1.Our approach
Security is foundational to HarmoniHRM. We hold sensitive workforce data on behalf of organisations around the world, and we design the product, our infrastructure and our processes to protect that data by default. This page summarises the controls we operate and how to report a concern. We continue to invest in our security programme as we grow, including towards recognised independent certifications.
2.Encryption in transit and at rest
All traffic between your browser and HarmoniHRM is encrypted using current TLS. Data is encrypted at rest in our managed infrastructure using strong, industry-standard algorithms. Encryption keys are managed by our infrastructure providers with strict access controls, and secrets are never stored in source code.
3.Access controls
Access to production systems and customer data is restricted to a small number of authorised staff who need it to operate and support the service, on a least-privilege basis. Internal access uses strong authentication and is logged. Within the product, customers control who can see and do what through roles and permissions, including our composable access model.
4.Tenant isolation
HarmoniHRM is multi-tenant by design. Each customer’s data is logically isolated and scoped to their organisation, and access is enforced at the data layer through tenant-scoped row-level security so that one organisation can never read or write another organisation’s data. Application requests are authenticated and authorised against the signed-in user’s tenant and role.
5.Audit logging
Significant actions in the platform are recorded with the actor, the action and a timestamp, supporting accountability, investigations and customer audits. Administrators can review relevant activity, and we retain operational and security logs for the periods needed to detect and investigate issues.
6.Infrastructure and availability
HarmoniHRM runs on reputable cloud infrastructure providers with strong physical and network security. We use managed, regularly patched services, automated backups, and monitoring to support availability and recovery. Our use of these providers is governed by our Sub-processors list and contractual data protection commitments.
7.Secure development
Security is built into how we develop. We use code review, dependency management, automated checks and staged deployments to reduce the chance of defects reaching production. Access to deploy is limited and logged, and we apply patches to underlying platforms promptly.
8.Incident response
We maintain an incident response process to detect, contain, investigate and remediate security events. If a personal data breach affects customer data, we will notify affected customers without undue delay and provide the information needed for them to meet their own obligations, in line with applicable law and our Data Processing Addendum.
9.Data protection and privacy
Our security controls support the privacy commitments described in our Privacy Notice. We collect only the data needed to run the service, restrict how it is used, and never sell it or use stored workforce content to train general-purpose models.
10.Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please report it to hello@harmonihrm.com with enough detail to reproduce the issue. We ask that you:
- Give us a reasonable time to investigate and fix the issue before public disclosure.
- Avoid accessing, modifying or deleting data that is not your own, and avoid degrading the service.
- Do not run automated scanning that could affect availability for others.
We will acknowledge valid reports, keep you updated, and will not pursue good-faith research that follows these guidelines.
11.Contact us
For security questions, due-diligence requests or to report a concern, contact hello@harmonihrm.com.