Security & trust

Built to pass vendor due diligence.
Not to be explained around it.

Banks hold Halden to the same standard as any critical ICT provider. Everything your security, outsourcing and DORA teams need is documented and published, not hidden behind a form.

Deployment

Three ways to run Halden. Same product in each.

Fastest to start

Halden Cloud (EU)

  • Hosted exclusively in EU data centres
  • Dedicated server instance per institution
  • Managed updates and template releases
Your cloud, your keys

Private cloud

  • Deployed in your own cloud subscription (Docker or systemd)
  • Encryption at rest with your own platform keys
  • Your network and access policies apply
Nothing leaves the building

On-premise

  • Runs inside your own data centre
  • AI assistant off, or on a local model with no outbound calls
  • Air-gapped installation possible
AI and your data

Clear answers to the questions your CISO will ask.

Is our data used to train models?Halden never uses customer data to train models. Third-party backends follow their own terms, so banks that need certainty use the local model.
Where does the AI run?Your choice per deployment: off, a local model inside your network, or Groq Cloud. On-premise means on-premise.
Can the AI change a submission?No. It only proposes rules; approved rules do the filling.
Is AI activity logged?Yes. Every request, and every accepted rule with its approver, is kept in the audit log. Users see the exact data before anything is sent.
Can we switch it off?Yes. Rules can be written fully by hand.
Controls

The controls you'd expect, documented the way auditors like.

Single sign-on

OpenID Connect with Entra ID, Okta, Google and others; signatures checked against the provider’s keys. Roles from your groups, SCIM provisioning, password login can be switched off.

Roles & four-eyes

Admin, maker, checker and viewer roles per organisation, with a recorded periodic access review. No one approves their own rule.

Encryption

TLS in transit, PBKDF2-hashed passwords and hashed tokens; data at rest encrypted at volume level.

Hash-chained audit log

Sign-ins, approvals, AI requests and exports, each chained to the last, so tampering breaks the chain. Export to your SIEM.

Penetration testing

Independent tests [CADENCE]; summaries shared under NDA.

Continuity

Nightly backup script, one-command restore, and a local mode that keeps working if the server is down.

Compliance

Certifications and regulatory support.

ISO/IEC 27001Information security management[STATUS]
SOC 2 Type IIIndependent controls attestation[STATUS]
GDPRData processing agreement and EU-only processingAvailable
DORAInput for your register of information, exit plans and resilience testingAvailable
EBA outsourcing guidelinesAudit, access and termination rights in our contractAvailable

Need more than the pack?
Our engineers will join your review.

Talk to sales

We'll walk through your use case and show the product on data structured like yours.

Talk to sales Book a 30-minute call
[sales@yourdomain.eu][+31 20 000 0000]
Talk to sales