Skip to content
Home Features HALO
HALO · NEW

The trust layer your AI is missing.

AI is now part of your supply chain. It moves fast, integrates deeply, and often requires more access than it should. HALO sits between customer data and your AI ecosystem so agents can collect files without ever accessing their contents. Move fast with AI, without extending trust by default.

What's inside HALO

Three components, one security layer.

HALO Send drops the upload modal into the chat. HALO Bridge connects it to whatever AI platform your team runs. HALO Native goes deeper for Zendesk and Intercom. Pick one, mix all three.

HALO Send

In-chat secure upload modal

A drag-and-drop upload modal that opens inside the chat window. Files are encrypted client-side with OpenPGP before they leave the user's device. Supports files up to 100 GB and never breaks the conversation flow.

Trigger: AI agent invokes the modal on intent Encryption: client-side, before upload UX: stays in the chat surface
HALO Bridge

Platform-agnostic connector layer

Standardized APIs that hand encrypted file collection off between AI and human support systems. One connector pattern works across Ada, Amazon Connect, and any contact-centre stack you bring to it.

Trigger: AI-to-human handoff event Surface: standardized REST + webhooks Examples: Ada, Amazon Connect, Agentforce
HALO Native

Deep integrations for Zendesk and Intercom

Native plug-ins for Zendesk Messenger and Intercom Fin that feel like part of the existing interface. Encrypted uploads appear inline in the customer conversation and surface inside the ticket for human agents.

Trigger: Zendesk Messenger / Fin event Surface: native to the messenger UI Compatible with: Fin Tasks, Custom Answers, Workflows
2026 SC Awards Finalist · Best Secure Messaging Solution — HALO

What it looks like in a live chat.

The AI agent identifies a sensitive file is needed and posts a HALO upload modal into the conversation. The customer drags a file in. Encryption happens in their browser. The agent resumes, without ever seeing the file.

support.example/ai-chat
HALO in a live AI chat: an Ada agent collects an identity document through an encrypted upload, without seeing its contents
Supported AI platforms

AI platforms with a HALO path today.

Don't see your agent below? Talk to our team about SendSafely's Universal connector. 

See full AI integrations directory
How it works

Seamless for customers. Invisible to your AI. Secure file collection, built into the conversation.

The agent detects a file is needed, HALO opens a secure upload, the customer's browser encrypts the file, and only authorized human agents (never the AI model) can later open it.

HALO flow step 1 illustration: an AI chatbot requests a sensitive file and HALO opens a secure upload card inside the conversation
The AI agent recognizes that a file is needed and asks HALO to open a secure upload inside the chat.
HALO flow step 2 illustration: the customer's browser encrypts the file with OpenPGP before any byte leaves the device
The file is encrypted with OpenPGP in the customer's browser. SendSafely and the AI platform see ciphertext only.
HALO flow step 3 illustration: an authorized human agent opens the encrypted file from inside the helpdesk after handoff
When the conversation hands off to a human, an authorized agent opens the encrypted file from inside the helpdesk.
Step 01
AI agent requests a file

During a workflow that needs sensitive data, the AI agent recognizes the intent and asks HALO to open an upload modal in the chat.

Step 02
HALO opens in-chat

A secure modal launches inside the chat window. No new tab, no portal hop. The user drags a file in or picks one natively.

Step 03
Browser encrypts client-side

The file is encrypted with OpenPGP in the customer's browser. SendSafely sees ciphertext only. The AI agent collects the file but cannot decrypt it.

Step 04
Secure handoff to humans

When the conversation hands off to a human agent or a back-end system, that authorized party opens the file from inside the ticketing platform.

Protected data never touches inference engines, chatbot logs, or training data. The AI agent only ever sees that a file exists — never its contents.

Who trusts Halo

Three teams, one trust layer for AI.

HALO turns AI chatbots into agents that can safely accept sensitive files — without exposing your tools or your customers.

For support teams

Encrypted file collection right inside the ticket.

Your CX agents accept files inside Zendesk, Intercom, or Salesforce conversations — no tab switch, no copy-paste, no plaintext leaving the customer's browser. Faster resolutions and a paper trail that satisfies compliance.

Zendesk · Intercom · Salesforce
See helpdesk integrations
For IT teams

Deployable in a day. Operable on autopilot.

SAML 2.0 + SCIM for identity. Audit log API to your SIEM. No new servers to host. No key escrow. One vendor across helpdesk, email, and AI workflows — not five.

SAML 2.0 · SCIM · audit log API · REST + SDKs
See the API and SDKs
For security & compliance

Limit blast radius by design.

HALO is the trust layer for sovereign AI: every file your chatbot touches is encrypted on the customer's device. AI vendors, cloud providers, and SendSafely itself only see ciphertext. Limit AI blast radius by design.

SOC 2 Type 2 · HIPAA · PCI DSS · GDPR
Read the security overview

Where teams put HALO to work first.

Anywhere an AI agent needs a file but shouldn't see it. 

KYC and identity verification

Securely collect ID documents, proof of address, and verification materials inside the AI chat. Encryption and audit trail satisfy KYC/AML controls without slowing the flow.

Financial services onboarding

Streamline account opening and loan applications. Sensitive financial documents stay encrypted end-to-end while the AI agent guides the customer through the workflow.

Healthcare intake

HIPAA-aligned collection of medical records, insurance cards, and patient information through chat. BAAs available on Enterprise plans.

Customer support

Collect screenshots, log files, and supporting documents directly inside support conversations — up to 100 GB — for faster resolution without manual ticket back-and-forth.

Split-key architecture

HALO files are encrypted before they reach any AI server

Every HALO upload is encrypted in the customer's browser using OpenPGP. The AI platform, SendSafely, and any model in between all see ciphertext only. The decryption key is split so nobody, not even SendSafely, can read the contents on its own.

SendSafely is SOC 2 Type 2 audited annually. HALO inherits the same compliance posture.

Compliance & certifications
SOC 2 Type 2 HIPAA PCI DSS GDPR CCPA
Client-side OpenPGP
Files are encrypted on the device before they ever leave it.
Split-key architecture
The decryption key is split so no single party—including SendSafely—can decrypt file contents on its own.
Full audit trail
Every send, recipient open, identity check, and download is logged with timestamps for compliance reporting.
Get started

Ship AI customer service without leaking sensitive files.

A SendSafely engineer will walk you through HALO end-to-end and help map a proof-of-concept against your AI platform of choice.