Hael
Book a meeting

TRUST

We hold the material you would least like to lose.

An engagement gives us your risk register, your audit findings, your incident records and your unremediated gaps. This page sets out how that material is protected, what we are aligned to, and what we do not claim.

Our position

Where we are certified, and where we are not.

Advisory firms are quick to imply certifications they do not hold. We state ours plainly. If a procurement team needs a certificate we do not have, we will tell you before you ask twice.

ISO/IEC 27001

We operate an information-security management system aligned to the standard. We do not hold an accredited certificate and we do not claim one.

UK GDPR, EU GDPR and the Data Protection Act 2018

We act as a processor for client engagement material and as a controller for our own business records, and we operate to those obligations.

ISO/IEC 17021-1

We do not certify. Certification is granted by an accredited certification body independent of the consultancy that built the management system. We keep that separation absolute.

Engagement material

How your material is handled.

The same discipline we ask our clients to evidence, applied to ourselves.

Access is granted per engagement

Client material sits in named, access-controlled workspaces. Access is given to the people working on the engagement, and withdrawn at closure.

Findings stay confidential

Gap registers, audit findings and draft artefacts are never reused as examples, templates or case material without written permission.

Encrypted, and behind multi-factor authentication

Material is encrypted in transit and at rest. Every account with access to client material requires multi-factor authentication.

Returned or destroyed at your direction

At the end of an engagement we return or destroy the material as you instruct, subject to the retention period in the engagement letter.

Confidentiality in writing

Everyone with access is under a written confidentiality undertaking. We do not subcontract advisory work without your prior written agreement.

One point of contact

Security and procurement questions are answered by the people delivering the work, on your form, in writing.

The platform

Our technology, and your data in it.

Hael operates a governance platform used during engagements and, where a client chooses, afterwards as their system of record for AI systems, controls and evidence.

Where you use it, your engagement letter governs how the data is held, who may access it, and what happens at the end of the term. Nothing is shared between clients.

How the record works →
Questions and disclosures

One address, answered by the people doing the work.

If your security or procurement team needs to assess Hael before an engagement, email hello@hael.ai and we will complete your questionnaire on your form. If you believe you have found a security issue affecting Hael, use the same address: we acknowledge within two business days and will not pursue anyone who reports in good faith without accessing data belonging to others.

Book a meetingPrivacy noticePolicy change history