Security
Security First
We understand that trust is earned. Our security practices are designed to protect your data with enterprise-grade controls.
Encryption
Data is encrypted in transit (TLS) and at rest (AES-256 where supported). We avoid storing source credentials whenever possible and use secure secrets management when required by integrations.
Access Control
Role-based access control with audit logging for system access and data operations. Multi-factor authentication support is available based on customer identity provider configuration.
Infrastructure
Hosted on enterprise cloud infrastructure with geographic redundancy and automated backups. Halobond maintains a documented SOC 2 Type II readiness program.
Data Minimization
We aim to minimize data collection to what’s necessary for warning generation. Customer data handling and retention depend on configured pipelines and contractual scope.
Compliance
Halobond maintains a documented SOC 2 Type II readiness program. Additional regulatory alignment depends on deployment configuration, contractual scope, and customer requirements.
Incident Response
Incident response procedures are defined and monitoring is in place. Notification timelines are governed by contract and regulatory requirements.