Security

Version
v3
Effective
Last reviewed

View change history

Security at Hael

We treat security as a first-order product requirement, not an afterthought.

Programme

Hael is built and operated to recognised information-security standards. Controls are implemented across access, encryption, tenancy, logging, and incident response, and are independently tested.

  • Aligned to ISO/IEC 27001 controls across access, cryptography, operations, and supplier management
  • Aligned to UK GDPR, EU GDPR, and the UK Data Protection Act 2018
  • Third-party penetration testing on a defined annual cadence, with quarterly internal control assessments

Architecture

  • Tenant isolation — Row-Level Security on every multi-tenant table, validated by an automated cross-tenant attack suite gated in CI
  • Authentication — bcrypt-hashed passwords, MFA enforced for admin roles, session lifecycle audited
  • Audit log — tamper-evident SHA-256 hash chain, 7-year retention, regulator-friendly export
  • Encryption — TLS 1.3 in transit, AES-256 at rest
  • Headers — strict Content-Security-Policy, HSTS preload, COOP/COEP isolation
  • Edge protection — rate limiting, WAF rules, CSP violation reporting

Operations

  • 24/7 alerting on security signals and SLA breaches
  • Documented incident-response runbook with severity classifications
  • Tested business-continuity and disaster-recovery plans
  • Vendor security reviews before any sub-processor engagement
  • Background checks on personnel with production access

Compliance & alignment

We state our posture plainly. We do not display badges we have not earned.

  • ISO/IEC 27001 — aligned to ISO/IEC 27001 controls
  • UK GDPR / EU GDPR / UK Data Protection Act 2018 — aligned; a data-protection programme is in operation and a DPO is appointed
  • EU AI Act — self-applied to our own AI systems as part of building the platform
  • Independent penetration testing — we run third-party penetration testing on an annual cadence. Summary available under NDA on request.

Where a certification is held, we will publish the report reference here.

Responsible disclosure

Report vulnerabilities to security@hael.ai. We acknowledge within 2 business days and aim to remediate critical issues within 14 days. We do not pursue legal action against good-faith researchers who follow our Responsible Disclosure policy.

For more detail, request our security questionnaire (CAIQ + SIG Lite) at trust@hael.ai.