Corporate and Physical Security
Physical and Environmental Security
Harmony operates no data centres of its own. All customer data is held in AWS facilities, whose physical and environmental controls are covered by AWS’s own audited certifications. Harmony offices are access-controlled, and visitors are received rather than given unaccompanied access.
Framework requirements this speaks to
- ISO 27001 A.7.1 (physical security perimeters)
- ISO 27001 A.7.2 (physical entry)
- ISO 27001 A.7.4 (physical security monitoring)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.