Hael
Book a meeting

SOC 2 AND SECURITY COMPLIANCE CONSULTING

SOC 2 compliance, implemented and managed end to end.

Hael helps technology companies achieve SOC 2 through readiness assessment, control implementation, evidence preparation, project management and independent CPA audit coordination. We support businesses across the US, UK and Europe.

WHY HAEL

A SOC 2 report, and controls that still operate behind it.

The criteria are public. What separates a clean report from a qualified one is whether the controls actually operate, whether the evidence holds together when an examiner tests it, and whether it still describes what you do six months later. That is what we build, and what we keep current.

Practice

Every engagement is led by a practitioner who has taken organisations through authorisation, supervision and examination. Scope is set correctly at the outset rather than corrected late in the programme.

Method

Scope, price and timetable are agreed before work begins. Progress, outstanding items and required client input are reported weekly.

Record

Systems, controls, evidence and approvals are maintained in a single record. It is included in every engagement and remains with the client afterwards.

WHAT WE DO

The work between the platform and the report.

Compliance platforms show you which controls are missing. Audit firms tell you whether the controls held. Neither one writes the policy, gathers the evidence, runs the project, or sits with your engineers to close the gap. That is the work. We run it from first scope through to the report, and we manage the platform, the timetable and the audit firm's requests along the way.

We work inside Vanta, Drata, Secureframe or whichever platform you already pay for, and on our own record where you have none. Your systems, controls, evidence and approvals live in one place, included in every engagement, and yours to keep afterwards. The tool is not the point. What sits behind the evidence is.

FRAMEWORKS

One partner across every framework.

Delivered by the same team, against one evidence base.

SOC 2
The report enterprise buyers open first. An independent CPA examination against the Trust Services Criteria, and the programme we run most. Read the guide
ISO 27001
The international security standard, usually run alongside SOC 2 so one control set and one evidence base serves both. Read the guide
ISO/IEC 42001
The AI management standard now appearing in enterprise procurement, certified by an accredited certification body. Read the guide
EU AI Act
Article-by-article classification, technical documentation, and the obligations phasing in through 2027. Read the guide
NIST AI RMF
The framework US buyers ask about, mapped to work you are already doing. Read the guide
GDPR for AI
Where data protection and AI governance overlap, handled once rather than twice. Read the guide

THE DIFFERENCE

Assurance that remains current between reporting cycles.

Enterprise buyers no longer accept a policy document as proof. They ask who approved the claim, what evidence sits behind it, and when it was last reviewed. We keep the record live, so the answer you give in month nine is as good as the one you gave at audit.

SERVICES

Services across the compliance lifecycle.

SOC 2 readiness and implementation

Scope, Trust Services Criteria, control implementation, policies, evidence and CPA audit coordination, run as one programme to a defined report date.

Compliance readiness and gap assessment

Where you stand against the framework you are being measured on, and what it will take. Days, not weeks.

Security control and policy implementation

Access administration, change management, logging, vulnerability management, incident response and vendor oversight, implemented so they operate every day.

Audit readiness and independent assessment support

Evidence coordination, interview preparation and findings remediation for an independent CPA examination or a certification assessment, depending on the framework.

Compliance project management

One plan, one owner list, one timetable. We manage the platform, the internal workstreams and the audit firm's requests.

Continuous compliance and assurance

Systems change, vendors change, rules change. We keep the control set and evidence current so the next period is a review, not a rebuild.

Buyer security reviews

Approved claims and supporting evidence used consistently across questionnaires, diligence calls and buyer-facing material, so the answers hold up under scrutiny.

AI governance implementation

Where AI is in scope, the policies, responsibilities, controls and evidence required by ISO/IEC 42001 and the EU AI Act, built on the same control base.

WHO THIS IS FOR

Where our engagements typically begin.

An enterprise customer has asked for a SOC 2 report

A deal is waiting on assurance you do not have yet. We scope the examination, build the control environment and take you to a report.

Controls have to be ready for a defined audit window

The window is fixed and the gap is real. We run implementation, evidence and the timetable so the observation period starts on time.

Vanta, Drata or Secureframe is in place, the programme is not finished

The platform shows what is missing. We work inside it and do the work: policies, controls, remediation, evidence and project management.

SOC 2 has to be maintained while another framework is added

ISO 27001, ISO/IEC 42001 or AI governance requirements arrive next. One control set and one evidence base serves them together.

HOW WE WORK

Three stages, with clarity on what each one delivers.

01

Scope

We review your systems, your target buyers and the standards you are being measured against, and agree a scope, a price and a schedule before any work starts.

02

Build

We stand up the management system, the controls and the evidence, and draft the artefacts against the standard you will be examined on.

03

Assure

After certification we keep the record current, answer buyer reviews from it, and track the regulatory changes that affect you.

ABOUT HAEL

A compliance consultancy specialising in SOC 2 and information security.

Hael manages SOC 2 programmes from readiness and implementation through audit preparation and ongoing compliance, and also supports ISO 27001, ISO/IEC 42001 and EU AI Act programmes. We work with technology and service businesses in the United States, the United Kingdom and Europe.

Every engagement is led by a practitioner. We agree scope, price and schedule before any work starts, deliver the controls, policies and evidence behind the report, and stay engaged afterwards so the position remains current between reporting periods.

We do not perform SOC 2 examinations and we do not issue SOC 2 reports. The examination is performed and the report issued by an independent, appropriately licensed CPA firm. Our work is to make the control environment presented for examination real, operating and evidenced.

Advisory practitioner at work in a professional office.

WHAT HAEL IS

A compliance consultancy specialising in SOC 2.

Hael is a compliance consultancy specialising in SOC 2, information security and technology assurance. We manage SOC 2 programmes end to end: scope and Trust Services Criteria selection, readiness assessment, control implementation, policy drafting, evidence preparation, project management, audit preparation and ongoing compliance. We work with technology companies across the United States, the United Kingdom and Europe.

Alongside SOC 2 we run ISO 27001 certification programmes and, where AI systems are in scope, ISO/IEC 42001 and EU AI Act work. Where frameworks overlap, one control set and one evidence base serves both.

Hael is not a CPA firm. We do not perform SOC 2 examinations and we do not issue SOC 2 reports. The examination is performed and the report issued by an independent, licensed CPA firm, which we help you select and coordinate. We are not an ISO certification body and issue no certificates. We take no commission from audit firms, certification bodies or compliance platforms.

SOC 2 compliance consulting

INSIGHTS

Written for the people who have to operationalise it.

Guides and briefings on the standards, the regulations, and the reviews that decide enterprise deals.

View all insights

Start with a scoping call.

Tell us the framework and the deadline. We will set out what the work involves and what it will cost. Thirty minutes, no obligation.

Book a meeting