HASP and SOC 2
HASP holds a SOC 2 Type II attestation, with controls continuously validated through third-party compliance monitoring. The platform also runs on a managed compliance substrate that carries its own SOC 2 Type II. This page lays out both — what HASP owns and attests to directly, and what is inherited at the substrate layer.
What HASP has today, in plain language.
HASP — SOC 2 Type II attested
HASP holds its own SOC 2 Type II attestation covering the application layer — the gateway, identity model, signed audit chain, and PHI handling — with controls continuously validated through third-party compliance monitoring.
Report and current bridge letter available under mutual NDA. Email [email protected].
Substrate — inherited SOC 2 Type II
In addition, the managed compliance substrate HASP is deployed on carries its own SOC 2 Type II report covering the compute, managed database, network, and operational controls HASP inherits at the infrastructure layer.
Available under the same mutual NDA, alongside HASP's control matrix mapping every criterion to its owner.
Which criteria are addressed.
SOC 2 reports describe how a service organization meets the AICPA Trust Services Criteria. HASP's SOC 2 Type II covers Security, Availability, and Confidentiality, with Privacy planned for a subsequent cycle. The substrate report HASP inherits at the infrastructure layer covers the same three criteria.
Security (Common Criteria)
Logical and physical access controls, change management, risk assessment, and incident response. Inherited at the infrastructure layer from the compliance substrate; extended at the application layer by HASP's gateway, IAM model, and signed audit chain.
Availability
System uptime, capacity planning, backup integrity, and disaster recovery. The compliance substrate carries the substrate availability commitments; HASP's application-layer availability targets and incident handling are described in the control matrix shared on request.
Confidentiality
Designating and protecting confidential information through encryption, access restriction, and disposal controls. The PHI gateway, per-org isolation boundaries, and customer-data retention controls map directly into this criterion.
Privacy (planned, future cycle)
The GDPR / CCPA controls HASP operates — Article 17 erasure, Article 20 portability, consent, sub-processor notice — will be mapped into the Privacy TSC once they have a long enough operating history to support a Type II observation. Not in the current scope.
Processing Integrity (out of scope)
HASP does not perform transactional processing that warrants the Processing Integrity criterion. We do not intend to include it. The signed audit chain provides a stronger equivalent for the events HASP does record.
Controls inherited from the compliance substrate.
The compliance substrate covers compute, database, and network. The following controls live in the substrate's SOC 2 Type II report and HASP does not duplicate them. The control matrix we share with prospects calls out every line so your auditor can trace each criterion to the responsible party.
Infrastructure layer
- Data-center physical security and environmental controls
- Host hardening, kernel patching, anti-malware
- Network segmentation between HASP's tenant and the substrate's management environment
- Vulnerability scanning and intrusion detection on the substrate
- Backup integrity and substrate-level disaster recovery
Operational layer
- 24×7 substrate monitoring and alerting
- Substrate change-management and release controls
- Substrate-operator personnel access logging on production hosts
- Substrate-level incident response and customer notification
- Annual third-party penetration testing of the platform
What HASP operates on top of the substrate.
Inherited substrate controls do not cover the layer where most AI risk actually lives — the gateway between users, agents, models, and customer data. Those controls are HASP's responsibility. They are tested in HASP's SOC 2 Type II attestation and continuously validated through third-party compliance monitoring.
AI gateway and IAM
A single gateway sits between every caller — user, API key, or agent — and every model provider. The gateway enforces tenant boundaries, BAA status, and pre-action authorization. Maps directly into the Security and Confidentiality TSCs.
Signed audit chain
Every PHI-adjacent event is hash-chained and Ed25519-signed. Auditors can verify integrity on their own machine with no HASP software. Verification recipe.
PHI handling
PHI handling is a HASP-owned capability — not outsourced to a third-party AI gateway product. HASP's PHI anonymization pipeline runs inside HASP's tenant boundary before prompts reach the model.
How to request the report.
- Email [email protected] from your work address. Mention SOC 2 and reference your evaluation if you are in an active procurement cycle.
- Mutual NDA. We countersign the standard mutual NDA promptly, or execute your form if your security team prefers. The NDA covers HASP's report, the substrate report, and the HASP control matrix together.
- Bundle delivered. You receive HASP's SOC 2 Type II report and current bridge letter, the substrate SOC 2 Type II report, HASP's signed control matrix mapping each criterion to its owner, and the sub-processor register snapshot pinned to that date.
- Walkthrough on request. If your auditor wants to walk through the matrix line by line, we run a one-hour session with compliance and engineering on the call. No extra cost, no enterprise gating.
Active procurement?
Send the questionnaire format your team prefers — SIG, CAIQ, HECVAT, or a custom workbook. Most are completed promptly.
One compliance floor. Every tier.
HASP's compliance posture is universal. Every tier runs on the same compliance substrate, the same gateway, the same signed audit chain. There is no separate "compliance edition" and no tier where audit logging or PHI handling is switched off. The SOC 2 posture — HASP's own attestation and the inherited substrate report — applies to every organization on HASP.
Higher tiers add capacity and isolation — Enterprise gets a dedicated data plane on dedicated infrastructure, custom domains, and SSO — but the underlying SOC 2 posture is the same control set. See pricing for the full tier matrix and the Trust Center for the complete compliance posture.
Frequently asked questions.
Is HASP SOC 2 compliant?
Yes. HASP maintains its own SOC 2 Type II attestation covering the platform's application-layer controls, with controls continuously validated through third-party compliance monitoring. The report and current bridge letter are available under mutual NDA. In addition, the managed compliance substrate HASP runs on carries its own SOC 2 Type II covering the underlying infrastructure, network, and operational controls HASP inherits — customers receive both reports plus HASP's signed control matrix under mutual NDA.
Is HASP SOC 2 Type I or Type II?
Type II. HASP's attestation is a SOC 2 Type II — controls tested over an observation window, not a point-in-time snapshot. The substrate report HASP inherits at the infrastructure layer is also a Type II.
Can I see HASP's SOC 2 report?
Yes — under mutual NDA. Email [email protected] and reference your evaluation. You receive HASP's SOC 2 Type II report and current bridge letter, the compliance substrate's SOC 2 Type II report for the infrastructure layer, and HASP's signed control matrix mapping each Trust Services Criterion to the responsible owner (HASP, the substrate, or shared).
Which Trust Services Criteria are in scope?
HASP's SOC 2 Type II covers Security, Availability, and Confidentiality. Privacy is planned for a subsequent cycle once the multi-tenant Privacy controls mapped to GDPR / CCPA enforcement are old enough to observe over a Type II window. Processing Integrity is not planned — HASP does not perform transactional processing. The substrate's report covers the same three criteria at the substrate layer.
Who is the auditor?
HASP's SOC 2 Type II is performed by a registered CPA firm; the auditor of record is named on the cover of the report itself, which we share under NDA. The substrate's report likewise names its own auditor of record on its cover.
How often is the audit performed?
Annually, over a rolling observation window, with a continuous controls baseline in between — controls are validated continuously through third-party compliance monitoring, not only during the observation window. The most recent report and bridge letter are both available under NDA. The substrate's SOC 2 Type II is re-issued annually on the same model.
Is the report HASP's own, or inherited from the infrastructure?
Both exist, and you can request both. HASP holds its own SOC 2 Type II attestation covering the application layer — the gateway, identity model, audit chain, and PHI handling. The compliance substrate holds a separate SOC 2 Type II covering the infrastructure layer. The control matrix we share maps every criterion to its owner so your auditor can trace each control to the responsible party.
What about inherited controls from the compliance substrate?
The compliance substrate is the managed hosting platform HASP is built on. The substrate is responsible for the physical and logical security of the cloud environment HASP runs in: data-center security, network segmentation, host hardening, vulnerability scanning, intrusion detection, backup integrity, and incident response at the infrastructure layer. Those controls are evidenced in the substrate's SOC 2 Type II. HASP inherits them and does not duplicate them. The control matrix we share calls out, line by line, which controls are inherited, which are HASP-owned, and which are shared.
How are HASP's sub-processors treated in the SOC 2 scope?
The major sub-processors — the compliance substrate, BAA-covered inference providers, and edge/CDN providers — are addressed in the report, with the controls each one carries described. The current sub-processor register is published at /sub-processors and is governed by the 30-day advance-notice commitment.
What encryption modules does HASP use?
Encryption in transit (TLS) and at rest (AES-256) are described in the SOC 2 control matrix. FIPS 140-3 module references — including the validated modules used by the compliance substrate and edge provider in HASP's chain — are documented separately at /trust/fips-modules so they can be cited in CAIQ and HECVAT questionnaires without depending on the SOC 2 report itself.
The other five frameworks.
HASP covers HIPAA, SOC 2, HITRUST, GDPR, CCPA, and PIPEDA on one control set — designed so that one signed audit chain and one gateway satisfy all six.
HIPAA
BAA available pre-signature, PHI handling at the gateway, 72-hour customer breach notification.
HITRUST CSF
HITRUST CSF e1 certification in progress; substrate-inherited posture available under NDA.
GDPR
Platform-level Article 17 erasure, Article 20 portability, Article 30 records, ADM boundaries.
CCPA / CPRA
Deletion, export, and opt-out served by the same mechanisms as GDPR.
PIPEDA
Canada's ten fair-information principles, satisfied by the same control set as GDPR.
Security overview
Infrastructure, encryption, access controls, application security, and responsible disclosure.
FIPS modules
FIPS 140-3 validated modules in HASP's encryption chain, cited for CAIQ and HECVAT.