Snapshot 22279
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Frameworks and certifications The security, privacy and compliance frameworks Harmony is built and audited against. Reports and certificates are listed under Documents, with how to get each one. SOC 2 Type II AICPA Trust Services Criteria for security, availability and confidentiality, examined over a period rather than at a point in time. SOC 1 Type II Controls relevant to a customer’s financial reporting, for the auditors who need assurance over a system we are part of. ISO/IEC 27001 The international standard for an information security management system: how security is governed, not only which controls exist. Cyber Essentials The UK government-backed baseline: firewalls, secure configuration, user access control, malware protection and security update management. NIST SP 800-53 The US federal catalogue of security and privacy controls, used here as the reference our control set is mapped against. NIST AI RMF The AI Risk Management Framework: govern, map, measure and manage the risks specific to an AI system. EU AI Act The European regulation on AI, which classifies systems by risk and sets obligations for transparency and human oversight. GDPR European data protection law. We act as a processor for customer data; a DPA is available under NDA. CCPA California’s privacy statute, covering the rights a resident has over personal information a business holds. HIPAA The US rules for protected health information, and the obligations they place on a vendor that handles it on a covered entity’s behalf. EU-US Data Privacy Framework The transfer mechanism for personal data moving from the EU, the UK and Switzerland to the United States. PCI DSS The payment card industry’s data security standard. Harmony does not store cardholder data; payments are handled by our payment processor. CSA STAR The Cloud Security Alliance’s registry and its Consensus Assessments questionnaire, the standard form of the cloud security review. The security controls behind them Each control says what we do and, where the control itself makes it explicit, how it is checked. Each one also carries the framework requirements it speaks to, so you can line it up against your own checklist. Information Security ManagementWho owns security at Harmony, the policies they maintain, and what every employee is held to.8 controls Network and Infrastructure SecurityHow the platform is run on AWS: availability, logging, recovery, and who can reach production.7 controls Data Privacy and ProtectionEncryption, retention and deletion for the data you put into Harmony.4 controls Product SecurityWhat the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing.12 controls AI and Agent ControlsWhat the agents can and cannot do, who approves the sensitive actions, and what record each run leaves.4 controls Incident Detection and ResponseWhat happens when something goes wrong, and how quickly someone is looking at it.4 controls Corporate and Physical SecurityHow the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled.3 controls Documents for a security review We do not host our reports as downloads. Audit reports, questionnaires and certificates are sent by email to a named person, so that we know who holds them and can tell you if something changes. Ask and we will send them. Under NDA SOC 2 report SOC 1 report Penetration test summary ISO 27001 certificate and Statement of Applicability Cyber Essentials certificate Data Processing Agreement (DPA) GDPR assessment AI governance self-assessment Request one of these Published Control list Subprocessor list Privacy Policy Terms of Use Cookies Notice Vulnerability disclosure contact What each document covers What the AI does with your data The questions every security review asks about the AI, answered plainly. LLM hosted on our cloud The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them. No training on customer data Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model. Never sold, never brokered Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our subprocessor list, strictly to deliver the service. One workspace cannot see another Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace. Only the context you granted An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant. Storage, retention and deletion Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at [email protected]. How agent access is bounded, in detail Subprocessors 3 subprocessors, all of them in the United States. The subprocessor page says what each one can see. Amazon Web Services, Inc. Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account. Descope, Inc. Authentication provider. Handles sign-in, session issuance and SSO federation. PostHog, Inc. Product analytics. How the product is used, so we can see what is and is not working. Data categories, regions and transfer mechanisms Something this page does not answer? Ask us. Questionnaires, a DPA, our SOC reports, or a question a reviewer raised that is not covered here - it all goes to the same place, and a person answers it. Request [email protected] the FAQ