Incident Detection and Response
Vulnerability Disclosure
Suspected vulnerabilities can be reported to privacy@harmony.io, published for researchers at /.well-known/security.txt. We acknowledge every report, keep the reporter updated through triage and remediation, and will not pursue researchers who report in good faith.
Framework requirements this speaks to
- ISO 27001 A.6.8 (information security event reporting)
- RFC 9116 (security.txt)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.