This page describes how the Halo Lineage platform is designed. Specific commitments for customers are set out in the customer agreement and data processing agreement.
Principles
Read-only by design
Halo Lineage connects to institutions to read data. It does not hold the authority to move money or place trades. Instructions to banks stay with the office’s own authorized people.
People approve every action
AI agents draft reports, letters, requests and proposals. A named person at the office reviews and approves before anything is sent to a family or to an institution. Every approval is recorded.
Isolation per office
Each office’s data is logically separated, with access enforced at the database level. Staff of one office cannot see another office’s data. Anonymized peer benchmarks are created only from offices that opt in, and never expose a family or an office.
Least privilege
Roles define who sees what: administrators, advisors, finance staff and families each see only what they need. Families see only their own data, and can see who in the office accessed it.
Protection in practice
- Encryption in transit (TLS) and at rest.
- Strong authentication, with single sign-on and multi-factor options for staff, and secure sign-in for families.
- Original source files kept alongside parsed data, so every figure can be traced back to its document.
- A full audit trail of sign-ins, views, changes, approvals and exports.
- Reputable cloud infrastructure, regular backups and monitoring.
- Data residency options to keep client data in the region the office requires.
Privacy and regulation
Halo Lineage is designed around Israel’s Privacy Protection Law, including Amendment 13 and the Data Security Regulations, and around the GDPR. Financial information is treated as information of special sensitivity. Where collecting data from institutions requires a license, Halo Lineage works through appropriately licensed partners.
Report a vulnerability
If you believe you have found a security issue, please email me@idanshchori.com with details. Please do not access data that is not yours, do not disrupt the service, and give us reasonable time to fix the issue before disclosing it. We appreciate responsible reports.