Controls
Network and Infrastructure Security
How the platform is run on AWS: availability, logging, recovery, and who can reach production.
Multi-Factor Authentication
MFA is enforced on all access to production. Access to the production environment, the deployment pipeline and the source control system each require multi-factor authentication and are restricted to authorised personnel. Corporate accounts authenticate through our identity provider with MFA enforced, and privileged accounts are separate from day-to-day accounts.
How it is checked: Tested in our SOC 2 Type II examination against production, deployment and source control access, with no deviations noted.
- ISO 27001 A.5.17 (authentication information)
- ISO 27001 A.8.5 (secure authentication)
- SOC 2 Common Criteria - Logical Access
Network Segmentation and Perimeter Protection
Production runs in a segmented AWS VPC with security groups and network ACLs enforcing least-privilege traffic flows. Public endpoints sit behind a web application firewall with DDoS protection at the edge, and firewall rules are configured to permit only approved services. Administrative access to production is not exposed to the public internet and is further restricted by source IP.
How it is checked: Firewall configuration and the restricted administrator list were inspected in our SOC 2 Type II examination, with no deviations noted.
- ISO 27001 A.8.20 (networks security)
- ISO 27001 A.8.22 (segregation of networks)
- ISO 27001 A.8.23 (web filtering)
Auto Scaling
Our infrastructure auto-scales to maintain high availability and support demand.
- ISO 27001 A.8.6 (capacity management)
- SOC 2 Availability
Audit Logging and Monitoring
On an application level, we produce audit logs for all activity and ship logs to a centralised logging system for analysis. All actions taken on production consoles or in the Harmony application are logged.
How it is checked: Logs are shipped off the producing system to a central platform for analysis.
- ISO 27001 A.8.15 (logging)
- ISO 27001 A.8.16 (monitoring activities)
- SOC 2 Common Criteria - Monitoring
Disaster Recovery
Harmony was built with disaster recovery in mind. All of our infrastructure and data are spread across different availability zones and will continue to work should any one of those data centers fail.
- ISO 27001 A.5.29 (information security during disruption)
- SOC 2 Availability
Backups and Restore Testing
Production data is backed up on a defined schedule under our backup policy, with point-in-time recovery for critical data. Backups are encrypted and held in a separate, access-controlled location from production, and for critical data in a geographically separate region. The restore process is performed and documented at least annually against our recovery objectives.
How it is checked: Restore is performed and documented annually, and the Disaster Recovery Plan is tested annually.
- ISO 27001 A.8.13 (information backup)
- ISO 27001 A.5.30 (ICT readiness for business continuity)
- SOC 2 Availability
Least Privilege
AWS Security Groups employed for our infrastructure are baselined regularly to maintain least privilege. Access granted to team members for our AWS production environment is baselined on a regular basis to maintain least privilege.
How it is checked: Security groups and production access are baselined on a regular basis.
- ISO 27001 A.8.2 (privileged access rights)
- ISO 27001 A.5.18 (access rights)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls