Incident Detection and Response

Breach Notification

If a security incident affects your data, we notify you without undue delay and within 72 hours of becoming aware of it, with what we know at the time and what we are doing about it. Notification duties and contacts are set out in our Data Processing Agreement. Harmony has not experienced a material security incident requiring customer or regulator notification.

Framework requirements this speaks to

  • GDPR Art. 33 (notification of a personal data breach)
  • ISO 27001 A.5.26 (response to information security incidents)
  • SOC 2 Common Criteria - Communication

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.