Controls
Data Privacy and Protection
Encryption, retention and deletion for the data you put into Harmony.
Encryption at Rest
We encrypt data at rest using an industry-standard AES-256 encryption algorithm.
- ISO 27001 A.8.24 (use of cryptography)
- SOC 2 Confidentiality
Encryption in Transit
Harmony is served 100% over HTTPS. All data sent to or from Harmony is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only.
- ISO 27001 A.8.24 (use of cryptography)
- SOC 2 Confidentiality
Data Retention and Disposal Policies
Workspace data is deleted within 30 days of a workspace being electively deleted by its teammates. You can request deletion of your data at any time.
How it is checked: Workspace data is deleted within 30 days of the workspace being deleted.
- ISO 27001 A.8.10 (information deletion)
- GDPR Art. 5(1)(e) (storage limitation)
Key and Secrets Management
Encryption keys are managed in AWS Key Management Service within our own account, with access restricted to the production role that needs it. Application secrets and credentials are held in a managed secret store, never in source code, and source repositories are scanned to enforce this.
- ISO 27001 A.8.24 (use of cryptography)
- ISO 27001 A.5.17 (authentication information)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls