Trust services

SOC 2 Type II — in observation.

Halo is working toward a SOC 2 Type II report. Controls are implemented across four Trust Service Criteria; the observation period is underway. First report expected next fiscal year.

SOC 2 compliance badge

Our position, in detail

Criteria in scope

Security (mandatory), Availability, Confidentiality, and Privacy. Processing Integrity is not in scope because Halo isn’t a transactional financial or medical-decisioning system.

Security

Access controls, encryption, endpoint protection, network segmentation, vulnerability management, penetration testing, incident response, secure SDLC. All controls mapped to CC-series criteria and evidenced monthly.

Availability

Multi-AZ deployment, automated failover, RPO 15 minutes / RTO 4 hours, chaos engineering exercises quarterly. Public status page at status.haloconnectedhealth.com.

Confidentiality

Data classification scheme (public / internal / confidential / restricted). Encryption at rest with per-tenant AWS KMS Customer Managed Keys. TLS 1.3 for transit. Confidential data segregated by tenant at DB row-level.

Privacy

Notice, choice, collection, use, retention, disclosure, quality, monitoring — every principle mapped to a specific system behaviour. Aligned to UK GDPR requirements.

Auditor

Independent third-party auditor engaged. Auditor selection and interim status available under NDA.

Documents & evidence available under NDA

  • Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
  • Sub-processor register
  • Data Processing Agreement template
  • Incident response runbook (redacted)
  • Independent penetration test summary
  • Latest internal audit findings (redacted)

Need this evidence for procurement?

Send us an NDA and we’ll return the full evidence pack for SOC 2 within 3 working days.