Third Party Index

Snapshot 22279

Document
Trust center
URL
https://trust.harmony.io/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
190018 bytes
SHA-256 (raw)
75be83d54c45166d4a1354d7b55db39f41b719f5bc6a61ee4e3b4bbe262e9b56
SHA-256 (normalized text)
5895346869f20415b1f2edf582e7fa7681a16f94848d330db2edb6afecec5140

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Frameworks and certifications
The security, privacy and compliance frameworks Harmony is built and audited against. Reports and certificates are listed under Documents, with how to get each one.
SOC 2 Type II
AICPA Trust Services Criteria for security, availability and confidentiality, examined over a period rather than at a point in time.
SOC 1 Type II
Controls relevant to a customer’s financial reporting, for the auditors who need assurance over a system we are part of.
ISO/IEC 27001
The international standard for an information security management system: how security is governed, not only which controls exist.
Cyber Essentials
The UK government-backed baseline: firewalls, secure configuration, user access control, malware protection and security update management.
NIST SP 800-53
The US federal catalogue of security and privacy controls, used here as the reference our control set is mapped against.
NIST AI RMF
The AI Risk Management Framework: govern, map, measure and manage the risks specific to an AI system.
EU AI Act
The European regulation on AI, which classifies systems by risk and sets obligations for transparency and human oversight.
GDPR
European data protection law. We act as a processor for customer data; a DPA is available under NDA.
CCPA
California’s privacy statute, covering the rights a resident has over personal information a business holds.
HIPAA
The US rules for protected health information, and the obligations they place on a vendor that handles it on a covered entity’s behalf.
EU-US Data Privacy Framework
The transfer mechanism for personal data moving from the EU, the UK and Switzerland to the United States.
PCI DSS
The payment card industry’s data security standard. Harmony does not store cardholder data; payments are handled by our payment processor.
CSA STAR
The Cloud Security Alliance’s registry and its Consensus Assessments questionnaire, the standard form of the cloud security review.
The security controls behind them
Each control says what we do and, where the control itself makes it explicit, how it is checked. Each one also carries the framework requirements it speaks to, so you can line it up against your own checklist.
Information Security ManagementWho owns security at Harmony, the policies they maintain, and what every employee is held to.8 controls
Network and Infrastructure SecurityHow the platform is run on AWS: availability, logging, recovery, and who can reach production.7 controls
Data Privacy and ProtectionEncryption, retention and deletion for the data you put into Harmony.4 controls
Product SecurityWhat the platform itself enforces: tenant isolation, authentication, authorisation, audit and testing.12 controls
AI and Agent ControlsWhat the agents can and cannot do, who approves the sensitive actions, and what record each run leaves.4 controls
Incident Detection and ResponseWhat happens when something goes wrong, and how quickly someone is looking at it.4 controls
Corporate and Physical SecurityHow the laptops Harmony employees work on are secured and managed, and how our offices and facilities are controlled.3 controls
Documents for a security review
We do not host our reports as downloads. Audit reports, questionnaires and certificates are sent by email to a named person, so that we know who holds them and can tell you if something changes. Ask and we will send them.
Under NDA
SOC 2 report
SOC 1 report
Penetration test summary
ISO 27001 certificate and Statement of Applicability
Cyber Essentials certificate
Data Processing Agreement (DPA)
GDPR assessment
AI governance self-assessment
Request one of these
Published
Control list
Subprocessor list
Privacy Policy
Terms of Use
Cookies Notice
Vulnerability disclosure contact
What each document covers
What the AI does with your data
The questions every security review asks about the AI, answered plainly.
LLM hosted on our cloud
The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them.
No training on customer data
Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model.
Never sold, never brokered
Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our subprocessor list, strictly to deliver the service.
One workspace cannot see another
Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace.
Only the context you granted
An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant.
Storage, retention and deletion
Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at [email protected].
How agent access is bounded, in detail
Subprocessors
3 subprocessors, all of them in the United States. The subprocessor page says what each one can see.
Amazon Web Services, Inc.
Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account.
Descope, Inc.
Authentication provider. Handles sign-in, session issuance and SSO federation.
PostHog, Inc.
Product analytics. How the product is used, so we can see what is and is not working.
Data categories, regions and transfer mechanisms
Something this page does not answer?
Ask us. Questionnaires, a DPA, our SOC reports, or a question a reviewer raised that is not covered here - it all goes to the same place, and a person answers it.
Request [email protected] the FAQ