WHY HAEL
A SOC 2 report, and controls that still operate behind it.
The criteria are public. What separates a clean report from a qualified one is whether the controls actually operate, whether the evidence holds together when an examiner tests it, and whether it still describes what you do six months later. That is what we build, and what we keep current.
Practice
Every engagement is led by a practitioner who has taken organisations through authorisation, supervision and examination. Scope is set correctly at the outset rather than corrected late in the programme.
Method
Scope, price and timetable are agreed before work begins. Progress, outstanding items and required client input are reported weekly.
Record
Systems, controls, evidence and approvals are maintained in a single record. It is included in every engagement and remains with the client afterwards.
FRAMEWORKS
One partner across every framework.
Delivered by the same team, against one evidence base.
SERVICES
Services across the compliance lifecycle.
SOC 2 readiness and implementation
Scope, Trust Services Criteria, control implementation, policies, evidence and CPA audit coordination, run as one programme to a defined report date.
Compliance readiness and gap assessment
Where you stand against the framework you are being measured on, and what it will take. Days, not weeks.
Security control and policy implementation
Access administration, change management, logging, vulnerability management, incident response and vendor oversight, implemented so they operate every day.
Audit readiness and independent assessment support
Evidence coordination, interview preparation and findings remediation for an independent CPA examination or a certification assessment, depending on the framework.
Compliance project management
One plan, one owner list, one timetable. We manage the platform, the internal workstreams and the audit firm's requests.
Continuous compliance and assurance
Systems change, vendors change, rules change. We keep the control set and evidence current so the next period is a review, not a rebuild.
Buyer security reviews
Approved claims and supporting evidence used consistently across questionnaires, diligence calls and buyer-facing material, so the answers hold up under scrutiny.
AI governance implementation
Where AI is in scope, the policies, responsibilities, controls and evidence required by ISO/IEC 42001 and the EU AI Act, built on the same control base.
WHO THIS IS FOR
Where our engagements typically begin.
An enterprise customer has asked for a SOC 2 report
A deal is waiting on assurance you do not have yet. We scope the examination, build the control environment and take you to a report.
Controls have to be ready for a defined audit window
The window is fixed and the gap is real. We run implementation, evidence and the timetable so the observation period starts on time.
Vanta, Drata or Secureframe is in place, the programme is not finished
The platform shows what is missing. We work inside it and do the work: policies, controls, remediation, evidence and project management.
SOC 2 has to be maintained while another framework is added
ISO 27001, ISO/IEC 42001 or AI governance requirements arrive next. One control set and one evidence base serves them together.
HOW WE WORK
Three stages, with clarity on what each one delivers.
Scope
We review your systems, your target buyers and the standards you are being measured against, and agree a scope, a price and a schedule before any work starts.
Build
We stand up the management system, the controls and the evidence, and draft the artefacts against the standard you will be examined on.
Assure
After certification we keep the record current, answer buyer reviews from it, and track the regulatory changes that affect you.
WHAT HAEL IS
A compliance consultancy specialising in SOC 2.
Hael is a compliance consultancy specialising in SOC 2, information security and technology assurance. We manage SOC 2 programmes end to end: scope and Trust Services Criteria selection, readiness assessment, control implementation, policy drafting, evidence preparation, project management, audit preparation and ongoing compliance. We work with technology companies across the United States, the United Kingdom and Europe.
Alongside SOC 2 we run ISO 27001 certification programmes and, where AI systems are in scope, ISO/IEC 42001 and EU AI Act work. Where frameworks overlap, one control set and one evidence base serves both.
Hael is not a CPA firm. We do not perform SOC 2 examinations and we do not issue SOC 2 reports. The examination is performed and the report issued by an independent, licensed CPA firm, which we help you select and coordinate. We are not an ISO certification body and issue no certificates. We take no commission from audit firms, certification bodies or compliance platforms.
INSIGHTS
Written for the people who have to operationalise it.
Guides and briefings on the standards, the regulations, and the reviews that decide enterprise deals.





