Trust Center

Security and privacy you can show your auditor.

Halley is built for regulated workflows: encrypted everywhere, scoped to approved data, source-linked and auditable, hosted in the U.S. with a SOC 2 compliant provider — and honest about what HIPAA-capable means.

Posture at a glance U.S. hosted
Encrypted everywhereAES-256 at rest · TLS 1.2/1.3 in transit.
No training on your dataYour content answers — it never trains shared models.
Auditable by designSource-linked answers, logging, regular audits.
SOC 2 hosting · NIST & ISO 27001 aligned
Controls

How we protect your data.

The same controls that let us serve healthcare and regulated operations apply across every deployment.

Encryption

Data at rest secured with AES-256; data in transit protected via TLS 1.2/1.3 over encrypted channels.

Access control

MFA on critical systems, role-based access (RBAC), and regular access reviews as roles change.

Controlled data boundaries

Assistants are scoped to approved sources; your content is never used to train shared models.

Monitoring & logging

Continuous monitoring, comprehensive logs for forensics, and periodic security audits.

U.S. hosting

Hosted in U.S. data centers operated by Rackspace®, a SOC 2 compliant provider.

Incident response

A structured plan to contain and resolve incidents, with post-incident review and continuous improvement.

HIPAA

HIPAA-capable — stated honestly.

What this means: Public demos, marketing assistants, and standard lead-capture forms are not intended to collect PHI. When PHI is in scope, Halley runs as a scoped custom implementation with a defined boundary, approved vendors and subprocessors, appropriate agreements (including BAA coverage), and documented safeguards before launch.

HIPAA scope depends on the deployed environment, data-handling rules, vendor contracts, BAA coverage, access controls, retention policy, monitoring, and operating procedures. We describe healthcare work as HIPAA-capable custom implementation rather than blanket HIPAA compliance for every deployment — because that's the accurate description.

Have a security or compliance question?

Talk to our team about controls, BAAs, and deployment boundaries for your environment.

Talk to our team