Your conversations,
private by default.
Harmony is built so sensitive conversations stay yours. Your data is never used to train AI, it is encrypted end to end, and you decide where it lives and how long it is kept.
GDPR compliant and SOC 2 Type I certified today. ISO 27001 is in progress, and our infrastructure runs on SOC 2 and ISO 27001 certified providers.
What matters most to your team
The questions security and privacy teams ask first, answered plainly.
Never used to train AI
Your conversations are never used to train Harmony's models or anyone else's. Our AI providers are contractually barred from training on your data.
Nothing kept after processing
We run a zero-retention policy with our AI providers. Data sent for processing is not stored beyond the moment it is used.
No voiceprints, ever
We tell speakers apart within a single conversation. We never build a voice signature that could identify someone later.
Encrypted end to end
Everything is encrypted with AES-256 at rest and TLS 1.3 in transit, with keys managed in Google Cloud KMS.
Your data stays yours
Export or delete your recordings and transcripts any time, and set your own retention or auto-delete rules.
You choose the region
Your data is processed in the EU, US, or Brazil. Need EU-only? We set that up at onboarding.
What we store, and what we never touch
Harmony keeps only what you need to get value from a conversation, and nothing you would not expect.
- Transcripts and the notes you create
- AI summaries and outputs you generate
- Basic metadata, like who attended and when
Encrypted, tenant-isolated, and deletable any time.
- Keep raw meeting audio after it is processed
- Create voiceprints or biometric identifiers
- Hand your data to AI providers to train on
By design, not by policy alone.
Control over who gets in
Single sign-on
Sign in with Google SSO (OAuth / OpenID Connect), with Microsoft Entra on the way.
Multi-factor authentication
Turn on MFA and require it across your whole organization from the admin console.
Roles and permissions
Give each person only the access they need with role-based permissions.
Tenant isolation
Every customer's data is kept separate, so your workspace is never mixed with anyone else's.
Audit logging
Security events are centrally logged and tamper-protected, kept 90 days live and a year in archive.
Admin controls
Enforce consent notices, retention, and access rules for the whole organization in one place.
How we run things day to day
Backups and recovery
Critical data is backed up daily, encrypted, stored in a separate region, and restore-tested every quarter.
Always-on monitoring
We centralize logs in an access-controlled system and alert on anything unusual, around the clock.
Secure development
Every code change is peer-reviewed and automatically scanned for vulnerabilities and secrets before it ships.
Vulnerability management
We scan continuously and patch on a clear schedule, with critical issues fixed within seven days.
People and training
Everyone is background-checked, trained on security in week one, and tested with quarterly phishing drills.
Incident response
A defined plan and on-call team contain issues fast, with customer and regulator notices inside legal deadlines.
Promises we put in writing
A monthly uptime commitment backed by service credits.
We notify authorities within 72 hours under GDPR, overseen by our DPO.
After you leave, export your data for 30 days, then we delete it.
No security breaches since day one.
A named owner for your data
Privacy is not an afterthought. We have a Data Protection Officer, a documented rights process, and clear points of contact.
Data Protection Officer
Appointed under GDPR Articles 37 to 39. Reach the team at [email protected].
Your privacy rights
Access, correction, and deletion requests are handled within statutory timelines, typically 30 days.
Recording and consent
In-product notices help participants know when capture starts, so you stay on the right side of consent laws.
The companies we trust to help
A short list of vetted providers that process data on our behalf, each held to strict security standards.
Cloud hosting and infrastructure
Cloud hosting, storage, and key management
Source code hosting and version control
CRM and marketing operations
Issue tracking and product management
Internal documentation
Internal team communication
Payments and billing
The current, authoritative list and processing locations are maintained at security.heyharmony.com.
Security questions, answered
If something is missing, our team is one email away.
Do you use my data to train AI?+−
Do you store my meeting audio?+−
Where is my data stored?+−
How is my data encrypted?+−
Can I export or delete my data?+−
Do you support SSO and MFA?+−
Are you SOC 2 certified?+−
Who do I talk to about security?+−
Security questions?
Talk to the team that built it.
We will walk your security and privacy team through how Harmony handles data, and share our evidence and policies.