Controls

The controls we operate

What we do, and where the control itself makes it explicit, how it is checked. Each control has its own page, so you can link a colleague at the one they asked about.

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Who owns security at Harmony, the policies they maintain, and what every employee is held to.

How the platform is run on AWS: availability, logging, recovery, and who can reach production.

Encryption, retention and deletion for the data you put into Harmony.

Product Security

12 controls

What the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing.

What the agents can and cannot do, who approves the sensitive actions, and what record each run leaves.

What happens when something goes wrong, and how quickly someone is looking at it.

How the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled.