WHAT WE DO
SOC 2 is our core practice.
We manage SOC 2 readiness, implementation, project management and audit preparation end to end: scope and Trust Services Criteria selection, control implementation, policy drafting, evidence preparation, and coordination of the independent CPA firm that performs the examination. We prepare both Type I and Type II engagements, and we remain engaged after the report so controls hold through the following period.
Alongside that we run ISO 27001 certification programmes, ISO/IEC 42001 and EU AI Act work where AI is in scope, and we answer the buyer security reviews that decide enterprise deals. Where two frameworks overlap, one control set and one evidence base serves both.
We support organisations across the United States, the United Kingdom and Europe, and we work inside Vanta, Drata, Secureframe or whichever compliance platform you already own. SOC 2 compliance consulting sets out what a programme involves.
WHERE WE ARE
London and Colorado Springs.
We support clients across the US, UK and Europe from our offices in Colorado Springs and London.
London, W2 6BDUnited StatesBriargate Office Center, 1755 Telstar Drive
Colorado Springs, CO 80920
WHERE WE COME FROM
Fifteen years in regulatory and compliance practice.
Hael is built on fifteen years of regulatory practice, advising firms through authorisation, supervision and examination.
Standards are written to be examined, and the difference between passing and failing is usually a judgement about what is sufficient. That judgement comes from working within examination processes rather than reading about them.
INDEPENDENCE
Independent from the audit.
Hael does not perform the independent SOC 2 examination and does not receive referral commissions from CPA firms. The examination is performed and the report issued by an independent, appropriately licensed CPA firm. We are not a certification body for ISO standards, and we issue no certificates.
We take no commission on platform subscriptions either, so our advice is not shaped by another firm's fee.
THE GAP WE FILL
Between the platform and the report.
Compliance platforms identify which controls are missing. The CPA firm forms an opinion on whether they held, and a certification body decides whether an ISO management system passes. None of them writes the policy, implements the control, assembles the evidence or runs the project.
That work requires judgement about what is enough, and it is where most SOC 2 and certification programmes stall.
OUR METHOD
Scope, build, assure.
The delivery model is the same across frameworks: define scope, implement controls, prepare evidence and manage the assessment.
Scope
We review your systems, the standards you are being measured against, and what your buyers are asking for. We agree what is in scope and what is not, and why.
You receive a written scope, a fixed price and a schedule before any work starts.
Build
We write the policies, establish the controls, assemble the evidence and prepare the documentation. We run the project, hold the schedule, prepare the people who will be interviewed, and manage the relationship with the CPA firm or certification body performing the assessment.
You are told each week what has moved, what is outstanding and what is needed from you.
Assure
Once the report is issued or the certificate granted, we maintain the record, answer buyer reviews from it, re-test controls on an agreed schedule and track the regulatory changes that affect your scope.
The position holds between reporting periods, not only on the day of an audit.
YOUR TOOLS
We work inside the platform you already own.
We work within Vanta, Drata, Secureframe or whichever platform you already have, and configure it properly. Where there is none, the engagement runs on the Hael platform, which is included and remains available to you afterwards as your system of record.
