Harmony
SECURITY

Your conversations,
private by default.

Harmony is built so sensitive conversations stay yours. Your data is never used to train AI, it is encrypted end to end, and you decide where it lives and how long it is kept.

GDPRCompliantSOC 2 Type ICompliantISO 27001In progress

GDPR compliant and SOC 2 Type I certified today. ISO 27001 is in progress, and our infrastructure runs on SOC 2 and ISO 27001 certified providers.

THE ESSENTIALS

What matters most to your team

The questions security and privacy teams ask first, answered plainly.

Never used to train AI

Your conversations are never used to train Harmony's models or anyone else's. Our AI providers are contractually barred from training on your data.

Nothing kept after processing

We run a zero-retention policy with our AI providers. Data sent for processing is not stored beyond the moment it is used.

No voiceprints, ever

We tell speakers apart within a single conversation. We never build a voice signature that could identify someone later.

Encrypted end to end

Everything is encrypted with AES-256 at rest and TLS 1.3 in transit, with keys managed in Google Cloud KMS.

Your data stays yours

Export or delete your recordings and transcripts any time, and set your own retention or auto-delete rules.

You choose the region

Your data is processed in the EU, US, or Brazil. Need EU-only? We set that up at onboarding.

HOW YOUR DATA IS HANDLED

What we store, and what we never touch

Harmony keeps only what you need to get value from a conversation, and nothing you would not expect.

What Harmony stores
  • Transcripts and the notes you create
  • AI summaries and outputs you generate
  • Basic metadata, like who attended and when

Encrypted, tenant-isolated, and deletable any time.

What Harmony never does
  • Keep raw meeting audio after it is processed
  • Create voiceprints or biometric identifiers
  • Hand your data to AI providers to train on

By design, not by policy alone.

ACCESS & IDENTITY

Control over who gets in

Single sign-on

Sign in with Google SSO (OAuth / OpenID Connect), with Microsoft Entra on the way.

Multi-factor authentication

Turn on MFA and require it across your whole organization from the admin console.

Roles and permissions

Give each person only the access they need with role-based permissions.

Tenant isolation

Every customer's data is kept separate, so your workspace is never mixed with anyone else's.

Audit logging

Security events are centrally logged and tamper-protected, kept 90 days live and a year in archive.

Admin controls

Enforce consent notices, retention, and access rules for the whole organization in one place.

BEHIND THE SCENES

How we run things day to day

Backups and recovery

Critical data is backed up daily, encrypted, stored in a separate region, and restore-tested every quarter.

Always-on monitoring

We centralize logs in an access-controlled system and alert on anything unusual, around the clock.

Secure development

Every code change is peer-reviewed and automatically scanned for vulnerabilities and secrets before it ships.

Vulnerability management

We scan continuously and patch on a clear schedule, with critical issues fixed within seven days.

People and training

Everyone is background-checked, trained on security in week one, and tested with quarterly phishing drills.

Incident response

A defined plan and on-call team contain issues fast, with customer and regulator notices inside legal deadlines.

OUR COMMITMENTS

Promises we put in writing

99%
monthly uptime

A monthly uptime commitment backed by service credits.

72 hours
breach notice

We notify authorities within 72 hours under GDPR, overseen by our DPO.

30 days
to export, then deleted

After you leave, export your data for 30 days, then we delete it.

0
breaches to date

No security breaches since day one.

PRIVACY & GOVERNANCE

A named owner for your data

Privacy is not an afterthought. We have a Data Protection Officer, a documented rights process, and clear points of contact.

Data Protection Officer

Appointed under GDPR Articles 37 to 39. Reach the team at [email protected].

Your privacy rights

Access, correction, and deletion requests are handled within statutory timelines, typically 30 days.

Recording and consent

In-product notices help participants know when capture starts, so you stay on the right side of consent laws.

SUBPROCESSORS

The companies we trust to help

A short list of vetted providers that process data on our behalf, each held to strict security standards.

AWS

Cloud hosting and infrastructure

SOC 2ISO 27001HIPAAGDPR
Google Cloud

Cloud hosting, storage, and key management

SOC 2ISO 27001HIPAAGDPR
GitHub

Source code hosting and version control

SOC 2ISO 27001
HubSpot

CRM and marketing operations

SOC 2ISO 27001GDPR
Linear

Issue tracking and product management

SOC 2GDPR
Notion

Internal documentation

SOC 2ISO 27001GDPR
Slack

Internal team communication

SOC 2ISO 27001GDPR
Stripe

Payments and billing

SOC 2PCI DSS

The current, authoritative list and processing locations are maintained at security.heyharmony.com.

QUESTIONS

Security questions, answered

If something is missing, our team is one email away.

Do you use my data to train AI?+
No. Your conversations are never used to train Harmony's models or any third party's, and our AI providers are contractually prohibited from doing so. We also apply a zero-retention policy, so data is not stored beyond the moment it is processed.
Do you store my meeting audio?+
No. Audio is transcribed and then discarded. We keep only the transcript, your notes, and the AI outputs you generate, all of which you can delete at any time.
Where is my data stored?+
In the EU, US, or Brazil, depending on your region. If you need an EU-only deployment, we can arrange it during onboarding.
How is my data encrypted?+
With AES-256 while stored and TLS 1.3 while moving over the network. Encryption keys are managed in Google Cloud KMS.
Can I export or delete my data?+
Yes, any time. You can export or delete recordings and transcripts yourself, and set custom retention or auto-delete rules. After you leave, you have 30 days to export before we delete your data.
Do you support SSO and MFA?+
Yes. Google SSO (OAuth / OpenID Connect) and multi-factor authentication are available today, and admins can require MFA across the organization. Microsoft Entra support is on the way.
Are you SOC 2 certified?+
Yes. We are GDPR compliant and SOC 2 Type I certified today, and ISO 27001 is actively in progress. Our infrastructure also runs on SOC 2 and ISO 27001 certified providers like AWS and Google Cloud.
Who do I talk to about security?+
Email [email protected]. Our Data Protection Officer and security team can walk your team through our evidence, policies, and any questionnaire you need.

Security questions?
Talk to the team that built it.

We will walk your security and privacy team through how Harmony handles data, and share our evidence and policies.