# Harmony Trust Center Harmony puts AI agents to work inside your IT estate, so we start from the assumption that the AI must never reach your IT core directly. This page is what a security review needs: the frameworks we are audited against, the controls behind them, what the agents can and cannot do with your data, who we share it with, and how to get our reports. Canonical URL: https://trust.harmony.io/ Last updated: 2026-09-21 Security and privacy contact: privacy@harmony.io Live availability: https://status.harmony.io Vulnerability disclosure: https://trust.harmony.io/.well-known/security.txt ## Risk profile - Deployment model: Multi-tenant SaaS, hosted on AWS - Data location: United States (AWS) - Data subjects: Your employees and contractors who use Harmony - Encryption: AES-256 at rest, HTTPS/TLS in transit - Authentication: SAML SSO, SCIM provisioning, RBAC - Training on customer data: No, never - Sale of customer data: No, never - Customer data retention: Deleted within 30 days of workspace deletion - Subprocessors: Three, all in the United States - Availability: Live status and 90-day history - Penetration testing: Annual, by a third party - Vulnerability reports: privacy@harmony.io ## Frameworks and certifications - SOC 2 Type II: AICPA Trust Services Criteria for security, availability and confidentiality, examined over a period rather than at a point in time. - SOC 1 Type II: Controls relevant to a customer’s financial reporting, for the auditors who need assurance over a system we are part of. - ISO/IEC 27001: The international standard for an information security management system: how security is governed, not only which controls exist. - Cyber Essentials: The UK government-backed baseline: firewalls, secure configuration, user access control, malware protection and security update management. - NIST SP 800-53: The US federal catalogue of security and privacy controls, used here as the reference our control set is mapped against. - NIST AI RMF: The AI Risk Management Framework: govern, map, measure and manage the risks specific to an AI system. - EU AI Act: The European regulation on AI, which classifies systems by risk and sets obligations for transparency and human oversight. - GDPR: European data protection law. We act as a processor for customer data; a DPA is available under NDA. - CCPA: California’s privacy statute, covering the rights a resident has over personal information a business holds. - HIPAA: The US rules for protected health information, and the obligations they place on a vendor that handles it on a covered entity’s behalf. - EU-US Data Privacy Framework: The transfer mechanism for personal data moving from the EU, the UK and Switzerland to the United States. - PCI DSS: The payment card industry’s data security standard. Harmony does not store cardholder data; payments are handled by our payment processor. - CSA STAR: The Cloud Security Alliance’s registry and its Consensus Assessments questionnaire, the standard form of the cloud security review. ## Security controls ### Information Security Management Who owns security at Harmony, the policies they maintain, and what every employee is held to. #### Security Leadership The Harmony leadership team and Data Privacy Officer (DPO) are responsible for determining and updating information security measures at Harmony. Framework references (indicative): ISO 27001 A.5.2 (roles and responsibilities); GDPR Art. 37 (data protection officer) URL: https://trust.harmony.io/controls/information-security-management/security-leadership #### Information Security Policies and Procedures Harmony maintains established information security policies and procedures for all employees and contractors, covering a range of topics. Policies and procedures are approved by management, reviewed at least annually, updated as needed, and made available to all employees via our intranet. How it is checked: Approved by management and reviewed at least annually. Framework references (indicative): ISO 27001 A.5.1 (policies for information security); SOC 2 Common Criteria - Control Environment URL: https://trust.harmony.io/controls/information-security-management/information-security-policies-and-procedures #### Background Checks Harmony performs background checks on all new employees in accordance with local laws. How it is checked: Pre-employment screening, to the extent local law permits. Framework references (indicative): ISO 27001 A.6.1 (screening) URL: https://trust.harmony.io/controls/information-security-management/background-checks #### Employee Confidentiality All employee contracts include a confidentiality agreement. Framework references (indicative): ISO 27001 A.6.6 (confidentiality agreements) URL: https://trust.harmony.io/controls/information-security-management/employee-confidentiality #### Mandatory Security Awareness Training All employees undergo mandatory security awareness training on an annual basis. Certain higher risk roles go through additional training specific for their role and its associated risks, annually. How it is checked: Annually for everyone, with extra role-specific training for higher-risk roles. Framework references (indicative): ISO 27001 A.6.3 (awareness, education and training) URL: https://trust.harmony.io/controls/information-security-management/mandatory-security-awareness-training #### Access Provisioning and Offboarding Access is granted by role from a documented baseline once onboarding is complete, and requires approval from the system owner for anything touching production. On a role change, access is reviewed and anything no longer needed is removed. On termination, a documented clearance process revokes system and premises access and recovers company property, and corporate accounts are disabled the same business day. Access permissions are recertified on a regular cycle. How it is checked: A documented termination clearance process tracked in our internal IT ticket system, and periodic recertification of access permissions. Framework references (indicative): ISO 27001 A.5.18 (access rights); ISO 27001 A.6.5 (responsibilities after termination or change of employment); SOC 2 Common Criteria - Logical Access URL: https://trust.harmony.io/controls/information-security-management/access-provisioning-and-offboarding #### Risk Assessment Harmony operates a formal information security risk assessment process as part of its ISO 27001 certified ISMS. Risks to the confidentiality, integrity and availability of customer data are identified, assessed against defined criteria, assigned an owner and a treatment, and reviewed at least annually and on material change to the environment. How it is checked: Reviewed at least annually and on material change, within the certified ISMS. Framework references (indicative): ISO 27001 Clause 6.1.2 (information security risk assessment); ISO 27001 Clause 8.2 (risk assessment performance); SOC 2 Common Criteria - Risk Assessment URL: https://trust.harmony.io/controls/information-security-management/risk-assessment #### Vendor Risk Assessments We formally assess the security posture of all third-party vendors, with a higher bar for those which handle sensitive data or have access to critical systems. How it is checked: Formal assessment before onboarding, with a higher bar for vendors that handle sensitive data. Framework references (indicative): ISO 27001 A.5.19 (security in supplier relationships); SOC 2 Common Criteria - Risk Assessment URL: https://trust.harmony.io/controls/information-security-management/vendor-risk-assessments ### Network and Infrastructure Security How the platform is run on AWS: availability, logging, recovery, and who can reach production. #### Multi-Factor Authentication MFA is enforced on all access to production. Access to the production environment, the deployment pipeline and the source control system each require multi-factor authentication and are restricted to authorised personnel. Corporate accounts authenticate through our identity provider with MFA enforced, and privileged accounts are separate from day-to-day accounts. How it is checked: Tested in our SOC 2 Type II examination against production, deployment and source control access, with no deviations noted. Framework references (indicative): ISO 27001 A.5.17 (authentication information); ISO 27001 A.8.5 (secure authentication); SOC 2 Common Criteria - Logical Access URL: https://trust.harmony.io/controls/network-infrastructure-security/multi-factor-authentication #### Network Segmentation and Perimeter Protection Production runs in a segmented AWS VPC with security groups and network ACLs enforcing least-privilege traffic flows. Public endpoints sit behind a web application firewall with DDoS protection at the edge, and firewall rules are configured to permit only approved services. Administrative access to production is not exposed to the public internet and is further restricted by source IP. How it is checked: Firewall configuration and the restricted administrator list were inspected in our SOC 2 Type II examination, with no deviations noted. Framework references (indicative): ISO 27001 A.8.20 (networks security); ISO 27001 A.8.22 (segregation of networks); ISO 27001 A.8.23 (web filtering) URL: https://trust.harmony.io/controls/network-infrastructure-security/network-segmentation-and-perimeter-protection #### Auto Scaling Our infrastructure auto-scales to maintain high availability and support demand. Framework references (indicative): ISO 27001 A.8.6 (capacity management); SOC 2 Availability URL: https://trust.harmony.io/controls/network-infrastructure-security/auto-scaling #### Audit Logging and Monitoring On an application level, we produce audit logs for all activity and ship logs to a centralised logging system for analysis. All actions taken on production consoles or in the Harmony application are logged. How it is checked: Logs are shipped off the producing system to a central platform for analysis. Framework references (indicative): ISO 27001 A.8.15 (logging); ISO 27001 A.8.16 (monitoring activities); SOC 2 Common Criteria - Monitoring URL: https://trust.harmony.io/controls/network-infrastructure-security/audit-logging-and-monitoring #### Disaster Recovery Harmony was built with disaster recovery in mind. All of our infrastructure and data are spread across different availability zones and will continue to work should any one of those data centers fail. Framework references (indicative): ISO 27001 A.5.29 (information security during disruption); SOC 2 Availability URL: https://trust.harmony.io/controls/network-infrastructure-security/disaster-recovery #### Backups and Restore Testing Production data is backed up on a defined schedule under our backup policy, with point-in-time recovery for critical data. Backups are encrypted and held in a separate, access-controlled location from production, and for critical data in a geographically separate region. The restore process is performed and documented at least annually against our recovery objectives. How it is checked: Restore is performed and documented annually, and the Disaster Recovery Plan is tested annually. Framework references (indicative): ISO 27001 A.8.13 (information backup); ISO 27001 A.5.30 (ICT readiness for business continuity); SOC 2 Availability URL: https://trust.harmony.io/controls/network-infrastructure-security/backups-and-restore-testing #### Least Privilege AWS Security Groups employed for our infrastructure are baselined regularly to maintain least privilege. Access granted to team members for our AWS production environment is baselined on a regular basis to maintain least privilege. How it is checked: Security groups and production access are baselined on a regular basis. Framework references (indicative): ISO 27001 A.8.2 (privileged access rights); ISO 27001 A.5.18 (access rights) URL: https://trust.harmony.io/controls/network-infrastructure-security/least-privilege ### Data Privacy and Protection Encryption, retention and deletion for the data you put into Harmony. #### Encryption at Rest We encrypt data at rest using an industry-standard AES-256 encryption algorithm. Framework references (indicative): ISO 27001 A.8.24 (use of cryptography); SOC 2 Confidentiality URL: https://trust.harmony.io/controls/data-privacy-protection/encryption-at-rest #### Encryption in Transit Harmony is served 100% over HTTPS. All data sent to or from Harmony is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only. Framework references (indicative): ISO 27001 A.8.24 (use of cryptography); SOC 2 Confidentiality URL: https://trust.harmony.io/controls/data-privacy-protection/encryption-in-transit #### Data Retention and Disposal Policies Workspace data is deleted within 30 days of a workspace being electively deleted by its teammates. You can request deletion of your data at any time. How it is checked: Workspace data is deleted within 30 days of the workspace being deleted. Framework references (indicative): ISO 27001 A.8.10 (information deletion); GDPR Art. 5(1)(e) (storage limitation) URL: https://trust.harmony.io/controls/data-privacy-protection/data-retention-and-disposal-policies #### Key and Secrets Management Encryption keys are managed in AWS Key Management Service within our own account, with access restricted to the production role that needs it. Application secrets and credentials are held in a managed secret store, never in source code, and source repositories are scanned to enforce this. Framework references (indicative): ISO 27001 A.8.24 (use of cryptography); ISO 27001 A.5.17 (authentication information) URL: https://trust.harmony.io/controls/data-privacy-protection/key-and-secrets-management ### Product Security What the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing. #### Multi-tenancy Data Protections Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace. Framework references (indicative): SOC 2 Confidentiality; ISO 27001 A.8.4 (access to source code and data) URL: https://trust.harmony.io/controls/product-security/multi-tenancy-data-protections #### SSO You can configure Harmony with SAML Single Sign-on (SSO) using Okta, Microsoft Entra ID or another SAML 2.0 identity provider. Framework references (indicative): ISO 27001 A.5.16 (identity management); ISO 27001 A.5.17 (authentication information) URL: https://trust.harmony.io/controls/product-security/sso #### Multi-Factor Authentication Workspaces that do not federate through SAML can require multi-factor authentication for their users. Where you use your own identity provider, your MFA policy applies and Harmony enforces it through the SSO session. Framework references (indicative): ISO 27001 A.5.17 (authentication information); ISO 27001 A.8.5 (secure authentication) URL: https://trust.harmony.io/controls/product-security/workspace-multi-factor-authentication #### SCIM Provisioning Harmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning from your identity provider, including group memberships. Framework references (indicative): ISO 27001 A.5.16 (identity management); ISO 27001 A.5.18 (access rights) URL: https://trust.harmony.io/controls/product-security/scim-provisioning #### RBAC Harmony provides Role-Based Access Control (RBAC) to manage user permissions and restrict access to sensitive data and features based on assigned roles. Framework references (indicative): ISO 27001 A.5.15 (access control) URL: https://trust.harmony.io/controls/product-security/rbac #### Audit Logs Harmony maintains comprehensive audit logs of all user and administrative actions within the platform, enabling security reviews, incident investigations and compliance reporting. Framework references (indicative): ISO 27001 A.8.15 (logging) URL: https://trust.harmony.io/controls/product-security/audit-logs #### Password Complexity Harmony enforces a password complexity standard. Framework references (indicative): ISO 27001 A.5.17 (authentication information) URL: https://trust.harmony.io/controls/product-security/password-complexity #### Upload Scanning High-risk executable files are automatically restricted for all workspaces. Customers can choose which filetypes can be uploaded by users to their workspace. Allowed files are scanned for malware. Framework references (indicative): ISO 27001 A.8.7 (protection against malware) URL: https://trust.harmony.io/controls/product-security/upload-scanning #### Code Review Each pull request to the Harmony code repositories must undergo a peer review before it can be accepted and merged. How it is checked: Peer review on every pull request, enforced in the repository. Framework references (indicative): ISO 27001 A.8.28 (secure coding) URL: https://trust.harmony.io/controls/product-security/code-review #### Change Management Changes to infrastructure and software are documented, reviewed and approved before they reach production, under a change management policy that is reviewed and approved annually. Development and production are separate environments, and engineers do not hold standing access to production or to production databases. Access for a specific project is granted deliberately, logged and reviewed. How it is checked: Approvals recorded in the change management system and sampled in our SOC 2 Type II examination. Framework references (indicative): ISO 27001 A.8.32 (change management); ISO 27001 A.8.31 (separation of development, test and production environments); SOC 2 Common Criteria - Change Management URL: https://trust.harmony.io/controls/product-security/change-management #### Vulnerability Management Vulnerabilities are identified continuously rather than only at audit time. Dependencies, container images and infrastructure are scanned on an ongoing basis, and findings are triaged and remediated against severity-based timelines. Critical issues are addressed immediately, with progressively longer windows for lower severities. The most recent third-party penetration test and its retest closed with no critical, high or medium findings outstanding. How it is checked: Continuous scanning with severity-based remediation timelines, plus an annual third-party penetration test and retest. Framework references (indicative): ISO 27001 A.8.8 (management of technical vulnerabilities); SOC 2 Common Criteria - Risk Assessment URL: https://trust.harmony.io/controls/product-security/vulnerability-management #### Penetration Testing We engage third-party security experts to perform a detailed penetration test of the production Harmony web application annually, followed by a retest of the findings. How it is checked: Annual third-party penetration test and retest. A summary is available under NDA. Framework references (indicative): ISO 27001 A.8.8 (management of technical vulnerabilities) URL: https://trust.harmony.io/controls/product-security/penetration-testing ### AI and Agent Controls What the agents can and cannot do, who approves the sensitive actions, and what record each run leaves. #### Scoped Integration Access An agent can retrieve only from the knowledge sources and call only the tools that a workspace administrator has connected for it. There is no ambient access to systems outside that grant, and each integration is scoped to the permissions it was given rather than to the permissions of the person who connected it. Framework references (indicative): ISO 27001 A.5.15 (access control); NIST AI RMF MANAGE 2.1; SOC 2 Confidentiality URL: https://trust.harmony.io/controls/ai-agent-controls/scoped-integration-access #### Human Approval on Sensitive Actions Actions that change state in a connected system can require an approver before they run. Sensitive actions are gated by default and the gate is configurable per workspace, so an administrator decides where the agent acts on its own and where a person signs off first. Framework references (indicative): ISO 27001 A.5.15 (access control); NIST AI RMF MANAGE 4.1; EU AI Act Art. 14 (human oversight) URL: https://trust.harmony.io/controls/ai-agent-controls/human-approval-on-sensitive-actions #### Deterministic Execution for State-Changing Operations Anything that changes state runs through a deterministic flow rather than through free-form model output. The model chooses which flow to invoke and with what inputs; the flow itself is code, with its own validation and its own permissions. Framework references (indicative): NIST AI RMF MEASURE 2.6; ISO 27001 A.8.28 (secure coding) URL: https://trust.harmony.io/controls/ai-agent-controls/deterministic-execution #### Agent Run Audit Record Every agent run produces a step-by-step record of what it retrieved, which tools it called, what it changed and why. The record is available to workspace administrators and is retained with the rest of the workspace audit log. How it is checked: Produced automatically for every run, and retained with the workspace audit log. Framework references (indicative): ISO 27001 A.8.15 (logging); NIST AI RMF GOVERN 1.5; EU AI Act Art. 12 (record-keeping) URL: https://trust.harmony.io/controls/ai-agent-controls/agent-run-audit-record ### Incident Detection and Response What happens when something goes wrong, and how quickly someone is looking at it. #### Incident Response Process Harmony implements a protocol for handling security events which includes escalation procedures, rapid mitigation and post mortem. All employees are informed of our policies. Framework references (indicative): ISO 27001 A.5.24 (incident management planning); ISO 27001 A.5.27 (learning from incidents) URL: https://trust.harmony.io/controls/incident-detection-response/incident-response-process #### On-call Coverage A member of engineering is on-call 24/7 to respond to alerts and pages. They can escalate directly to a security team member as needed. How it is checked: 24/7 engineering on-call rotation, with escalation to security. Framework references (indicative): SOC 2 Availability; ISO 27001 A.5.26 (response to incidents) URL: https://trust.harmony.io/controls/incident-detection-response/on-call-coverage #### Breach Notification If a security incident affects your data, we notify you without undue delay and within 72 hours of becoming aware of it, with what we know at the time and what we are doing about it. Notification duties and contacts are set out in our Data Processing Agreement. Harmony has not experienced a material security incident requiring customer or regulator notification. Framework references (indicative): GDPR Art. 33 (notification of a personal data breach); ISO 27001 A.5.26 (response to information security incidents); SOC 2 Common Criteria - Communication URL: https://trust.harmony.io/controls/incident-detection-response/breach-notification #### Vulnerability Disclosure Suspected vulnerabilities can be reported to privacy@harmony.io, published for researchers at /.well-known/security.txt. We acknowledge every report, keep the reporter updated through triage and remediation, and will not pursue researchers who report in good faith. Framework references (indicative): ISO 27001 A.6.8 (information security event reporting); RFC 9116 (security.txt) URL: https://trust.harmony.io/controls/incident-detection-response/vulnerability-disclosure ### Corporate and Physical Security How the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled. #### Endpoint Encryption All corporate devices are encrypted to protect data in case of loss or theft. They can be remotely wiped to prevent data leakage if a device is compromised or lost. Framework references (indicative): ISO 27001 A.8.1 (user endpoint devices); ISO 27001 A.8.24 (use of cryptography) URL: https://trust.harmony.io/controls/endpoint-security/endpoint-encryption #### Endpoint Management We push updates to employee laptops such that they are on the latest, patched version of their required operating system. We require the use of a managed browser with only an approved set of browser extensions. Framework references (indicative): ISO 27001 A.8.1 (user endpoint devices); ISO 27001 A.8.8 (management of technical vulnerabilities) URL: https://trust.harmony.io/controls/endpoint-security/endpoint-management #### Physical and Environmental Security Harmony operates no data centres of its own. All customer data is held in AWS facilities, whose physical and environmental controls are covered by AWS’s own audited certifications. Harmony offices are access-controlled, and visitors are received rather than given unaccompanied access. Framework references (indicative): ISO 27001 A.7.1 (physical security perimeters); ISO 27001 A.7.2 (physical entry); ISO 27001 A.7.4 (physical security monitoring) URL: https://trust.harmony.io/controls/endpoint-security/physical-and-environmental-security ## AI and agents - LLM hosted on our cloud: The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them. - No training on customer data: Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model. - Never sold, never brokered: Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our subprocessor list, strictly to deliver the service. - One workspace cannot see another: Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace. - Only the context you granted: An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant. - Storage, retention and deletion: Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at privacy@harmony.io. How agent access is bounded: - Nothing is connected until an admin connects it. There is no ambient access to a system Harmony was not given. - Every integration has a scope ceiling set by an admin. An agent calls the tools it was granted, and nothing else. - Anything that changes state runs as a deterministic flow you can read before you ship it, not as improvisation by a model. - Sensitive actions wait for a named approver by default, and the decision is recorded. - Every run produces a step-by-step audit record of what the agent did and why. - Disconnecting an integration revokes Harmony’s access to it. The NIST AI Risk Management Framework and the EU AI Act are the AI-specific frameworks we build and govern against. Neither is a certification and we do not present them as one. The controls on this page are where the work behind them shows up: scoped access per integration, an approver on sensitive actions, deterministic flows for anything that changes state, and a step-by-step audit record of every agent run. ## Documents We do not host our reports as downloads. Audit reports, questionnaires and certificates are sent by email to a named person, so that we know who holds them and can tell you if something changes. Ask and we will send them. ### SOC 2 report An independent auditor’s examination of our security, availability and confidentiality controls, including the auditor’s opinion and the tests performed. The authoritative mapping of our controls to the Trust Services Criteria. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### SOC 1 report An independent auditor’s examination of the controls relevant to your financial reporting, for teams whose auditors ask for one. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### Penetration test summary The summary letter from our most recent third-party penetration test of the Harmony application and infrastructure, including scope and the status of findings. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### ISO 27001 certificate and Statement of Applicability Our certificate, and the statement of which Annex A controls are in scope. Read alongside the control list on this page, which is the plain-language version. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### Cyber Essentials certificate Our certificate under the UK government’s Cyber Essentials scheme, assessed against the whole organisation rather than a carved-out scope. The scheme is reassessed every year, and the certificate carries a number you can verify with the certification body. Availability: Under NDA. Sent by email once a mutual NDA is in place. Issued by: IQ in IT, an IASME-accredited certification body Period covered: 21 September 2026 to 21 September 2027 ### Data Processing Agreement (DPA) The processor terms for customer personal data, including the Standard Contractual Clauses for transfers out of the EEA and the UK, and the subprocessor list. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### GDPR assessment Our assessment of Harmony against the GDPR obligations that apply to a processor: the roles each party holds, records of processing, the transfer mechanism for data leaving the EEA and the UK, how data subject requests reach us and are answered, retention and deletion, and the technical and organisational measures behind Article 32. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### AI governance self-assessment How our AI governance measures up against the NIST AI Risk Management Framework and the EU AI Act: where models run, what they are allowed to do, the human approval points, what is logged, and how we evaluate changes. Completed by us rather than by an auditor, which is what "self-assessment" means here. Availability: Under NDA. Sent by email once a mutual NDA is in place. ### Control list Every control on this page, with the framework requirements each one speaks to. Printable in one page if you need it in a review pack. Availability: Public. Published, and linked from this page. URL: https://trust.harmony.io/print ### Subprocessor list Every third party that processes customer data, what they do, and what they see. Availability: Public. Published, and linked from this page. URL: https://trust.harmony.io/subprocessors ### Privacy Policy What personal data we process, why, and the rights you have over it. Availability: Public. Published, and linked from this page. URL: https://trust.harmony.iohttps://harmony.io/privacy ### Terms of Use The agreement that governs your use of Harmony. Availability: Public. Published, and linked from this page. URL: https://trust.harmony.iohttps://harmony.io/terms ### Cookies Notice The cookies harmony.io sets, and how to control them. Availability: Public. Published, and linked from this page. URL: https://trust.harmony.iohttps://harmony.io/cookies-notice ### Vulnerability disclosure contact Our RFC 9116 security.txt, so a researcher who finds something has one obvious place to look for where to send it. Availability: Public. Published, and linked from this page. URL: https://trust.harmony.io/.well-known/security.txt Request any of these at https://trust.harmony.io/request or by emailing privacy@harmony.io. ## Subprocessors Every subprocessor is contracted under a data processing agreement that includes the European Commission’s Standard Contractual Clauses for transfers out of the EEA and the UK, and is assessed before onboarding under the vendor risk control on this page. Our DPA lists them, and we will tell you before a new one starts processing customer data. On models specifically: the models Harmony runs are hosted on AWS inside our own account, your prompts and context are not handed to a consumer AI product, and no model provider retains them. If you need the exact models and providers in scope for your workspace named in writing, ask us and we will put it in writing. ### Amazon Web Services, Inc. Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account. Customer data it can see: All customer data: request and conversation content, attachments, directory and device records synced from your connected tools, and audit logs. Location: United States Transfer mechanism: data processing agreement including the EU Standard Contractual Clauses and the UK Addendum ### Descope, Inc. Authentication provider. Handles sign-in, session issuance and SSO federation. Customer data it can see: Account identifiers and authentication metadata: name, work email address, identity provider and sign-in events. No request content. Location: United States Transfer mechanism: data processing agreement including the EU Standard Contractual Clauses and the UK Addendum ### PostHog, Inc. Product analytics. How the product is used, so we can see what is and is not working. Customer data it can see: Product usage events and the account identifiers attached to them. No request content and no attachments. Location: United States Transfer mechanism: data processing agreement including the EU Standard Contractual Clauses and the UK Addendum ## What we process as a processor - Directory and identity data: Yes - Names, work email addresses, job details and group memberships, synced from the identity provider and HR system an admin connected. - Request and conversation content: Yes - What your employees ask Harmony, the agent’s replies, and anything they attach. Retained for the workspace and deleted with it. - Device and asset records: Yes - Device, asset and licence records read from the endpoint and asset tools an admin connected. - Special category data: No - Not required by the service and never requested by it. Harmony does not ask for health, biometric, or racial or ethnic origin data. - Payment card data: No - Never processed or stored in the Harmony platform. ## What we process as a controller - Employee personal data: Yes - Our own employees and contractors, for employment and access management. - Business contact data: Yes - Names, work email addresses and company details of the people we talk to about Harmony. - Website analytics: Yes - Usage of harmony.io and this page. See the Cookies Notice at https://harmony.io/cookies-notice. ## Questions asked in review ### How do I report a security issue or concern? Email privacy@harmony.io. Please include enough detail for us to reproduce the issue. We acknowledge reports and keep you updated through triage and remediation. The same contact is published for researchers at https://trust.harmony.io/.well-known/security.txt. URL: https://trust.harmony.io/faq#q1 ### How do I get your SOC 2 report? Ask us at privacy@harmony.io, or use the request form on this page. Reports go out by email once a mutual NDA is in place - we do not host them as downloads, so that we know who holds a copy and can tell you if something changes. URL: https://trust.harmony.io/faq#q2 ### How is customer data protected? We implement multiple layers of security including encryption at rest and in transit, access controls, and regular security audits. URL: https://trust.harmony.io/faq#q3 ### Where is customer data stored? Customer data is stored in secure, compliant data centers with our primary cloud provider Amazon Web Services in the USA. URL: https://trust.harmony.io/faq#q4 ### Does Harmony use customer data to train AI models? No. Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service and is never used for training, fine-tuning, or improving any AI or machine learning models. URL: https://trust.harmony.io/faq#q5 ### Does Harmony sell customer data to third parties? No. Harmony does not sell customer data to any third parties. We share data only with the subprocessors published in our Trust Center, strictly to deliver our services. URL: https://trust.harmony.io/faq#q6 ### How can I request deletion of my data? You can submit a data deletion request at any time by emailing privacy@harmony.io. We will process your request in accordance with applicable law and our data retention policy. URL: https://trust.harmony.io/faq#q7 ### Is Harmony GDPR compliant? Yes. Harmony is fully compliant with the General Data Protection Regulation (GDPR). We act as a data processor for our customers' data. We offer a Data Processing Agreement (DPA) that you can request by contacting privacy@harmony.io. URL: https://trust.harmony.io/faq#q8 ### Does Harmony support single sign-on (SSO)? Yes. Harmony supports SAML-based single sign-on with providers including Okta, Microsoft Entra ID, and other SAML 2.0-compatible identity providers. URL: https://trust.harmony.io/faq#q9 ### Does Harmony support SCIM provisioning? Yes. Harmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning directly from your identity provider. This allows you to automatically sync user accounts and group memberships without manual administration. URL: https://trust.harmony.io/faq#q10 ### Does Harmony support role-based access control (RBAC)? Yes. Harmony provides role-based access control so administrators can assign roles to users and control access to features and data based on those roles. This helps organizations enforce least-privilege access and meet compliance requirements. URL: https://trust.harmony.io/faq#q11 ### Does Harmony provide audit logs? Yes. Harmony maintains comprehensive audit logs of all user and administrative actions within the platform. Audit logs capture who did what and when, enabling security reviews, incident investigations, and compliance reporting. URL: https://trust.harmony.io/faq#q12 ### Can an AI agent take an action in my systems without approval? Only if you configure it that way. Sensitive actions wait for an explicit approver by default, every integration has a scope ceiling set by an admin, and each run produces a step-by-step audit log of what the agent did and why. URL: https://trust.harmony.io/faq#q13 ### Which third parties can see our data? Three, all of them in the United States: AWS for infrastructure and model hosting, Descope for authentication, and PostHog for product analytics. The subprocessor page on this site says what each of them can see, and our DPA lists them contractually. URL: https://trust.harmony.io/faq#q14 ### Do you support on-premises or single-tenant deployment? Harmony is a multi-tenant SaaS platform hosted on AWS in the United States, with safeguards that stop data from one workspace being used or displayed in another. If your requirements go beyond that, talk to us at privacy@harmony.io rather than assuming the answer either way. URL: https://trust.harmony.io/faq#q15