SOC2C

Is this your company? Buyers are checking Haiilo here. Claim haiilo.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Haiilo logo

Haiilo

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Haiilo is SOC 2 Type II compliant. Haiilo also holds ISO 27001, GDPR, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

We help companies build their unique culture through the stories of their employees and empower their workforce to be the best version of themselves – any where at any time.

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee NameEmployee Email Address

Documents

3

Subprocessors

10
  • T
    T-Systems International GmbH · External Key Management (applies to EU Sovereign Cloud only)
    Germany
  • G
    Google Cloud Platform · Hosting Provider
    Germany (for USA customers: USA)
  • A
    Amazon Web Services · Advocacy Hosting Provider
    Ireland
  • Z
    Zendesk Inc · SaaS Servicedesk (Ticket System)
    European Economic Area (EEA)
  • I
    ImageKit Inc · Content Delivery Network (Optimised Media Delivery)
    Germany
  • T
    Twilio Inc · Email sending/Delivery service
    USA
  • M
    Mailchimp - The Rocket Science Group · Editing and sending Emails
    USA
  • G
    Gainsight Inc. (Skilljar) · Knowledge sharing
    USA
  • A
    Appcues · Digital Adoption Platform Service
    USA
  • S
    Sisense · Data analytics
    Germany

Compliance leadership

The person who leads Haiilo's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Haiilo's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Haiilo SOC 2 compliant?
Haiilo is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Haiilo ISO 27001 certified?
According to Haiilo's public trust center, Haiilo is ISO 27001 certified. On SOC2C this listing is Listed.
Is Haiilo GDPR compliant?
According to Haiilo's public trust center, Haiilo is GDPR compliant. On SOC2C this listing is Listed.
Is Haiilo HIPAA compliant?
According to Haiilo's public trust center, Haiilo is HIPAA compliant. On SOC2C this listing is Listed.
Is Haiilo SOC 2 Type I or Type II?
Haiilo is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Haiilo

Reproduced from Haiilo's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does the system ensure data availability and recovery in case of an incident?
We run daily backups of all relevant systems, storing them at geo-redundant locations that are optimized for performance. These backups are readily available for incident recovery, ensuring data availability and minimizing downtime.
How does the system ensure the security of its IT infrastructure and web applications?
We conduct annual penetration tests (pentests) on our IT infrastructure and web applications to identify and address potential vulnerabilities. Additionally, we perform regular internal security scans and checks as part of our secure software development lifecycle process to maintain robust security standards.
How does the system ensure that its IT infrastructure is secure and up-to-date?
Our internal and external IT infrastructure is hardened in accordance with the CIS Benchmark. We regularly benchmark our systems to identify any potential vulnerabilities and apply necessary updates as quickly as possible to maintain a secure environment.
How is data protected in transit and at rest, and how are users' passwords secured?
All data in transit is secured via HTTPS with TLS 1.2 or higher, incorporating Perfect Forward Secrecy (PFS) and earning an A+ rating with Qualys. At rest, data is encrypted using AES 256, meeting regulatory and industry standards. Additionally, we use robust one-way hash functions to encrypt users' passwords, minimizing the impact of potential data breaches.

Business & Industrial peers that completed SOC 2