Helm

Security

Built to be assessed

Helm is aligned with NIST SP 800-171 Rev. 2 practices and built with the technical controls a CMMC Level 2 environment expects from an application. Helm is not itself certified: certification is an assessment of your organization. Our aim is to make sure your everyday tools are not the gap.

Multifactor authentication

Time-based one-time codes with single-use recovery codes. New workspaces require MFA for every member by default; owners can adjust the policy after enrolling.

Invitation-only onboarding

People join a workspace only through a single-use invitation link from an owner or admin. Links are bound to one email address and expire after seven days.

Audit trail

Sign-ins, privileged changes, billing, invitations, AI use, and changes to business records are written to an append-only log. Owners and admins can review and export it as CSV.

Tenant isolation

Every record is scoped to your organization on the server, and every referenced record is verified to belong to it before it is linked or changed.

Transport and browser protection

TLS 1.2 or newer, HSTS, a per-request Content Security Policy, and hardened headers on every response. There are no inbound ports on the application host.

Credentials at rest

Passwords are stored with bcrypt. Third-party integration tokens are encrypted with AES-256-GCM using keys held outside the database.

Control mapping and plan of action

Customers receive a requirement-by-requirement mapping of NIST SP 800-171 Rev. 2 that separates what the application does, what the deployment does, and what remains the operating organization's responsibility, written to attach to a System Security Plan. Known gaps are published in the same document rather than hidden.

Reporting a vulnerability

Please do not disclose suspected vulnerabilities publicly. Email [email protected] with a description, the affected feature, reproduction steps, and impact. Allow a reasonable period for investigation and remediation before public disclosure.