Security & privacy
Security overview
How Harmona protects company data: permissions that follow the person asking, approvals, safety switches on by default, and where it runs.
Документация доступна на английском и турецком, как и интерфейс Harmona. Эта страница показана на английском.
Harmona is built so that the people who own the data stay in control of it. This page covers the controls you see in the product. Contracts and technical documentation are available on request; see Security.
Access follows the person asking
- Harmona reads your data with the rights of the person asking.
- Every agent, workflow, connection, integration, training set and skill has exactly one owner. Others get view, use or manage rights only when the owner shares it.
- Admins see that something exists, but can't use or change it without a share.
- Chats are private to the person who started them; admins don't see them. A Worker is open only to its members.
- A personal account, such as someone's Gmail or Google Drive, is usable only by its owner, or by whoever they share it with.
The details are in Sharing and access.
A person approves what goes out
Each conversation has an approval mode, which you pick in the chat. See Approvals.
| Mode | What happens |
|---|---|
| Ask every time | Every action that changes something asks you first. |
| External only | Changes inside Harmona run on their own. Anything that leaves Harmona (mail, calendar, tickets, running a workflow), sharing and deletions still ask. |
| Auto | Nothing asks. Every action still leaves a receipt in the chat. |
Tasks a Worker runs on a schedule keep to the permissions approved when the task was created. Anything outside them is declined and reported. See Tasks and delegation.
Safety switches on every agent
Every agent has three switches under Security Controls, in its configuration. All three are on when an agent is created. Turning one off is a deliberate change in the agent's settings.
| Switch | What it does |
|---|---|
| PII Protection | Masks private data before a model sees it, both in what people type and in what tools return. |
| Advice Restriction | The agent declines medical, legal and financial advice and points people to a qualified professional. |
| Content Restriction | The agent refuses harmful content, security and privacy violations, and questions about how it is built, such as its model or instructions. |
What PII Protection detects
| Data | What happens | Where |
|---|---|---|
| Email addresses | Redacted | In what people type. Not in tool results, so mail and calendar tools keep working. |
| Card numbers | Masked; the last four digits stay | Input and tool results |
| Phone numbers in Turkish formats | Masked | Input and tool results |
| Turkish national ID numbers (TCKN) | Redacted | Input and tool results |
| IP addresses | Redacted | Input and tool results |
| MAC addresses | Redacted | Input and tool results |
| OpenAI-style API keys | Blocked: the request stops | Input and tool results |
Внимание
Your data
- Connected sources are processed into your own workspace, and answers cite the source they came from.
- Harmona trains no models on your data.
- Harmona uses models from OpenAI, Anthropic and Google through their APIs. A provider receives only the part of your content needed for a response, and under their business API terms they don't train on it.
Where data is stored and what you can delete is described in Data handling and deletion.
Where Harmona runs
| Option | Details |
|---|---|
| Cloud | Runs on Amazon Web Services in Ireland (European Union). Requests to model providers may be processed outside the EU and Türkiye. |
| Private cloud | Enterprise: a dedicated environment for your organization. |
| On-premises | Enterprise: Harmona inside your own network, with your own model keys if you prefer. |
On Enterprise plans, the model providers and regions used are set out in your agreement.
Compliance
- Data-processing agreements for GDPR and KVKK, in English or Turkish.
- ISO 27001 and ISO 42001: programmes are in progress. Ask us for the current status and documentation.
- SSO and an SLA on Enterprise plans.
- The model providers and infrastructure we use are listed on request.
For how personal data is handled, read the Privacy Policy.
Обновлено 2026-09-24
