Hael is an advisory firm. In the course of an engagement we handle some of the most sensitive material an organisation holds: risk registers, audit findings, incident records, penetration-test reports and unremediated control gaps. This page sets out how we protect it.
We state our position plainly. Where we hold a certification we say so. Where we align to a standard without holding a certificate, we say that instead.
Our position on standards
- ISO/IEC 27001 — we operate an information-security management system aligned to ISO/IEC 27001. We do not currently hold an accredited ISO/IEC 27001 certificate and we do not claim one.
- UK GDPR, EU GDPR and the Data Protection Act 2018 — we act as a data processor for client engagement material and as a controller for our own business records, and we operate to those obligations.
- ISO/IEC 17021-1 — we do not certify. Certification is granted by an accredited certification body independent of the consultancy that built the management system, and we keep that separation absolute.
Engagement material
- Client material is held in named, access-controlled workspaces. Access is granted per engagement, to the individuals working on it, and withdrawn at closure.
- Findings, gap registers and draft artefacts are treated as confidential to the client and are never used as examples, templates or case material without written permission.
- Material is encrypted in transit and at rest by the platforms we use to hold it.
- Multi-factor authentication is required on every account with access to client material.
- We return or destroy engagement material at the client's direction at the end of an engagement, subject to the retention period in the engagement letter.
Our people
- Every person with access to client material is subject to a written confidentiality undertaking.
- Access is granted on the basis of the engagement they are assigned to, and no wider.
- We do not subcontract advisory work without the client's prior written agreement.
Our own technology
Hael operates a governance platform used during engagements and, where a client chooses, afterwards as their system of record. Where a client uses it, the terms in the engagement letter govern how their data is held, who may access it, and what happens at the end of the term.
Reporting a security concern
If you believe you have found a security issue affecting Hael, email hello@hael.ai. We will acknowledge within two business days and keep you informed while we investigate. We will not pursue action against anyone who reports an issue in good faith and does not access or alter data belonging to others.
Questions from procurement
If your security or procurement team needs to assess Hael before an engagement, email hello@hael.ai. We will answer your questionnaire directly, on your form, and we will tell you where the answer is "we do not do that" rather than fill a box.
