Snapshot 22277
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust and security Secure by design Harmony gives AI agents real work to do inside your IT estate, so the architecture starts from the assumption that the AI must never reach your IT core directly. Four layers stand between a request and a change, and every one of them is set by you. Visit the Trust Center Frameworks and certifications Harmony is built and audited against the frameworks enterprise IT and procurement teams ask about. Current attestations, reports and certificates, including our SOC reports under NDA, are published in the Trust Center, which is the single source of truth for our status under each one. See current reports and certificates SOC 1 Controls relevant to customers’ financial reporting, examined by an independent auditor. SOC 2 Security, availability and confidentiality controls, examined by an independent auditor. ISO 27001 An information security management system covering how we run, review and improve security. Cyber Essentials The UK government-backed scheme covering the technical controls that stop the most common cyber attacks. PCI DSS The Payment Card Industry Data Security Standard for handling payment card data. GDPR EU data protection law. We act as processor for customer data, and offer a DPA on request. HIPAA US safeguards for protected health information. A BAA is available on request. CSA STAR The Cloud Security Alliance’s Security, Trust, Assurance and Risk assessment for cloud providers. Data Privacy Framework The EU-U.S. Data Privacy Framework, covering transatlantic transfers of personal data. CCPA California privacy law, including the access and deletion rights of California residents. NIST SP 800-53 The NIST catalog of security and privacy controls for information systems. EU AI Act The EU regulation for AI systems, covering transparency, risk management and human oversight. NIST AI RMF The NIST AI Risk Management Framework for governing, mapping, measuring and managing AI risk. Four layers of security between AI and your IT A request arrives "Reset my MFA", "give me access to Figma", "my laptop will not boot" Guardrails Policy decides what may be said Every response is filtered by policy before it reaches the person who asked. Topics, tone and the data an agent may reveal are all set by an admin, not by the model. Human-in-the-loop A named approver decides Sensitive actions wait for explicit approval. The agent gathers the context and proposes the change; a named approver decides, and the decision is recorded. Deterministic flows The change runs as reviewed code The automation agent runs as code, not improvisation. A flow does the same thing on run one thousand as it did on run one, and you can read it before you ship it. Scoped access Least privilege, per integration Connections are least-privilege, with a scope ceiling per integration. An agent never gets direct access to your IT core. It calls the tools you granted it, and nothing else. Privilege boundary Only then, your IT core Identity, devices, apps and records, through the tools an admin connected Governed by SAML and SCIM based access RBAC managed by your IdP Approvals on every action Step-by-step audit log per run What the AI does with your data The questions we get asked most in security review, answered plainly. LLM hosted on our cloud The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them. No training on customer data Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model. Never sold, never brokered Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our Trust Center, strictly to deliver the service. One workspace cannot see another Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace. Only the context you granted An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant. Storage, retention and deletion Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at [email protected]. Documents and reporting Everything a security review needs, plus where to send a report if you find something. Trust CenterCurrent certifications, the full control list and our subprocessors. Reports are available under NDA. Status pageLive and historical availability for the Harmony platform. Privacy PolicyWhat personal data we process, why, and the rights you have over it. Terms of UseThe agreement that governs your use of Harmony. Cookies NoticeThe cookies this site sets and how to control them. DPA, BAA and security questionnairesRequest a Data Processing Agreement, a Business Associate Agreement or a completed questionnaire at [email protected]. Found a vulnerability? Report it to [email protected]. We acknowledge every report, keep you updated through triage and remediation, and will not pursue researchers who report in good faith. Security FAQ Email [email protected]. Please include enough detail for us to reproduce the issue. We acknowledge reports and keep you updated through triage and remediation.