Security at HelixSync

How HelixSync protects your data, what controls are in place today, and what we have not built yet. We would rather tell you plainly than badge something we cannot evidence.

Role-based access control
Audit logging
Tenant isolation
Encrypted in transit

Enterprise-Grade Security

We employ multiple layers of security to ensure your data remains protected at every level.

Data Encryption

All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Your information is protected at every stage.

Access Control

Role-based access control. Admin, Developer and User accounts are scoped to your company, and to your department where a feature supports it. SuperAdmin is the platform operator role held by HelixSync, with access across companies. Single sign-on is not yet available.

Infrastructure Security

Hosted on secure cloud infrastructure with firewalls, intrusion detection, DDoS protection, and regular security patches.

Monitoring & Logging

API requests and authentication events are written to an audit log with the actor, endpoint, action, outcome, IP address and timestamp. HelixSync operators review it from the platform console and threat detection can alert them by email; customer-facing audit reporting is not yet available.

Data Backup

Automated daily backups with point-in-time recovery. Data is replicated across multiple availability zones for redundancy.

Network Security

Web Application Firewall (WAF), VPN access for internal systems, and network segmentation protect against external threats.

Certifications

HelixSync does not currently hold a security certification. Rather than imply otherwise, here is exactly where we stand. If a certification matters to your procurement process, tell us — it helps us prioritise.

SOC 2 Type II

Not certified, and we have not committed to a date. We have not engaged an auditor and hold no report.

ISO 27001

Not certified, and we have not committed to a date. No certification body has assessed our information security management system.

GDPR

We support data export and deletion on request, and describe our processing in the privacy policy. We do not yet publish a data processing agreement or a named sub-processor list.

HIPAA

We do not offer a Business Associate Agreement and HelixSync should not be used to store protected health information.

Data Protection Policies

We are committed to protecting your data throughout its lifecycle.

Data Ownership

  • You retain full ownership of all data you upload to HelixSync
  • We never sell, share, or use your data for advertising purposes
  • Export your data at any time in standard formats
  • Data deletion on request after account termination

Data Retention

  • Active data retained while your subscription is active
  • 30-day grace period after subscription cancellation
  • Audit logs retained for 7 years for compliance purposes
  • Configurable retention policies for enterprise customers

Incident Response

We have a comprehensive incident response plan to handle security events quickly and effectively.

Our Incident Response Process

1
Detection

Anomalies are surfaced by monitoring and by customer reports

2
Assessment

We evaluate the severity and scope of the incident

3
Containment

Immediate action to isolate and contain any potential threats

4
Notification

Affected customers are notified without undue delay

5
Recovery

Restore normal operations and verify system integrity

6
Post-Incident Review

Root cause analysis and implementation of preventive measures

Security Research Program

We value the security research community and welcome responsible disclosure of vulnerabilities.

Responsible Disclosure

We do not run a paid bug bounty programme. We do want to hear about vulnerabilities, and we are particularly interested in:

  • Authentication and authorization flaws
  • Data exposure vulnerabilities
  • Remote code execution
  • Cross-site scripting (XSS) and injection attacks

To report a vulnerability, please email security@helix-sync.com with details. We will acknowledge your report and keep you updated as we investigate.

Security Questions?

Our security team is here to help. Whether you have questions about our security practices, need compliance documentation, or want to report a concern, we are ready to assist.

For urgent security concerns, email security@helix-sync.com