Hael
Sign inRequest a demo
Trust Center

Hael's security and governance posture.

We hold our own AI systems to the standard Hael enforces. This is our live posture — the same surface Hael gives every customer.

Certifications in progress are shown as in progress; alignments are shown as alignments. We do not display badges we have not earned.

Aligned to ISO/IEC 27001 controlsGDPR & UK DPA 2018Third-party penetration testedEU & US data residency
Request access to reportsLast reviewed · 2026-07-08
Framework alignment

Built to the standards you're assessed against.

Hael's controls are implemented to recognised information-security frameworks and independently tested. Where Hael is aligned to a framework but not certified against it, we say so — plainly. Tenant isolation, encryption in transit and at rest, MFA on production access, tamper-evident audit logging, incident response, and third-party penetration testing all run continuously. Full detail is on the Security page.

ISO
ISO/IEC 27001
Controls aligned
GDPR
GDPR & UK DPA
Aligned
EU·AI
EU AI Act
Self-applied
PEN
Penetration test
Third-party, annual
Controls

The controls behind the posture.

Every claim above maps to an operating control. These run continuously and are evidenced in our audit chain.

hael.ai / trust / controls
Operating controls
Live posture · enforced
8/8
operating
Encryption in transit & at rest
TLS 1.3, AES-256
Enforced
Access reviews
Quarterly, role-based
Active
Penetration testing
Annual, third-party
Active
Vendor risk monitoring
Continuous
Active
Audit logging
Hash-chained, retained
Enabled
MFA on production access
WebAuthn / TOTP
Enforced
Background checks
All employees
Enforced
Incident response runbook
Tested, on-call rotation
Active
Data handling

Where your data lives, and who touches it.

Customer data is hosted in the EU (London, primary) with US failover, encrypted in transit (TLS 1.3) and at rest (AES-256), tenant-isolated by Row-Level Security, and retained per the customer contract. Hael does not use customer data to train shared or third-party AI models. Full detail is in the Privacy Notice and DPA.

Category
Purpose
Region
Cloud hosting
Application & database hosting
EU (primary), US
Model inference
LLM inference for governance tasks
EU / US
Email
Transactional email delivery
EU / US
Analytics
Product analytics (privacy-preserving)
EU
Error monitoring
Runtime error reporting
EU
Customer support
Ticketing & customer comms
EU
At a glance
Data residencyEU & US
Encryption at restAES-256
Encryption in transitTLS 1.2+
RetentionPer contract
Sub-processor changesNotified in advance
Tenant isolationPer-customer keys
See full sub-processor list →
What you can request

Buyer diligence, on request.

The following documents are shared under mutual NDA, typically within one business day.

Security overview (CAIQ / SIG Lite)
On request
Penetration test summary
On request
Architecture and controls overview
On request
Sub-processor list
On request
DPA
On request
Reports

Request our reports.

Pick the documents you need. We review each request before sharing gated materials; access is granted under NDA, typically within one business day.

Request access
Select one or more documents from the list

We review each request before sharing gated materials. Access is granted under a mutual NDA.

Want this for your own AI systems?

The Trust Center you're looking at is a Hael product. Give your buyers the same live proof of posture — generated from your actual controls, not from prose.