Security at Hael
We treat security as a first-order product requirement, not an afterthought.
Programme
Hael is built and operated to recognised information-security standards. Controls are implemented across access, encryption, tenancy, logging, and incident response, and are independently tested.
- Aligned to ISO/IEC 27001 controls across access, cryptography, operations, and supplier management
- Aligned to UK GDPR, EU GDPR, and the UK Data Protection Act 2018
- Third-party penetration testing on a defined annual cadence, with quarterly internal control assessments
Architecture
- Tenant isolation — Row-Level Security on every multi-tenant table, validated by an automated cross-tenant attack suite gated in CI
- Authentication — bcrypt-hashed passwords, MFA enforced for admin roles, session lifecycle audited
- Audit log — tamper-evident SHA-256 hash chain, 7-year retention, regulator-friendly export
- Encryption — TLS 1.3 in transit, AES-256 at rest
- Headers — strict Content-Security-Policy, HSTS preload, COOP/COEP isolation
- Edge protection — rate limiting, WAF rules, CSP violation reporting
Operations
- 24/7 alerting on security signals and SLA breaches
- Documented incident-response runbook with severity classifications
- Tested business-continuity and disaster-recovery plans
- Vendor security reviews before any sub-processor engagement
- Background checks on personnel with production access
Compliance & alignment
We state our posture plainly. We do not display badges we have not earned.
- ISO/IEC 27001 — aligned to ISO/IEC 27001 controls
- UK GDPR / EU GDPR / UK Data Protection Act 2018 — aligned; a data-protection programme is in operation and a DPO is appointed
- EU AI Act — self-applied to our own AI systems as part of building the platform
- Independent penetration testing — we run third-party penetration testing on an annual cadence. Summary available under NDA on request.
Where a certification is held, we will publish the report reference here.
Responsible disclosure
Report vulnerabilities to security@hael.ai. We acknowledge within 2 business days and aim to remediate critical issues within 14 days. We do not pursue legal action against good-faith researchers who follow our Responsible Disclosure policy.
For more detail, request our security questionnaire (CAIQ + SIG Lite) at trust@hael.ai.