Haleos builds products that people and institutions trust with important work. Security is part of how those products are made, not a layer added afterward. This page describes our security program at the level of principle and practice. It is written for customers, prospects, and the public.
This page is not a technical blueprint. Haleos technology is proprietary. We do not publish system architecture, internal frameworks, control implementations, or other information that would help someone attack the Services or copy our work.
Our commitment
We protect the confidentiality, integrity, and availability of customer information. We design the Services so that access is limited to what is needed, changes are controlled, and incidents can be detected and answered.
Qualified customers may receive additional security information under a non-disclosure agreement. Public Trust Center pages are intentionally limited to information that can be shared without reducing our protection or revealing Haleos proprietary technology.
Principles
We operate to a small set of durable principles:
- Least privilege. People and systems receive only the access required for their role.
- Separation. Customer information is kept logically separate. One customer is not given another customer’s content.
- Defense in depth. No single control is treated as sufficient.
- Secure defaults. New systems and features are reviewed for security before they are broadly available.
- Least disclosure. We share the minimum operational detail needed for a customer to assess trust.
These principles describe how we work. They are not an inventory of Haleos methods.
Protecting information
Customer information is protected in transit and at rest using industry-standard cryptography. We limit where information is stored and who can reach it. We retain information as described in our Privacy Policy, then delete or de-identify it when it is no longer needed.
We do not use public pages to describe storage layouts, processing paths, or internal data handling. Those details are Haleos confidential information.
Access and identity
Administrative access to Haleos systems is restricted to authorized personnel, protected by strong authentication, and reviewed. Production access is logged. We revoke access when it is no longer required.
Customers are responsible for the accounts, credentials, and permissions they control, and for the information they choose to submit.
People and vendors
Employees and contractors who may encounter customer information are bound by confidentiality and are granted access only as needed. We review vendors that process customer information and require contractual protections appropriate to the service they provide.
We do not publish a complete vendor or infrastructure map on this page. Doing so would not help a customer use the Services and would create unnecessary exposure.
Product security
Haleos reviews changes that could affect the security of the Services. We maintain processes for identifying and remediating vulnerabilities. We prohibit unauthorized testing of the Services; authorized security research must be arranged in writing.
You may not use security testing, traffic inspection, or product use to discover Haleos proprietary technology. Security research authorized by Haleos is limited to the scope we approve and does not include a right to copy or disclose our methods.
Enterprise and institutional deployments
Haleos offers enterprise and institutional arrangements, including options discussed with qualified customers for deployment, residency, and administrative control. The specific arrangement is defined in the commercial agreement. Public marketing describes the existence of those options. It does not disclose implementation detail.
Monitoring and incident response
We monitor for conditions that may indicate abuse, fraud, or a security incident. If we confirm an incident that affects your personal information in a way that the law requires us to notify, we will notify you and, where required, regulators, without undue delay.
Current availability of Haleos public systems is published on our System Status page.
Please report suspected security issues to security@haleos.com. Include enough detail for us to investigate. Do not include exploit code or instructions in a public channel.
Compliance program
Haleos maintains a security and privacy program aligned with widely recognized enterprise frameworks. Independent assessments and attestations are made available to qualified customers under appropriate confidentiality. Current status should be confirmed with Haleos; public badges and summaries are not a substitute for the underlying report.
We do not treat a public badge as permission to disclose the evidence behind it.
What this page does not include
To protect our customers and our company, this page does not include:
- Internal architecture, diagrams, or system inventories
- Model, method, or framework descriptions
- Detailed control configurations
- Unpublished product plans
- Information that would materially assist an attacker or a competitor
If a questionnaire asks for that information, we will respond through a confidential customer process, not through the public website.
Your responsibilities
Security is shared. You should:
- Use strong authentication and keep credentials confidential
- Submit only information you have the right to submit
- Review Outputs before relying on them
- Notify Haleos promptly of suspected unauthorized access
- Use the Services in accordance with our Terms of Use
Contact
Security: security@haleos.com Privacy: privacy@haleos.com Legal: legal@haleos.com
Haleos, Inc. Austin, Texas United States