Security at HelixSync
How HelixSync protects your data, what controls are in place today, and what we have not built yet. We would rather tell you plainly than badge something we cannot evidence.
Enterprise-Grade Security
We employ multiple layers of security to ensure your data remains protected at every level.
Data Encryption
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Your information is protected at every stage.
Access Control
Role-based access control. Admin, Developer and User accounts are scoped to your company, and to your department where a feature supports it. SuperAdmin is the platform operator role held by HelixSync, with access across companies. Single sign-on is not yet available.
Infrastructure Security
Hosted on secure cloud infrastructure with firewalls, intrusion detection, DDoS protection, and regular security patches.
Monitoring & Logging
API requests and authentication events are written to an audit log with the actor, endpoint, action, outcome, IP address and timestamp. HelixSync operators review it from the platform console and threat detection can alert them by email; customer-facing audit reporting is not yet available.
Data Backup
Automated daily backups with point-in-time recovery. Data is replicated across multiple availability zones for redundancy.
Network Security
Web Application Firewall (WAF), VPN access for internal systems, and network segmentation protect against external threats.
Certifications
HelixSync does not currently hold a security certification. Rather than imply otherwise, here is exactly where we stand. If a certification matters to your procurement process, tell us — it helps us prioritise.
SOC 2 Type II
Not certified, and we have not committed to a date. We have not engaged an auditor and hold no report.
ISO 27001
Not certified, and we have not committed to a date. No certification body has assessed our information security management system.
GDPR
We support data export and deletion on request, and describe our processing in the privacy policy. We do not yet publish a data processing agreement or a named sub-processor list.
HIPAA
We do not offer a Business Associate Agreement and HelixSync should not be used to store protected health information.
Data Protection Policies
We are committed to protecting your data throughout its lifecycle.
Data Ownership
- You retain full ownership of all data you upload to HelixSync
- We never sell, share, or use your data for advertising purposes
- Export your data at any time in standard formats
- Data deletion on request after account termination
Data Retention
- Active data retained while your subscription is active
- 30-day grace period after subscription cancellation
- Audit logs retained for 7 years for compliance purposes
- Configurable retention policies for enterprise customers
Incident Response
We have a comprehensive incident response plan to handle security events quickly and effectively.
Our Incident Response Process
Anomalies are surfaced by monitoring and by customer reports
We evaluate the severity and scope of the incident
Immediate action to isolate and contain any potential threats
Affected customers are notified without undue delay
Restore normal operations and verify system integrity
Root cause analysis and implementation of preventive measures
Security Research Program
We value the security research community and welcome responsible disclosure of vulnerabilities.
Responsible Disclosure
We do not run a paid bug bounty programme. We do want to hear about vulnerabilities, and we are particularly interested in:
- Authentication and authorization flaws
- Data exposure vulnerabilities
- Remote code execution
- Cross-site scripting (XSS) and injection attacks
To report a vulnerability, please email security@helix-sync.com with details. We will acknowledge your report and keep you updated as we investigate.
Security Questions?
Our security team is here to help. Whether you have questions about our security practices, need compliance documentation, or want to report a concern, we are ready to assist.
For urgent security concerns, email security@helix-sync.com