Security & compliance
Audit-ready by design.
Care providers operate under some of the most demanding regulatory frameworks in any industry. Halo is built to make those frameworks easier to live with — not harder. Every access to a record is logged. Every alert is timestamped and attributed. Every data subject request becomes a one-click export.
UK-built. UK-hosted. UK-aligned.
Where we stand on each framework
Click through to the detail page for each framework — you’ll find our current position, the evidence we maintain, and where we’re going.
UK GDPR / Data Protection Act 2018
Lawful basis, DPIA process, data subject request fulfilment, cross-border transfer position.
NHS Data Security & Protection Toolkit
Our position on each of the ten DSPT data security standards and the supporting evidence we maintain.
ISO 27001:2022
Information Security Management System scope, Statement of Applicability, gap analysis position.
SOC 2
Trust Service Criteria we’re building toward (Security, Availability, Confidentiality, Privacy).
HIPAA
Technical safeguards under §164.312 — encryption, audit controls, integrity, access control, transmission security. BAA template available.
CQC fundamental standards
How Halo’s controls map to each Fundamental Standard and corresponding KLOE. Evidence pack downloadable for inspection prep.
Clinical Safety (DCB 0129 / 0160)
Hazard identification, clinical risk management and the safety case for a connected health platform under NHS Digital’s clinical risk management standards.
Where we are on the compliance journey
We’re honest about certification status. Not every framework listed above is a live certification — some are in-progress. Here’s the truth:
- UK GDPR / DPA 2018 — compliant, DPO appointed, ROPA maintained, DPIAs conducted per feature launch.
- NHS DSPT — self-assessment submitted and in review; we publish our answers on request under NDA.
- ISO 27001:2022 — ISMS in place, Statement of Applicability drafted, external certification audit scheduled.
- Cyber Essentials Plus — certified.
- SOC 2 Type II — controls implemented, observation period underway. First report expected next fiscal year.
- HIPAA — technical safeguards implemented for our US pilot partners; BAA available.
- DCB 0129 / 0160 — Clinical Safety Officer appointed, Clinical Safety Case Report drafted, hazard log maintained.
Security posture at a glance
Encryption in transit
TLS 1.3 only. HSTS preload. Certificate transparency monitoring.
Encryption at rest
AES-256 for structured data (RDS Postgres, DynamoDB). Envelope encryption via AWS KMS with per-tenant CMKs.
Access control
RBAC + attribute-based scoping. Break-glass access logged and reviewed weekly.
Audit logging
Every read AND write of resident data logged with actor, action, timestamp, IP. Immutable append-only log in S3 Object Lock.
Backups
Point-in-time recovery for Postgres (7 days minimum). Cross-region encrypted replication.
Incident response
IR runbook exercised quarterly. SLA-backed notification of confirmed breaches within 24 hours.
