Third Party Index

Snapshot 22277

Document
Security page
URL
https://harmony.io/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
674503 bytes
SHA-256 (raw)
9138e8050ce391a6ccc489d5de1ed29ae959be2c5db9c64f8197fcac91743673
SHA-256 (normalized text)
da05b67b1d4d84e9863a3e0bf0b8d61401a2f404b605fe315c6e4c9c45d9f8d3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust and security
Secure by design
Harmony gives AI agents real work to do inside your IT estate, so the architecture starts from the assumption that the AI must never reach your IT core directly. Four layers stand between a request and a change, and every one of them is set by you.
Visit the Trust Center
Frameworks and certifications
Harmony is built and audited against the frameworks enterprise IT and procurement teams ask about. Current attestations, reports and certificates, including our SOC reports under NDA, are published in the Trust Center, which is the single source of truth for our status under each one.
See current reports and certificates
SOC 1
Controls relevant to customers’ financial reporting, examined by an independent auditor.
SOC 2
Security, availability and confidentiality controls, examined by an independent auditor.
ISO 27001
An information security management system covering how we run, review and improve security.
Cyber Essentials
The UK government-backed scheme covering the technical controls that stop the most common cyber attacks.
PCI DSS
The Payment Card Industry Data Security Standard for handling payment card data.
GDPR
EU data protection law. We act as processor for customer data, and offer a DPA on request.
HIPAA
US safeguards for protected health information. A BAA is available on request.
CSA STAR
The Cloud Security Alliance’s Security, Trust, Assurance and Risk assessment for cloud providers.
Data Privacy Framework
The EU-U.S. Data Privacy Framework, covering transatlantic transfers of personal data.
CCPA
California privacy law, including the access and deletion rights of California residents.
NIST SP 800-53
The NIST catalog of security and privacy controls for information systems.
EU AI Act
The EU regulation for AI systems, covering transparency, risk management and human oversight.
NIST AI RMF
The NIST AI Risk Management Framework for governing, mapping, measuring and managing AI risk.
Four layers of security between AI and your IT
A request arrives
"Reset my MFA", "give me access to Figma", "my laptop will not boot"
Guardrails
Policy decides what may be said
Every response is filtered by policy before it reaches the person who asked. Topics, tone and the data an agent may reveal are all set by an admin, not by the model.
Human-in-the-loop
A named approver decides
Sensitive actions wait for explicit approval. The agent gathers the context and proposes the change; a named approver decides, and the decision is recorded.
Deterministic flows
The change runs as reviewed code
The automation agent runs as code, not improvisation. A flow does the same thing on run one thousand as it did on run one, and you can read it before you ship it.
Scoped access
Least privilege, per integration
Connections are least-privilege, with a scope ceiling per integration. An agent never gets direct access to your IT core. It calls the tools you granted it, and nothing else.
Privilege boundary
Only then, your IT core
Identity, devices, apps and records, through the tools an admin connected
Governed by
SAML and SCIM based access
RBAC managed by your IdP
Approvals on every action
Step-by-step audit log per run
What the AI does with your data
The questions we get asked most in security review, answered plainly.
LLM hosted on our cloud
The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them.
No training on customer data
Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model.
Never sold, never brokered
Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our Trust Center, strictly to deliver the service.
One workspace cannot see another
Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace.
Only the context you granted
An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant.
Storage, retention and deletion
Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at [email protected].
Documents and reporting
Everything a security review needs, plus where to send a report if you find something.
Trust CenterCurrent certifications, the full control list and our subprocessors. Reports are available under NDA.
Status pageLive and historical availability for the Harmony platform.
Privacy PolicyWhat personal data we process, why, and the rights you have over it.
Terms of UseThe agreement that governs your use of Harmony.
Cookies NoticeThe cookies this site sets and how to control them.
DPA, BAA and security questionnairesRequest a Data Processing Agreement, a Business Associate Agreement or a completed questionnaire at [email protected].
Found a vulnerability?
Report it to [email protected]. We acknowledge every report, keep you updated through triage and remediation, and will not pursue researchers who report in good faith.
Security FAQ
Email [email protected]. Please include enough detail for us to reproduce the issue. We acknowledge reports and keep you updated through triage and remediation.