FAQ
Questions we are asked in review
Every answer here is on the page as text, not behind a toggle - so it can be searched, quoted into a questionnaire, and read by whatever is summarising this page for your team.
How do I report a security issue or concern?
Email privacy@harmony.io. Please include enough detail for us to reproduce the issue. We acknowledge reports and keep you updated through triage and remediation. The same contact is published for researchers at https://trust.harmony.io/.well-known/security.txt.
How do I get your SOC 2 report?
Ask us at privacy@harmony.io, or use the request form on this page. Reports go out by email once a mutual NDA is in place - we do not host them as downloads, so that we know who holds a copy and can tell you if something changes.
How is customer data protected?
We implement multiple layers of security including encryption at rest and in transit, access controls, and regular security audits.
Where is customer data stored?
Customer data is stored in secure, compliant data centers with our primary cloud provider Amazon Web Services in the USA.
Does Harmony use customer data to train AI models?
No. Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service and is never used for training, fine-tuning, or improving any AI or machine learning models.
Does Harmony sell customer data to third parties?
No. Harmony does not sell customer data to any third parties. We share data only with the subprocessors published in our Trust Center, strictly to deliver our services.
How can I request deletion of my data?
You can submit a data deletion request at any time by emailing privacy@harmony.io. We will process your request in accordance with applicable law and our data retention policy.
Is Harmony GDPR compliant?
Yes. Harmony is fully compliant with the General Data Protection Regulation (GDPR). We act as a data processor for our customers' data. We offer a Data Processing Agreement (DPA) that you can request by contacting privacy@harmony.io.
Does Harmony support single sign-on (SSO)?
Yes. Harmony supports SAML-based single sign-on with providers including Okta, Microsoft Entra ID, and other SAML 2.0-compatible identity providers.
Does Harmony support SCIM provisioning?
Yes. Harmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning directly from your identity provider. This allows you to automatically sync user accounts and group memberships without manual administration.
Does Harmony support role-based access control (RBAC)?
Yes. Harmony provides role-based access control so administrators can assign roles to users and control access to features and data based on those roles. This helps organizations enforce least-privilege access and meet compliance requirements.
Does Harmony provide audit logs?
Yes. Harmony maintains comprehensive audit logs of all user and administrative actions within the platform. Audit logs capture who did what and when, enabling security reviews, incident investigations, and compliance reporting.
Can an AI agent take an action in my systems without approval?
Only if you configure it that way. Sensitive actions wait for an explicit approver by default, every integration has a scope ceiling set by an admin, and each run produces a step-by-step audit log of what the agent did and why.
Which third parties can see our data?
Three, all of them in the United States: AWS for infrastructure and model hosting, Descope for authentication, and PostHog for product analytics. The subprocessor page on this site says what each of them can see, and our DPA lists them contractually.
Do you support on-premises or single-tenant deployment?
Harmony is a multi-tenant SaaS platform hosted on AWS in the United States, with safeguards that stop data from one workspace being used or displayed in another. If your requirements go beyond that, talk to us at privacy@harmony.io rather than assuming the answer either way.
Not here?
Send us the question, or send us your questionnaire and we will complete it. We would rather answer the thing you actually asked than point you at something adjacent to it.