Security & compliance

Audit-ready by design.

Care providers operate under some of the most demanding regulatory frameworks in any industry. Halo is built to make those frameworks easier to live with — not harder. Every access to a record is logged. Every alert is timestamped and attributed. Every data subject request becomes a one-click export.

UK-built. UK-hosted. UK-aligned.

Layered protective shields labelled UK GDPR, DSPT, ISO 27001, DCB 0129 / 0160, and CQC 12 and 17

Where we stand on each framework

Click through to the detail page for each framework — you’ll find our current position, the evidence we maintain, and where we’re going.

UK GDPR / Data Protection Act 2018

Lawful basis, DPIA process, data subject request fulfilment, cross-border transfer position.

Read more →

NHS Data Security & Protection Toolkit

Our position on each of the ten DSPT data security standards and the supporting evidence we maintain.

Read more →

ISO 27001:2022

Information Security Management System scope, Statement of Applicability, gap analysis position.

Read more →

SOC 2

Trust Service Criteria we’re building toward (Security, Availability, Confidentiality, Privacy).

Read more →

HIPAA

Technical safeguards under §164.312 — encryption, audit controls, integrity, access control, transmission security. BAA template available.

Read more →

CQC fundamental standards

How Halo’s controls map to each Fundamental Standard and corresponding KLOE. Evidence pack downloadable for inspection prep.

Read more →

Clinical Safety (DCB 0129 / 0160)

Hazard identification, clinical risk management and the safety case for a connected health platform under NHS Digital’s clinical risk management standards.

Read more →

Where we are on the compliance journey

We’re honest about certification status. Not every framework listed above is a live certification — some are in-progress. Here’s the truth:

  • UK GDPR / DPA 2018 — compliant, DPO appointed, ROPA maintained, DPIAs conducted per feature launch.
  • NHS DSPT — self-assessment submitted and in review; we publish our answers on request under NDA.
  • ISO 27001:2022 — ISMS in place, Statement of Applicability drafted, external certification audit scheduled.
  • Cyber Essentials Plus — certified.
  • SOC 2 Type II — controls implemented, observation period underway. First report expected next fiscal year.
  • HIPAA — technical safeguards implemented for our US pilot partners; BAA available.
  • DCB 0129 / 0160 — Clinical Safety Officer appointed, Clinical Safety Case Report drafted, hazard log maintained.

Security posture at a glance

Encryption in transit

TLS 1.3 only. HSTS preload. Certificate transparency monitoring.

Encryption at rest

AES-256 for structured data (RDS Postgres, DynamoDB). Envelope encryption via AWS KMS with per-tenant CMKs.

Access control

RBAC + attribute-based scoping. Break-glass access logged and reviewed weekly.

Audit logging

Every read AND write of resident data logged with actor, action, timestamp, IP. Immutable append-only log in S3 Object Lock.

Backups

Point-in-time recovery for Postgres (7 days minimum). Cross-region encrypted replication.

Incident response

IR runbook exercised quarterly. SLA-backed notification of confirmed breaches within 24 hours.

Procurement without the procurement dance.

Request our compliance pack — full evidence bundle, DPIA extract, ISMS scope, and DPA templates under NDA.