Documents
What we can send you
We do not host our reports as downloads. Audit reports, questionnaires and certificates are sent by email to a named person, so that we know who holds them and can tell you if something changes. Ask and we will send them.
Under NDA
Sent by email once a mutual NDA is in place.
SOC 2 report
An independent auditor’s examination of our security, availability and confidentiality controls, including the auditor’s opinion and the tests performed. The authoritative mapping of our controls to the Trust Services Criteria.
SOC 1 report
An independent auditor’s examination of the controls relevant to your financial reporting, for teams whose auditors ask for one.
Penetration test summary
The summary letter from our most recent third-party penetration test of the Harmony application and infrastructure, including scope and the status of findings.
ISO 27001 certificate and Statement of Applicability
Our certificate, and the statement of which Annex A controls are in scope. Read alongside the control list on this page, which is the plain-language version.
Cyber Essentials certificate
Our certificate under the UK government’s Cyber Essentials scheme, assessed against the whole organisation rather than a carved-out scope. The scheme is reassessed every year, and the certificate carries a number you can verify with the certification body.
- Issued by
- IQ in IT, an IASME-accredited certification body
- Period covered
- 21 September 2026 to 21 September 2027
Data Processing Agreement (DPA)
The processor terms for customer personal data, including the Standard Contractual Clauses for transfers out of the EEA and the UK, and the subprocessor list.
GDPR assessment
Our assessment of Harmony against the GDPR obligations that apply to a processor: the roles each party holds, records of processing, the transfer mechanism for data leaving the EEA and the UK, how data subject requests reach us and are answered, retention and deletion, and the technical and organisational measures behind Article 32.
AI governance self-assessment
How our AI governance measures up against the NIST AI Risk Management Framework and the EU AI Act: where models run, what they are allowed to do, the human approval points, what is logged, and how we evaluate changes. Completed by us rather than by an auditor, which is what "self-assessment" means here.
Published
Published, and linked from this page.
Control list
Every control on this page, with the framework requirements each one speaks to. Printable in one page if you need it in a review pack.
Subprocessor list
Every third party that processes customer data, what they do, and what they see.
Privacy Policy
What personal data we process, why, and the rights you have over it.
Terms of Use
The agreement that governs your use of Harmony.
Vulnerability disclosure contact
Our RFC 9116 security.txt, so a researcher who finds something has one obvious place to look for where to send it.