarmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning from your identity provider, including group memberships.
- ISO 27001 A.5.16 (identity management)
- ISO 27001 A.5.18 (access rights)
- RBACHarmony provides Role-Based Access Control (RBAC) to manage user permissions and restrict access to sensitive data and features based on assigned roles.
- ISO 27001 A.5.15 (access control)
- Audit LogsHarmony maintains comprehensive audit logs of all user and administrative actions within the platform, enabling security reviews, incident investigations and compliance reporting.
- ISO 27001 A.8.15 (logging)
- Password ComplexityHarmony enforces a password complexity standard.
- ISO 27001 A.5.17 (authentication information)
- Upload ScanningHigh-risk executable files are automatically restricted for all workspaces. Customers can choose which filetypes can be uploaded by users to their workspace. Allowed files are scanned for malware.
- ISO 27001 A.8.7 (protection against malware)
- Code ReviewEach pull request to the Harmony code repositories must undergo a peer review before it can be accepted and merged.How it is checked: Peer review on every pull request, enforced in the repository.
- ISO 27001 A.8.28 (secure coding)
- Change ManagementChanges to infrastructure and software are documented, reviewed and approved before they reach production, under a change management policy that is reviewed and approved annually. Development and production are separate environments, and engineers do not hold standing access to production or to production databases. Access for a specific project is granted deliberately, logged and reviewed.How it is checked: Approvals recorded in the change management system and sampled in our SOC 2 Type II examination.
- ISO 27001 A.8.32 (change management)
- ISO 27001 A.8.31 (separation of development, test and production environments)
- SOC 2 Common Criteria - Change Management
- Vulnerability ManagementVulnerabilities are identified continuously rather than only at audit time. Dependencies, container images and infrastructure are scanned on an ongoing basis, and findings are triaged and remediated against severity-based timelines. Critical issues are addressed immediately, with progressively longer windows for lower severities. The most recent third-party penetration test and its retest closed with no critical, high or medium findings outstanding.How it is checked: Continuous scanning with severity-based remediation timelines, plus an annual third-party penetration test and retest.
- ISO 27001 A.8.8 (management of technical vulnerabilities)
- SOC 2 Common Criteria - Risk Assessment
- Penetration TestingWe engage third-party security experts to perform a detailed penetration test of the production Harmony web application annually, followed by a retest of the findings.How it is checked: Annual third-party penetration test and retest. A summary is available under NDA.
- ISO 27001 A.8.8 (management of technical vulnerabilities)
AI and Agent Controls
4 controlsWhat the agents can and cannot do, who approves the sensitive actions, and what record each run leaves.
- Scoped Integration AccessAn agent can retrieve only from the knowledge sources and call only the tools that a workspace administrator has connected for it. There is no ambient access to systems outside that grant, and each integration is scoped to the permissions it was given rather than to the permissions of the person who connected it.
- ISO 27001 A.5.15 (access control)
- NIST AI RMF MANAGE 2.1
- SOC 2 Confidentiality
- Human Approval on Sensitive ActionsActions that change state in a connected system can require an approver before they run. Sensitive actions are gated by default and the gate is configurable per workspace, so an administrator decides where the agent acts on its own and where a person signs off first.
- ISO 27001 A.5.15 (access control)
- NIST AI RMF MANAGE 4.1
- EU AI Act Art. 14 (human oversight)
- Deterministic Execution for State-Changing OperationsAnything that changes state runs through a deterministic flow rather than through free-form model output. The model chooses which flow to invoke and with what inputs; the flow itself is code, with its own validation and its own permissions.
- NIST AI RMF MEASURE 2.6
- ISO 27001 A.8.28 (secure coding)
- Agent Run Audit RecordEvery agent run produces a step-by-step record of what it retrieved, which tools it called, what it changed and why. The record is available to workspace administrators and is retained with the rest of the workspace audit log.How it is checked: Produced automatically for every run, and retained with the workspace audit log.
- ISO 27001 A.8.15 (logging)
- NIST AI RMF GOVERN 1.5
- EU AI Act Art. 12 (record-keeping)
Incident Detection and Response
4 controlsWhat happens when something goes wrong, and how quickly someone is looking at it.
- Incident Response ProcessHarmony implements a protocol for handling security events which includes escalation procedures, rapid mitigation and post mortem. All employees are informed of our policies.
- ISO 27001 A.5.24 (incident management planning)
- ISO 27001 A.5.27 (learning from incidents)
- On-call CoverageA member of engineering is on-call 24/7 to respond to alerts and pages. They can escalate directly to a security team member as needed.How it is checked: 24/7 engineering on-call rotation, with escalation to security.
- SOC 2 Availability
- ISO 27001 A.5.26 (response to incidents)
- Breach NotificationIf a security incident affects your data, we notify you without undue delay and within 72 hours of becoming aware of it, with what we know at the time and what we are doing about it. Notification duties and contacts are set out in our Data Processing Agreement. Harmony has not experienced a material security incident requiring customer or regulator notification.
- GDPR Art. 33 (notification of a personal data breach)
- ISO 27001 A.5.26 (response to information security incidents)
- SOC 2 Common Criteria - Communication
- Vulnerability DisclosureSuspected vulnerabilities can be reported to privacy@harmony.io, published for researchers at /.well-known/security.txt. We acknowledge every report, keep the reporter updated through triage and remediation, and will not pursue researchers who report in good faith.
- ISO 27001 A.6.8 (information security event reporting)
- RFC 9116 (security.txt)
Corporate and Physical Security
3 controlsHow the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled.
- Endpoint EncryptionAll corporate devices are encrypted to protect data in case of loss or theft. They can be remotely wiped to prevent data leakage if a device is compromised or lost.
- ISO 27001 A.8.1 (user endpoint devices)
- ISO 27001 A.8.24 (use of cryptography)
- Endpoint ManagementWe push updates to employee laptops such that they are on the latest, patched version of their required operating system. We require the use of a managed browser with only an approved set of browser extensions.
- ISO 27001 A.8.1 (user endpoint devices)
- ISO 27001 A.8.8 (management of technical vulnerabilities)
- Physical and Environmental SecurityHarmony operates no data centres of its own. All customer data is held in AWS facilities, whose physical and environmental controls are covered by AWS’s own audited certifications. Harmony offices are access-controlled, and visitors are received rather than given unaccompanied access.
- ISO 27001 A.7.1 (physical security perimeters)
- ISO 27001 A.7.2 (physical entry)
- ISO 27001 A.7.4 (physical security monitoring)