# Harmony Trust Center > Harmony builds AI agents that resolve employee IT and HR requests. This site is what > a security review needs: the frameworks we are audited against, every control behind > them, what the agents can and cannot do with customer data, our subprocessors, and how > to get our SOC 2 report and other documents. Nothing here is downloadable - reports > are sent by email to a named recipient, under NDA where one applies. Last updated: 2026-09-21. Security and privacy contact: privacy@harmony.io. Every claim on this site is maintained as code in the repository that serves it, so the answer a page gives today is the answer it gave when it was deployed. ## Pages - [Harmony Trust Center | Security, Privacy and Compliance](https://trust.harmony.io/): Harmony’s Trust Center: our certifications and frameworks, the full control list, what AI agents do with your data, our subprocessors, and how to request our SOC 2 report and other documents. - [Security controls](https://trust.harmony.io/controls): Every security control Harmony operates, across information security management, network and infrastructure security, data privacy and protection, product security, ai and agent controls, incident detection and response, corporate and physical security - each mapped to the framework requirements it speaks to. - [Documents](https://trust.harmony.io/documents): Every document Harmony can give you for a security review - SOC 2 and SOC 1 reports, penetration test summary, ISO 27001 certificate, DPA, and our GDPR and AI governance assessments - with what each one covers and how to get it. - [AI and agents](https://trust.harmony.io/ai): How Harmony governs its AI agents: models hosted in our own AWS account, no training on customer data, no data sold, one workspace never sees another, four layers between a request and a change in your systems, and what an agent reads and writes in each system you connect. - [Subprocessors](https://trust.harmony.io/subprocessors): Every third party that processes Harmony customer data: what they do, exactly what they can see, where the processing happens, and the transfer mechanism. Three subprocessors, all in the United States. - [FAQ](https://trust.harmony.io/faq): Answers to the questions security reviews ask Harmony most: how to get our SOC 2 report, where data is stored, whether we train on customer data, SSO and SCIM, audit logs, GDPR, deletion, and which third parties can see your data. - [Request documents](https://trust.harmony.io/request): Request Harmony’s SOC 2 Type II report, ISO 27001 certificate, penetration test summary, DPA, or our GDPR and AI governance assessments. Sent by email to a named recipient - nothing is downloadable from this page. ## Security controls - [Information Security Management](https://trust.harmony.io/controls/information-security-management): Who owns security at Harmony, the policies they maintain, and what every employee is held to. - [Information Security Management: Security Leadership](https://trust.harmony.io/controls/information-security-management/security-leadership): The Harmony leadership team and Data Privacy Officer (DPO) are responsible for determining and updating information security measures at Harmony. - [Information Security Management: Information Security Policies and Procedures](https://trust.harmony.io/controls/information-security-management/information-security-policies-and-procedures): Harmony maintains established information security policies and procedures for all employees and contractors, covering a range of topics. Policies and procedures are approved by management, reviewed at least annually, updated as needed, and made available to all employees via our intranet. How it is checked: Approved by management and reviewed at least annually. - [Information Security Management: Background Checks](https://trust.harmony.io/controls/information-security-management/background-checks): Harmony performs background checks on all new employees in accordance with local laws. How it is checked: Pre-employment screening, to the extent local law permits. - [Information Security Management: Employee Confidentiality](https://trust.harmony.io/controls/information-security-management/employee-confidentiality): All employee contracts include a confidentiality agreement. - [Information Security Management: Mandatory Security Awareness Training](https://trust.harmony.io/controls/information-security-management/mandatory-security-awareness-training): All employees undergo mandatory security awareness training on an annual basis. Certain higher risk roles go through additional training specific for their role and its associated risks, annually. How it is checked: Annually for everyone, with extra role-specific training for higher-risk roles. - [Information Security Management: Access Provisioning and Offboarding](https://trust.harmony.io/controls/information-security-management/access-provisioning-and-offboarding): Access is granted by role from a documented baseline once onboarding is complete, and requires approval from the system owner for anything touching production. On a role change, access is reviewed and anything no longer needed is removed. On termination, a documented clearance process revokes system and premises access and recovers company property, and corporate accounts are disabled the same business day. Access permissions are recertified on a regular cycle. How it is checked: A documented termination clearance process tracked in our internal IT ticket system, and periodic recertification of access permissions. - [Information Security Management: Risk Assessment](https://trust.harmony.io/controls/information-security-management/risk-assessment): Harmony operates a formal information security risk assessment process as part of its ISO 27001 certified ISMS. Risks to the confidentiality, integrity and availability of customer data are identified, assessed against defined criteria, assigned an owner and a treatment, and reviewed at least annually and on material change to the environment. How it is checked: Reviewed at least annually and on material change, within the certified ISMS. - [Information Security Management: Vendor Risk Assessments](https://trust.harmony.io/controls/information-security-management/vendor-risk-assessments): We formally assess the security posture of all third-party vendors, with a higher bar for those which handle sensitive data or have access to critical systems. How it is checked: Formal assessment before onboarding, with a higher bar for vendors that handle sensitive data. - [Network and Infrastructure Security](https://trust.harmony.io/controls/network-infrastructure-security): How the platform is run on AWS: availability, logging, recovery, and who can reach production. - [Network and Infrastructure Security: Multi-Factor Authentication](https://trust.harmony.io/controls/network-infrastructure-security/multi-factor-authentication): MFA is enforced on all access to production. Access to the production environment, the deployment pipeline and the source control system each require multi-factor authentication and are restricted to authorised personnel. Corporate accounts authenticate through our identity provider with MFA enforced, and privileged accounts are separate from day-to-day accounts. How it is checked: Tested in our SOC 2 Type II examination against production, deployment and source control access, with no deviations noted. - [Network and Infrastructure Security: Network Segmentation and Perimeter Protection](https://trust.harmony.io/controls/network-infrastructure-security/network-segmentation-and-perimeter-protection): Production runs in a segmented AWS VPC with security groups and network ACLs enforcing least-privilege traffic flows. Public endpoints sit behind a web application firewall with DDoS protection at the edge, and firewall rules are configured to permit only approved services. Administrative access to production is not exposed to the public internet and is further restricted by source IP. How it is checked: Firewall configuration and the restricted administrator list were inspected in our SOC 2 Type II examination, with no deviations noted. - [Network and Infrastructure Security: Auto Scaling](https://trust.harmony.io/controls/network-infrastructure-security/auto-scaling): Our infrastructure auto-scales to maintain high availability and support demand. - [Network and Infrastructure Security: Audit Logging and Monitoring](https://trust.harmony.io/controls/network-infrastructure-security/audit-logging-and-monitoring): On an application level, we produce audit logs for all activity and ship logs to a centralised logging system for analysis. All actions taken on production consoles or in the Harmony application are logged. How it is checked: Logs are shipped off the producing system to a central platform for analysis. - [Network and Infrastructure Security: Disaster Recovery](https://trust.harmony.io/controls/network-infrastructure-security/disaster-recovery): Harmony was built with disaster recovery in mind. All of our infrastructure and data are spread across different availability zones and will continue to work should any one of those data centers fail. - [Network and Infrastructure Security: Backups and Restore Testing](https://trust.harmony.io/controls/network-infrastructure-security/backups-and-restore-testing): Production data is backed up on a defined schedule under our backup policy, with point-in-time recovery for critical data. Backups are encrypted and held in a separate, access-controlled location from production, and for critical data in a geographically separate region. The restore process is performed and documented at least annually against our recovery objectives. How it is checked: Restore is performed and documented annually, and the Disaster Recovery Plan is tested annually. - [Network and Infrastructure Security: Least Privilege](https://trust.harmony.io/controls/network-infrastructure-security/least-privilege): AWS Security Groups employed for our infrastructure are baselined regularly to maintain least privilege. Access granted to team members for our AWS production environment is baselined on a regular basis to maintain least privilege. How it is checked: Security groups and production access are baselined on a regular basis. - [Data Privacy and Protection](https://trust.harmony.io/controls/data-privacy-protection): Encryption, retention and deletion for the data you put into Harmony. - [Data Privacy and Protection: Encryption at Rest](https://trust.harmony.io/controls/data-privacy-protection/encryption-at-rest): We encrypt data at rest using an industry-standard AES-256 encryption algorithm. - [Data Privacy and Protection: Encryption in Transit](https://trust.harmony.io/controls/data-privacy-protection/encryption-in-transit): Harmony is served 100% over HTTPS. All data sent to or from Harmony is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only. - [Data Privacy and Protection: Data Retention and Disposal Policies](https://trust.harmony.io/controls/data-privacy-protection/data-retention-and-disposal-policies): Workspace data is deleted within 30 days of a workspace being electively deleted by its teammates. You can request deletion of your data at any time. How it is checked: Workspace data is deleted within 30 days of the workspace being deleted. - [Data Privacy and Protection: Key and Secrets Management](https://trust.harmony.io/controls/data-privacy-protection/key-and-secrets-management): Encryption keys are managed in AWS Key Management Service within our own account, with access restricted to the production role that needs it. Application secrets and credentials are held in a managed secret store, never in source code, and source repositories are scanned to enforce this. - [Product Security](https://trust.harmony.io/controls/product-security): What the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing. - [Product Security: Multi-tenancy Data Protections](https://trust.harmony.io/controls/product-security/multi-tenancy-data-protections): Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace. - [Product Security: SSO](https://trust.harmony.io/controls/product-security/sso): You can configure Harmony with SAML Single Sign-on (SSO) using Okta, Microsoft Entra ID or another SAML 2.0 identity provider. - [Product Security: Multi-Factor Authentication](https://trust.harmony.io/controls/product-security/workspace-multi-factor-authentication): Workspaces that do not federate through SAML can require multi-factor authentication for their users. Where you use your own identity provider, your MFA policy applies and Harmony enforces it through the SSO session. - [Product Security: SCIM Provisioning](https://trust.harmony.io/controls/product-security/scim-provisioning): Harmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning from your identity provider, including group memberships. - [Product Security: RBAC](https://trust.harmony.io/controls/product-security/rbac): Harmony provides Role-Based Access Control (RBAC) to manage user permissions and restrict access to sensitive data and features based on assigned roles. - [Product Security: Audit Logs](https://trust.harmony.io/controls/product-security/audit-logs): Harmony maintains comprehensive audit logs of all user and administrative actions within the platform, enabling security reviews, incident investigations and compliance reporting. - [Product Security: Password Complexity](https://trust.harmony.io/controls/product-security/password-complexity): Harmony enforces a password complexity standard. - [Product Security: Upload Scanning](https://trust.harmony.io/controls/product-security/upload-scanning): High-risk executable files are automatically restricted for all workspaces. Customers can choose which filetypes can be uploaded by users to their workspace. Allowed files are scanned for malware. - [Product Security: Code Review](https://trust.harmony.io/controls/product-security/code-review): Each pull request to the Harmony code repositories must undergo a peer review before it can be accepted and merged. How it is checked: Peer review on every pull request, enforced in the repository. - [Product Security: Change Management](https://trust.harmony.io/controls/product-security/change-management): Changes to infrastructure and software are documented, reviewed and approved before they reach production, under a change management policy that is reviewed and approved annually. Development and production are separate environments, and engineers do not hold standing access to production or to production databases. Access for a specific project is granted deliberately, logged and reviewed. How it is checked: Approvals recorded in the change management system and sampled in our SOC 2 Type II examination. - [Product Security: Vulnerability Management](https://trust.harmony.io/controls/product-security/vulnerability-management): Vulnerabilities are identified continuously rather than only at audit time. Dependencies, container images and infrastructure are scanned on an ongoing basis, and findings are triaged and remediated against severity-based timelines. Critical issues are addressed immediately, with progressively longer windows for lower severities. The most recent third-party penetration test and its retest closed with no critical, high or medium findings outstanding. How it is checked: Continuous scanning with severity-based remediation timelines, plus an annual third-party penetration test and retest. - [Product Security: Penetration Testing](https://trust.harmony.io/controls/product-security/penetration-testing): We engage third-party security experts to perform a detailed penetration test of the production Harmony web application annually, followed by a retest of the findings. How it is checked: Annual third-party penetration test and retest. A summary is available under NDA. - [AI and Agent Controls](https://trust.harmony.io/controls/ai-agent-controls): What the agents can and cannot do, who approves the sensitive actions, and what record each run leaves. - [AI and Agent Controls: Scoped Integration Access](https://trust.harmony.io/controls/ai-agent-controls/scoped-integration-access): An agent can retrieve only from the knowledge sources and call only the tools that a workspace administrator has connected for it. There is no ambient access to systems outside that grant, and each integration is scoped to the permissions it was given rather than to the permissions of the person who connected it. - [AI and Agent Controls: Human Approval on Sensitive Actions](https://trust.harmony.io/controls/ai-agent-controls/human-approval-on-sensitive-actions): Actions that change state in a connected system can require an approver before they run. Sensitive actions are gated by default and the gate is configurable per workspace, so an administrator decides where the agent acts on its own and where a person signs off first. - [AI and Agent Controls: Deterministic Execution for State-Changing Operations](https://trust.harmony.io/controls/ai-agent-controls/deterministic-execution): Anything that changes state runs through a deterministic flow rather than through free-form model output. The model chooses which flow to invoke and with what inputs; the flow itself is code, with its own validation and its own permissions. - [AI and Agent Controls: Agent Run Audit Record](https://trust.harmony.io/controls/ai-agent-controls/agent-run-audit-record): Every agent run produces a step-by-step record of what it retrieved, which tools it called, what it changed and why. The record is available to workspace administrators and is retained with the rest of the workspace audit log. How it is checked: Produced automatically for every run, and retained with the workspace audit log. - [Incident Detection and Response](https://trust.harmony.io/controls/incident-detection-response): What happens when something goes wrong, and how quickly someone is looking at it. - [Incident Detection and Response: Incident Response Process](https://trust.harmony.io/controls/incident-detection-response/incident-response-process): Harmony implements a protocol for handling security events which includes escalation procedures, rapid mitigation and post mortem. All employees are informed of our policies. - [Incident Detection and Response: On-call Coverage](https://trust.harmony.io/controls/incident-detection-response/on-call-coverage): A member of engineering is on-call 24/7 to respond to alerts and pages. They can escalate directly to a security team member as needed. How it is checked: 24/7 engineering on-call rotation, with escalation to security. - [Incident Detection and Response: Breach Notification](https://trust.harmony.io/controls/incident-detection-response/breach-notification): If a security incident affects your data, we notify you without undue delay and within 72 hours of becoming aware of it, with what we know at the time and what we are doing about it. Notification duties and contacts are set out in our Data Processing Agreement. Harmony has not experienced a material security incident requiring customer or regulator notification. - [Incident Detection and Response: Vulnerability Disclosure](https://trust.harmony.io/controls/incident-detection-response/vulnerability-disclosure): Suspected vulnerabilities can be reported to privacy@harmony.io, published for researchers at /.well-known/security.txt. We acknowledge every report, keep the reporter updated through triage and remediation, and will not pursue researchers who report in good faith. - [Corporate and Physical Security](https://trust.harmony.io/controls/endpoint-security): How the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled. - [Corporate and Physical Security: Endpoint Encryption](https://trust.harmony.io/controls/endpoint-security/endpoint-encryption): All corporate devices are encrypted to protect data in case of loss or theft. They can be remotely wiped to prevent data leakage if a device is compromised or lost. - [Corporate and Physical Security: Endpoint Management](https://trust.harmony.io/controls/endpoint-security/endpoint-management): We push updates to employee laptops such that they are on the latest, patched version of their required operating system. We require the use of a managed browser with only an approved set of browser extensions. - [Corporate and Physical Security: Physical and Environmental Security](https://trust.harmony.io/controls/endpoint-security/physical-and-environmental-security): Harmony operates no data centres of its own. All customer data is held in AWS facilities, whose physical and environmental controls are covered by AWS’s own audited certifications. Harmony offices are access-controlled, and visitors are received rather than given unaccompanied access. ## Documents - [SOC 2 report](https://trust.harmony.io/documents#soc-2): Under NDA. An independent auditor’s examination of our security, availability and confidentiality controls, including the auditor’s opinion and the tests performed. The authoritative mapping of our controls to the Trust Services Criteria. - [SOC 1 report](https://trust.harmony.io/documents#soc-1): Under NDA. An independent auditor’s examination of the controls relevant to your financial reporting, for teams whose auditors ask for one. - [Penetration test summary](https://trust.harmony.io/documents#penetration-test-summary): Under NDA. The summary letter from our most recent third-party penetration test of the Harmony application and infrastructure, including scope and the status of findings. - [ISO 27001 certificate and Statement of Applicability](https://trust.harmony.io/documents#iso-27001-certificate): Under NDA. Our certificate, and the statement of which Annex A controls are in scope. Read alongside the control list on this page, which is the plain-language version. - [Cyber Essentials certificate](https://trust.harmony.io/documents#cyber-essentials-certificate): Under NDA. Our certificate under the UK government’s Cyber Essentials scheme, assessed against the whole organisation rather than a carved-out scope. The scheme is reassessed every year, and the certificate carries a number you can verify with the certification body. - [Data Processing Agreement (DPA)](https://trust.harmony.io/documents#dpa): Under NDA. The processor terms for customer personal data, including the Standard Contractual Clauses for transfers out of the EEA and the UK, and the subprocessor list. - [GDPR assessment](https://trust.harmony.io/documents#gdpr-assessment): Under NDA. Our assessment of Harmony against the GDPR obligations that apply to a processor: the roles each party holds, records of processing, the transfer mechanism for data leaving the EEA and the UK, how data subject requests reach us and are answered, retention and deletion, and the technical and organisational measures behind Article 32. - [AI governance self-assessment](https://trust.harmony.io/documents#ai-governance-self-assessment): Under NDA. How our AI governance measures up against the NIST AI Risk Management Framework and the EU AI Act: where models run, what they are allowed to do, the human approval points, what is logged, and how we evaluate changes. Completed by us rather than by an auditor, which is what "self-assessment" means here. - [Control list](https://trust.harmony.io/print): Public. Every control on this page, with the framework requirements each one speaks to. Printable in one page if you need it in a review pack. - [Subprocessor list](https://trust.harmony.io/subprocessors): Public. Every third party that processes customer data, what they do, and what they see. - [Privacy Policy](https://trust.harmony.iohttps://harmony.io/privacy): Public. What personal data we process, why, and the rights you have over it. - [Terms of Use](https://trust.harmony.iohttps://harmony.io/terms): Public. The agreement that governs your use of Harmony. - [Cookies Notice](https://trust.harmony.iohttps://harmony.io/cookies-notice): Public. The cookies harmony.io sets, and how to control them. - [Vulnerability disclosure contact](https://trust.harmony.io/.well-known/security.txt): Public. Our RFC 9116 security.txt, so a researcher who finds something has one obvious place to look for where to send it. ## Subprocessors - [Amazon Web Services, Inc.](https://trust.harmony.io/subprocessors): Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account. Processes in United States. Can see: All customer data: request and conversation content, attachments, directory and device records synced from your connected tools, and audit logs. - [Descope, Inc.](https://trust.harmony.io/subprocessors): Authentication provider. Handles sign-in, session issuance and SSO federation. Processes in United States. Can see: Account identifiers and authentication metadata: name, work email address, identity provider and sign-in events. No request content. - [PostHog, Inc.](https://trust.harmony.io/subprocessors): Product analytics. How the product is used, so we can see what is and is not working. Processes in United States. Can see: Product usage events and the account identifiers attached to them. No request content and no attachments. ## Questions asked in review - [How do I report a security issue or concern?](https://trust.harmony.io/faq#q1): Email privacy@harmony.io. Please include enough detail for us to reproduce the issue. We acknowledge reports and keep you updated through triage and remediation. The same contact is published for researchers at https://trust.harmony.io/.well-known/security.txt. - [How do I get your SOC 2 report?](https://trust.harmony.io/faq#q2): Ask us at privacy@harmony.io, or use the request form on this page. Reports go out by email once a mutual NDA is in place - we do not host them as downloads, so that we know who holds a copy and can tell you if something changes. - [How is customer data protected?](https://trust.harmony.io/faq#q3): We implement multiple layers of security including encryption at rest and in transit, access controls, and regular security audits. - [Where is customer data stored?](https://trust.harmony.io/faq#q4): Customer data is stored in secure, compliant data centers with our primary cloud provider Amazon Web Services in the USA. - [Does Harmony use customer data to train AI models?](https://trust.harmony.io/faq#q5): No. Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service and is never used for training, fine-tuning, or improving any AI or machine learning models. - [Does Harmony sell customer data to third parties?](https://trust.harmony.io/faq#q6): No. Harmony does not sell customer data to any third parties. We share data only with the subprocessors published in our Trust Center, strictly to deliver our services. - [How can I request deletion of my data?](https://trust.harmony.io/faq#q7): You can submit a data deletion request at any time by emailing privacy@harmony.io. We will process your request in accordance with applicable law and our data retention policy. - [Is Harmony GDPR compliant?](https://trust.harmony.io/faq#q8): Yes. Harmony is fully compliant with the General Data Protection Regulation (GDPR). We act as a data processor for our customers' data. We offer a Data Processing Agreement (DPA) that you can request by contacting privacy@harmony.io. - [Does Harmony support single sign-on (SSO)?](https://trust.harmony.io/faq#q9): Yes. Harmony supports SAML-based single sign-on with providers including Okta, Microsoft Entra ID, and other SAML 2.0-compatible identity providers. - [Does Harmony support SCIM provisioning?](https://trust.harmony.io/faq#q10): Yes. Harmony supports SCIM (System for Cross-domain Identity Management) to automate user provisioning and deprovisioning directly from your identity provider. This allows you to automatically sync user accounts and group memberships without manual administration. - [Does Harmony support role-based access control (RBAC)?](https://trust.harmony.io/faq#q11): Yes. Harmony provides role-based access control so administrators can assign roles to users and control access to features and data based on those roles. This helps organizations enforce least-privilege access and meet compliance requirements. - [Does Harmony provide audit logs?](https://trust.harmony.io/faq#q12): Yes. Harmony maintains comprehensive audit logs of all user and administrative actions within the platform. Audit logs capture who did what and when, enabling security reviews, incident investigations, and compliance reporting. - [Can an AI agent take an action in my systems without approval?](https://trust.harmony.io/faq#q13): Only if you configure it that way. Sensitive actions wait for an explicit approver by default, every integration has a scope ceiling set by an admin, and each run produces a step-by-step audit log of what the agent did and why. - [Which third parties can see our data?](https://trust.harmony.io/faq#q14): Three, all of them in the United States: AWS for infrastructure and model hosting, Descope for authentication, and PostHog for product analytics. The subprocessor page on this site says what each of them can see, and our DPA lists them contractually. - [Do you support on-premises or single-tenant deployment?](https://trust.harmony.io/faq#q15): Harmony is a multi-tenant SaaS platform hosted on AWS in the United States, with safeguards that stop data from one workspace being used or displayed in another. If your requirements go beyond that, talk to us at privacy@harmony.io rather than assuming the answer either way. ## Full text - [Everything on this site as one document](https://trust.harmony.io/llms-full.txt): Risk profile, every control with its verification and framework references, documents, subprocessors and the full FAQ, as plain text.