Security & data protection

Built so that the people who own the data stay in control of it.

Harmona reads your data with the rights of the person asking, keeps it in your own workspace, and waits for a person before anything leaves. Here is how that works in practice, and the answers data-protection teams ask for first.

Your workspace, your data

Sources are processed into your own workspace's store. Delete a connection and everything built on it goes with it. No model is trained on your data.

Permissions travel with the data

Every read happens with the rights of the person asking. Personal accounts are usable only by their owner, or by whoever they explicitly share with.

A person before anything leaves

Outbound actions wait for an approval card. Unattended tasks keep to the permissions granted at creation and report what they declined.

Safety on by default

Private data redaction plus content and advice restrictions are switched on for every new agent. Turning one off is a deliberate act.

Where your data lives

Processed into your workspace. Deleted with one click.

Connect a database, a drive or a documentation site and Harmona processes it into your own workspace's store: vectors for search, file states for freshness. Answers cite the source they came from. Delete the connection and the sources, vectors and files built on it are removed with it. The model providers we use and their terms are listed for you on request.

Who can see what

One owner per asset. Explicit rights for everyone else.

Agents, workflows, connections, integrations, skills and training sets each have exactly one owner. Everyone else gets view, use or manage rights only when the owner shares. Org admins see that an asset exists, nothing more, until someone shares it with them. Chat rooms are never shared, and a colleague's Gmail or Drive stays theirs.

Safety switches

Private data is masked before a model sees it.

Every new agent starts with private data redaction (e-mail addresses, phone numbers, card numbers, national IDs, API keys), advice restriction for medical, legal and financial topics, and content restriction across ten violation classes. Each switch is per agent, on at creation, and turning one off is a deliberate act.

Deployment

Cloud, private cloud, or your own servers.

EU region

Cloud

Self-serve plans run on Harmona Cloud in the EU region. Credentials are never entered in chat; integrations are health-checked every six hours.

Enterprise

Private cloud

A dedicated environment for your organisation with SSO, an SLA and a data-processing agreement.

Enterprise

On-premises

Harmona inside your own network, with your own model keys if you prefer. SAP connections and sales-assisted onboarding.

GDPR and KVKK

Data-processing agreements for both, in English or Turkish.

ISO 27001 and ISO 42001

Programmes in progress. Current status and documentation on request.

SSO and SLA

On every Enterprise plan.

Sub-processors

The model providers and infrastructure we use, listed on request.

For data-protection teams

The questions we are asked first.

Short answers here; contracts and technical documentation on request.

  • On cloud plans it is processed in the EU region. Enterprise plans can run in a private cloud or on your own servers. The model providers involved and the data flow are written into the agreement.

Tomorrow is a long time in AI. Start today.

Every week without a Worker is a week of work you did by hand. Create a workspace today and have your first one running before your next meeting.

14-day free trial · No credit card · 2,000 credits included