Trust and security
Secure by design
Harmony gives AI agents real work to do inside your IT estate, so the architecture starts from the assumption that the AI must never reach your IT core directly. Four layers stand between a request and a change, and every one of them is set by you.
Frameworks and certifications
Harmony is built and audited against the frameworks enterprise IT and procurement teams ask about. Current attestations, reports and certificates, including our SOC reports under NDA, are published in the Trust Center, which is the single source of truth for our status under each one.
See current reports and certificatesSOC 1
Controls relevant to customers’ financial reporting, examined by an independent auditor.
SOC 2
Security, availability and confidentiality controls, examined by an independent auditor.
ISO 27001
An information security management system covering how we run, review and improve security.
PCI DSS
The Payment Card Industry Data Security Standard for handling payment card data.
GDPR
EU data protection law. We act as processor for customer data, and offer a DPA on request.
HIPAA
US safeguards for protected health information. A BAA is available on request.
CSA STAR
The Cloud Security Alliance’s Security, Trust, Assurance and Risk assessment for cloud providers.
DPF
The EU-U.S. Data Privacy Framework, covering transatlantic transfers of personal data.
CCPA
California privacy law, including the access and deletion rights of California residents.
NIST SP 800-53
The NIST catalog of security and privacy controls for information systems.
Four layers of security between AI and your IT
A request arrives
"Reset my MFA", "give me access to Figma", "my laptop will not boot"
Guardrails
Policy decides what may be said
Every response is filtered by policy before it reaches the person who asked. Topics, tone and the data an agent may reveal are all set by an admin, not by the model.
Human-in-the-loop
A named approver decides
Sensitive actions wait for explicit approval. The agent gathers the context and proposes the change; a named approver decides, and the decision is recorded.
Deterministic flows
The change runs as reviewed code
The automation agent runs as code, not improvisation. A flow does the same thing on run one thousand as it did on run one, and you can read it before you ship it.
Scoped access
Least privilege, per integration
Connections are least-privilege, with a scope ceiling per integration. An agent never gets direct access to your IT core. It calls the tools you granted it, and nothing else.
Privilege boundary
Only then, your IT core
Identity, devices, apps and records, through the tools an admin connected
Governed by
- SAML and SCIM based access
- RBAC managed by your IdP
- Approvals on every action
- Step-by-step audit log per run
What the AI does with your data
The questions we get asked most in security review, answered plainly.
LLM hosted on our cloud
The models Harmony runs on are hosted on AWS inside our own account. Your prompts and context are not handed to a consumer AI product, and no third-party model provider retains them.
No training on customer data
Harmony does not use customer data to train AI models. Your data is used solely to provide you with the Harmony service, and is never used for training, fine-tuning or improving any AI or machine learning model.
Never sold, never brokered
Harmony does not sell customer data to any third party. Data is shared only with the subprocessors published in our Trust Center, strictly to deliver the service.
One workspace cannot see another
Safeguards are in place such that data from one Harmony workspace can never be used or displayed within another workspace.
Only the context you granted
An agent retrieves from the knowledge sources and calls the tools an admin has connected for it. There is no ambient access to systems outside that grant.
Storage, retention and deletion
Customer data is stored in secure, compliant AWS data centers in the USA. Workspace data is deleted within 30 days of a workspace being deleted, and you can request deletion at any time at privacy@harmony.io.
Documents and reporting
Everything a security review needs, plus where to send a report if you find something.
- Trust CenterCurrent certifications, the full control list and our subprocessors. Reports are available under NDA.
- Status pageLive and historical availability for the Harmony platform.
- Privacy PolicyWhat personal data we process, why, and the rights you have over it.
- Terms of UseThe agreement that governs your use of Harmony.
- Cookies NoticeThe cookies this site sets and how to control them.
- DPA, BAA and security questionnairesRequest a Data Processing Agreement, a Business Associate Agreement or a completed questionnaire at privacy@harmony.io.
Found a vulnerability?
Report it to privacy@harmony.io. We acknowledge every report, keep you updated through triage and remediation, and will not pursue researchers who report in good faith.
Security FAQ
Email privacy@harmony.io. Please include enough detail for us to reproduce the issue. We acknowledge reports and keep you updated through triage and remediation.