Security & data protection
Built so that the people who own the data stay in control of it.
Harmona reads your data with the rights of the person asking, keeps it in your own workspace, and waits for a person before anything leaves. Here is how that works in practice, and the answers data-protection teams ask for first.
Your workspace, your data
Sources are processed into your own workspace's store. Delete a connection and everything built on it goes with it. No model is trained on your data.
Permissions travel with the data
Every read happens with the rights of the person asking. Personal accounts are usable only by their owner, or by whoever they explicitly share with.
A person before anything leaves
Outbound actions wait for an approval card. Unattended tasks keep to the permissions granted at creation and report what they declined.
Safety on by default
Private data redaction plus content and advice restrictions are switched on for every new agent. Turning one off is a deliberate act.
Where your data lives
Processed into your workspace. Deleted with one click.
Connect a database, a drive or a documentation site and Harmona processes it into your own workspace's store: vectors for search, file states for freshness. Answers cite the source they came from. Delete the connection and the sources, vectors and files built on it are removed with it. The model providers we use and their terms are listed for you on request.
Your workspace store
- Vectors3,860
- File states118
No model is trained on it.
Finance Analyst
Q3 revenue is $468K, 4.2% under plan.sales_db · revenue_by_regionWho can see what
One owner per asset. Explicit rights for everyone else.
Agents, workflows, connections, integrations, skills and training sets each have exactly one owner. Everyone else gets view, use or manage rights only when the owner shares. Org admins see that an asset exists, nothing more, until someone shares it with them. Chat rooms are never shared, and a colleague's Gmail or Drive stays theirs.
- YYouOwner
- SSarah KimNo access
- AAlex MorganView
- OOrg adminInventory only
Safety switches
Private data is masked before a model sees it.
Every new agent starts with private data redaction (e-mail addresses, phone numbers, card numbers, national IDs, API keys), advice restriction for medical, legal and financial topics, and content restriction across ten violation classes. Each switch is per agent, on at creation, and turning one off is a deliberate act.
Every switch is on for a new agent. Here is what each one does.
Deployment
Cloud, private cloud, or your own servers.
Cloud
Self-serve plans run on Harmona Cloud in the EU region. Credentials are never entered in chat; integrations are health-checked every six hours.
Private cloud
A dedicated environment for your organisation with SSO, an SLA and a data-processing agreement.
On-premises
Harmona inside your own network, with your own model keys if you prefer. SAP connections and sales-assisted onboarding.
GDPR and KVKK
Data-processing agreements for both, in English or Turkish.
ISO 27001 and ISO 42001
Programmes in progress. Current status and documentation on request.
SSO and SLA
On every Enterprise plan.
Sub-processors
The model providers and infrastructure we use, listed on request.
For data-protection teams
The questions we are asked first.
Short answers here; contracts and technical documentation on request.
On cloud plans it is processed in the EU region. Enterprise plans can run in a private cloud or on your own servers. The model providers involved and the data flow are written into the agreement.
Tomorrow is a long time in AI. Start today.
Every week without a Worker is a week of work you did by hand. Create a workspace today and have your first one running before your next meeting.
14-day free trial · No credit card · 2,000 credits included
