# Helm — Hub for Every Level of Management

> Helm is one secure workspace where every level of management sees what they need: CRM and pipeline, projects and tasks, people and time off, finance, inventory and orders, docs and announcements, and an AI analyst grounded in the company's own data.

Made by Mission Success Solutions, LLC. Website: https://helmsapp.com. Support: support@missionsuccesssolutions.com.

## What it is
Business operating hub for small and mid-size companies. Helm is one secure workspace where every level of management sees what they need: CRM and pipeline, projects and tasks, people and time off, finance, inventory and orders, docs and announcements, and an AI analyst grounded in the company's own data.

## Who it is for
- Small defense subcontractors (10 to 100 people) that need everyday business tools able to stand up to a NIST SP 800-171 / CMMC Level 2 assessment
- Fractional COOs and consultancies running several client companies from one place with roles and an audit trail
- Local service businesses that have outgrown spreadsheets and a shared inbox

## Modules
- Command deck: Owner dashboard: open pipeline, receivables, spend, stock value, headcount, win rate, and a ranked needs-attention list of overdue invoices, late tasks, low stock, pending approvals, and stale deals.
- CRM and pipeline: Accounts, contacts, deals on a stage board with weighted forecast, win rate, and stale-deal alerts.
- Projects and tasks: Cross-project kanban, per-project progress, workload by person, due-this-week and overdue views.
- People: Directory with roles and departments, time-off requests and approvals, out-of-office visibility, invitations and SCIM provisioning.
- Finance: Invoices and expenses, receivables aging, six-month invoiced-versus-spent, expenses by category.
- Inventory and orders: Stock on hand, reorder alerts, movements, sales orders, stock value.
- Docs and announcements: Nested company wiki and announcements that land on every dashboard.
- AI Ops: Ask questions like 'what should I focus on today' and get answers grounded only in the workspace's live records; rate-limited and logged.
- Security settings: MFA enrollment, org-wide MFA policy, single sign-on, SCIM tokens, audit log with CSV export, API keys, integrations.

## Pricing
50,000 sats per workspace per 30 days. Unlimited members. Paid by Lightning invoice from inside the app. No card on file, no per-seat pricing. Unused days roll forward on renewal. Sign-up and a full sample-data tour are free before paying.

## Security and compliance
- Multifactor authentication (TOTP with recovery codes) required for every member by default
- Members join only by owner/admin invitation or SCIM provisioning from the customer's directory
- Enterprise single sign-on via OpenID Connect to Microsoft Entra ID, Okta, OneLogin, Ping Identity, or any OIDC provider; SCIM 2.0 served by Helm
- Adaptive step-up re-verification before sensitive actions
- Append-only audit log covering authentication, authorization changes, billing, integrations, API use, and record changes, with CSV export
- Server-side authorization on every request and tenant isolation on every record
- Per-request Content Security Policy, HSTS, and hardened headers
- Third-party OAuth tokens encrypted at rest with AES-256-GCM; webhooks from Stripe, Square, and HubSpot verified by HMAC signature
- A NIST SP 800-171 Rev. 2 control mapping covering all 14 families, written to attach to a System Security Plan

Helm is aligned with NIST SP 800-171 Rev. 2 practices and built with the technical controls a CMMC Level 2 environment expects from an application. Helm is not itself certified; CMMC certification is an assessment of the customer's organization by an authorized assessor.

## Integrations and API
Connects to Stripe, Square, HubSpot. Customers generate scoped, rate-limited API keys; the OpenAPI 3.1 document is at /api/v1/openapi.json.

## Links
- Home: https://helmsapp.com/
- About: https://helmsapp.com/about
- Help and FAQ: https://helmsapp.com/help
- Security and compliance: https://helmsapp.com/help/security
- Sign up: https://helmsapp.com/signup
- OpenAPI document: https://helmsapp.com/api/v1/openapi.json
