About Halo
Compliance work has a credibility problem: the record of who approved what, on what evidence, is usually scattered across spreadsheets, tickets, and Slack threads — reconstructed after the fact for an auditor rather than kept as it happens. As AI tools get folded into that work, the problem compounds: a recommendation quietly becoming an approved control, with no record of a human ever having agreed to it, is the exact failure mode that turns a control programme into liability rather than assurance.
Halo is built to make that failure mode structurally impossible rather than procedurally discouraged. It is an AI-native, human-governed control operations platform: AI does the reading, mapping, and drafting; a human makes every decision that changes what “approved” means; and the record of that decision — including any moment someone overrode a flagged risk, and why — is written down immutably, not reconstructed later.
Our doctrine
- —The canonical control workbook remains the single source of truth — the platform is the operating layer on top of it.
- —AI may observe, infer, stage, recommend, and summarise. AI may never directly mutate approved state.
- —Human approval is mandatory before anything is promoted to approved truth.
- —Approved, Staged, Experimental, and Archived zones stay technically and visibly distinct at all times — no view is allowed to blur them.
- —Halo tracks and supports a customer’s path to certification; it does not itself certify or assert compliance status.
Halo is built on the canonical Common Controls Framework — a structured, cross-framework control library mapped to SOC 2, ISO 27001, MAS TRM, DORA, and the EU AI Act. It is designed for security and compliance teams running a real, ongoing control programme across multiple frameworks and jurisdictions — not a one-time certificate sprint.
