HaloHalo

A tour of Halo

Every screen below is a real screenshot of the running platform — the same views a practitioner, reviewer, admin, or auditor sees in production.

Controls workspace

01Controls workspace

Browse the full control library with cross-framework mapping visibility. Every control carries its zone, owner, and evidence in one place.

Control detail

02Control detail

Implementation guidance, cross-framework mappings, commentary history, and attached evidence for a single control.

Framework coverage

03Framework coverage

See coverage and gaps against a specific framework — ISO 27001, SOC 2, MAS TRM, DORA, EU AI Act — without leaving the control library.

Review Centre

04Review Centre

A unified queue for every pending human decision. AI proposals, flagged warnings, and override reasons all surface here before anything reaches Approved.

Audit trail

05Audit trail

An immutable record of every state change — who promoted what, on what evidence, with what policy version and integrity hash.

Posture

06Posture

A governance-first view of where the programme actually stands — pending review counts, not a misleadingly aggregated "percent done."

Executive view

07Executive view

A roll-up built for a CRO or a board, not a practitioner — the state of the programme in the language buyers and auditors actually use.

Auditor workspace

08Auditor workspace

A dedicated, scoped view for external auditors — the evidence trail they need, without exposing anything beyond it.

How Halo is different

They've all broadened into multi-framework libraries too — Vanta cross-maps DORA against SOC 2/ISO 27001 as a headline capability, Scrut ships MAS TRM 2021 and DORA out of the box, Sprinto maps AI tooling to ISO 42001, NIST AI RMF, and the EU AI Act. Framework breadth alone isn't the gap it used to be, and we don't claim otherwise. What none of them market is the specific mechanism: a required, named, written reason captured at the moment a human promotes a control despite the AI's own flagged warning, recorded immutably alongside a policy version and integrity hash on every state change. That's what a regulator or a second-year auditor actually interrogates — not “do you cover framework X,” but “who signed off on this control, on what evidence, and did anyone override a flagged risk, and why.”