Trust services
SOC 2 Type II — in observation.
Halo is working toward a SOC 2 Type II report. Controls are implemented across four Trust Service Criteria; the observation period is underway. First report expected next fiscal year.
Our position, in detail
Criteria in scope
Security (mandatory), Availability, Confidentiality, and Privacy. Processing Integrity is not in scope because Halo isn’t a transactional financial or medical-decisioning system.
Security
Access controls, encryption, endpoint protection, network segmentation, vulnerability management, penetration testing, incident response, secure SDLC. All controls mapped to CC-series criteria and evidenced monthly.
Availability
Multi-AZ deployment, automated failover, RPO 15 minutes / RTO 4 hours, chaos engineering exercises quarterly. Public status page at status.haloconnectedhealth.com.
Confidentiality
Data classification scheme (public / internal / confidential / restricted). Encryption at rest with per-tenant AWS KMS Customer Managed Keys. TLS 1.3 for transit. Confidential data segregated by tenant at DB row-level.
Privacy
Notice, choice, collection, use, retention, disclosure, quality, monitoring — every principle mapped to a specific system behaviour. Aligned to UK GDPR requirements.
Auditor
Independent third-party auditor engaged. Auditor selection and interim status available under NDA.
Documents & evidence available under NDA
- Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
- Sub-processor register
- Data Processing Agreement template
- Incident response runbook (redacted)
- Independent penetration test summary
- Latest internal audit findings (redacted)
