Security overviewМеню документации

Security & privacy

Security overview

How Harmona protects company data: permissions that follow the person asking, approvals, safety switches on by default, and where it runs.

Документация доступна на английском и турецком, как и интерфейс Harmona. Эта страница показана на английском.

Harmona is built so that the people who own the data stay in control of it. This page covers the controls you see in the product. Contracts and technical documentation are available on request; see Security.

Access follows the person asking

  • Harmona reads your data with the rights of the person asking.
  • Every agent, workflow, connection, integration, training set and skill has exactly one owner. Others get view, use or manage rights only when the owner shares it.
  • Admins see that something exists, but can't use or change it without a share.
  • Chats are private to the person who started them; admins don't see them. A Worker is open only to its members.
  • A personal account, such as someone's Gmail or Google Drive, is usable only by its owner, or by whoever they share it with.

The details are in Sharing and access.

A person approves what goes out

Each conversation has an approval mode, which you pick in the chat. See Approvals.

ModeWhat happens
Ask every timeEvery action that changes something asks you first.
External onlyChanges inside Harmona run on their own. Anything that leaves Harmona (mail, calendar, tickets, running a workflow), sharing and deletions still ask.
AutoNothing asks. Every action still leaves a receipt in the chat.

Tasks a Worker runs on a schedule keep to the permissions approved when the task was created. Anything outside them is declined and reported. See Tasks and delegation.

Safety switches on every agent

Every agent has three switches under Security Controls, in its configuration. All three are on when an agent is created. Turning one off is a deliberate change in the agent's settings.

SwitchWhat it does
PII ProtectionMasks private data before a model sees it, both in what people type and in what tools return.
Advice RestrictionThe agent declines medical, legal and financial advice and points people to a qualified professional.
Content RestrictionThe agent refuses harmful content, security and privacy violations, and questions about how it is built, such as its model or instructions.

What PII Protection detects

DataWhat happensWhere
Email addressesRedactedIn what people type. Not in tool results, so mail and calendar tools keep working.
Card numbersMasked; the last four digits stayInput and tool results
Phone numbers in Turkish formatsMaskedInput and tool results
Turkish national ID numbers (TCKN)RedactedInput and tool results
IP addressesRedactedInput and tool results
MAC addressesRedactedInput and tool results
OpenAI-style API keysBlocked: the request stopsInput and tool results

Внимание

The switches reduce risk; they don't make an agent compliant with a regulation such as HIPAA on their own. Web addresses are not redacted. For regulated work, have a compliance expert review the setup.

Your data

  • Connected sources are processed into your own workspace, and answers cite the source they came from.
  • Harmona trains no models on your data.
  • Harmona uses models from OpenAI, Anthropic and Google through their APIs. A provider receives only the part of your content needed for a response, and under their business API terms they don't train on it.

Where data is stored and what you can delete is described in Data handling and deletion.

Where Harmona runs

OptionDetails
CloudRuns on Amazon Web Services in Ireland (European Union). Requests to model providers may be processed outside the EU and Türkiye.
Private cloudEnterprise: a dedicated environment for your organization.
On-premisesEnterprise: Harmona inside your own network, with your own model keys if you prefer.

On Enterprise plans, the model providers and regions used are set out in your agreement.

Compliance

  • Data-processing agreements for GDPR and KVKK, in English or Turkish.
  • ISO 27001 and ISO 42001: programmes are in progress. Ask us for the current status and documentation.
  • SSO and an SLA on Enterprise plans.
  • The model providers and infrastructure we use are listed on request.

For how personal data is handled, read the Privacy Policy.

Обновлено 2026-09-24