Controls
Incident Detection and Response
What happens when something goes wrong, and how quickly someone is looking at it.
Incident Response Process
Harmony implements a protocol for handling security events which includes escalation procedures, rapid mitigation and post mortem. All employees are informed of our policies.
- ISO 27001 A.5.24 (incident management planning)
- ISO 27001 A.5.27 (learning from incidents)
On-call Coverage
A member of engineering is on-call 24/7 to respond to alerts and pages. They can escalate directly to a security team member as needed.
How it is checked: 24/7 engineering on-call rotation, with escalation to security.
- SOC 2 Availability
- ISO 27001 A.5.26 (response to incidents)
Breach Notification
If a security incident affects your data, we notify you without undue delay and within 72 hours of becoming aware of it, with what we know at the time and what we are doing about it. Notification duties and contacts are set out in our Data Processing Agreement. Harmony has not experienced a material security incident requiring customer or regulator notification.
- GDPR Art. 33 (notification of a personal data breach)
- ISO 27001 A.5.26 (response to information security incidents)
- SOC 2 Common Criteria - Communication
Vulnerability Disclosure
Suspected vulnerabilities can be reported to privacy@harmony.io, published for researchers at /.well-known/security.txt. We acknowledge every report, keep the reporter updated through triage and remediation, and will not pursue researchers who report in good faith.
- ISO 27001 A.6.8 (information security event reporting)
- RFC 9116 (security.txt)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls