Controls
Product Security
What the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing.
Multi-tenancy Data Protections
Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace.
- SOC 2 Confidentiality
- ISO 27001 A.8.4 (access to source code and data)
SSO
You can configure Harmony with SAML Single Sign-on (SSO) using Okta, Microsoft Entra ID or another SAML 2.0 identity provider.
- ISO 27001 A.5.16 (identity management)
- ISO 27001 A.5.17 (authentication information)
Multi-Factor Authentication
Workspaces that do not federate through SAML can require multi-factor authentication for their users. Where you use your own identity provider, your MFA policy applies and Harmony enforces it through the SSO session.
- ISO 27001 A.5.17 (authentication information)
- ISO 27001 A.8.5 (secure authentication)
SCIM Provisioning
Harmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning from your identity provider, including group memberships.
- ISO 27001 A.5.16 (identity management)
- ISO 27001 A.5.18 (access rights)
RBAC
Harmony provides Role-Based Access Control (RBAC) to manage user permissions and restrict access to sensitive data and features based on assigned roles.
- ISO 27001 A.5.15 (access control)
Audit Logs
Harmony maintains comprehensive audit logs of all user and administrative actions within the platform, enabling security reviews, incident investigations and compliance reporting.
- ISO 27001 A.8.15 (logging)
Password Complexity
Harmony enforces a password complexity standard.
- ISO 27001 A.5.17 (authentication information)
Upload Scanning
High-risk executable files are automatically restricted for all workspaces. Customers can choose which filetypes can be uploaded by users to their workspace. Allowed files are scanned for malware.
- ISO 27001 A.8.7 (protection against malware)
Code Review
Each pull request to the Harmony code repositories must undergo a peer review before it can be accepted and merged.
How it is checked: Peer review on every pull request, enforced in the repository.
- ISO 27001 A.8.28 (secure coding)
Change Management
Changes to infrastructure and software are documented, reviewed and approved before they reach production, under a change management policy that is reviewed and approved annually. Development and production are separate environments, and engineers do not hold standing access to production or to production databases. Access for a specific project is granted deliberately, logged and reviewed.
How it is checked: Approvals recorded in the change management system and sampled in our SOC 2 Type II examination.
- ISO 27001 A.8.32 (change management)
- ISO 27001 A.8.31 (separation of development, test and production environments)
- SOC 2 Common Criteria - Change Management
Vulnerability Management
Vulnerabilities are identified continuously rather than only at audit time. Dependencies, container images and infrastructure are scanned on an ongoing basis, and findings are triaged and remediated against severity-based timelines. Critical issues are addressed immediately, with progressively longer windows for lower severities. The most recent third-party penetration test and its retest closed with no critical, high or medium findings outstanding.
How it is checked: Continuous scanning with severity-based remediation timelines, plus an annual third-party penetration test and retest.
- ISO 27001 A.8.8 (management of technical vulnerabilities)
- SOC 2 Common Criteria - Risk Assessment
Penetration Testing
We engage third-party security experts to perform a detailed penetration test of the production Harmony web application annually, followed by a retest of the findings.
How it is checked: Annual third-party penetration test and retest. A summary is available under NDA.
- ISO 27001 A.8.8 (management of technical vulnerabilities)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
All controls