Third Party Index

Snapshot 22274

Document
Data processing addendum
URL
https://trust.harmony.io/documents
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
151500 bytes
SHA-256 (raw)
80488afcaf86d0937b12a368869527c679c65b36d9d33ee90791175051e71ac3
SHA-256 (normalized text)
712cc1bbe2f326d7de682842b01177195e6b57546258d9b69308936aa0ba77a5

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Under NDA
Sent by email once a mutual NDA is in place.
SOC 2 report
An independent auditor’s examination of our security, availability and confidentiality controls, including the auditor’s opinion and the tests performed. The authoritative mapping of our controls to the Trust Services Criteria.
Request this document
SOC 1 report
An independent auditor’s examination of the controls relevant to your financial reporting, for teams whose auditors ask for one.
Request this document
Penetration test summary
The summary letter from our most recent third-party penetration test of the Harmony application and infrastructure, including scope and the status of findings.
Request this document
ISO 27001 certificate and Statement of Applicability
Our certificate, and the statement of which Annex A controls are in scope. Read alongside the control list on this page, which is the plain-language version.
Request this document
Cyber Essentials certificate
Our certificate under the UK government’s Cyber Essentials scheme, assessed against the whole organisation rather than a carved-out scope. The scheme is reassessed every year, and the certificate carries a number you can verify with the certification body.
Issued by
IQ in IT, an IASME-accredited certification body
Period covered
21 September 2026 to 21 September 2027
Request this document
Data Processing Agreement (DPA)
The processor terms for customer personal data, including the Standard Contractual Clauses for transfers out of the EEA and the UK, and the subprocessor list.
Request this document
GDPR assessment
Our assessment of Harmony against the GDPR obligations that apply to a processor: the roles each party holds, records of processing, the transfer mechanism for data leaving the EEA and the UK, how data subject requests reach us and are answered, retention and deletion, and the technical and organisational measures behind Article 32.
Request this document
AI governance self-assessment
How our AI governance measures up against the NIST AI Risk Management Framework and the EU AI Act: where models run, what they are allowed to do, the human approval points, what is logged, and how we evaluate changes. Completed by us rather than by an auditor, which is what "self-assessment" means here.
Request this document
Published
Published, and linked from this page.
Control list
Every control on this page, with the framework requirements each one speaks to. Printable in one page if you need it in a review pack.
Read it
Subprocessor list
Every third party that processes customer data, what they do, and what they see.
Read it
Privacy Policy
What personal data we process, why, and the rights you have over it.
Read it
Terms of Use
The agreement that governs your use of Harmony.
Read it
Cookies Notice
The cookies harmony.io sets, and how to control them.
Read it
Vulnerability disclosure contact
Our RFC 9116 security.txt, so a researcher who finds something has one obvious place to look for where to send it.
Read it