Enterprise-Grade Security & Privacy by Design
Helm is built on battle-tested, state-of-the-art infrastructure designed to protect your financial metrics with institutional-grade encryption and privacy controls.
This page is maintained by Helm (PactAI) to answer common security and privacy questions about the product. Certifications noted below apply to our underlying cloud infrastructure providers (Supabase, AWS); Helm is not itself an independently certified auditor.
Your data security architecture
Four layers of protection working in concert — from the network edge down to the database row.
Bank-Grade Encryption
All data moving to and from Helm travels through encrypted TLS 1.3 tunnels. At rest, database storage and cached metrics are protected using 256-bit AES encryption — the same standard required by major financial institutions.
Institutional Cloud Infrastructure
Helm runs on enterprise-tier PostgreSQL architecture managed by Supabase and hosted inside Amazon Web Services (AWS) data centers. Your data benefits from multi-region physical security, automatic point-in-time backups, and 24/7 biometric facility protection.
Strict Row-Level Data Isolation
We enforce PostgreSQL Row-Level Security (RLS) directly at the database layer. Your organization's metrics are mathematically isolated to your workspace — no other account, user, or organization can query or access your records.
Zero AI Model Training
Your financial metrics belong solely to you. Data ingested into Helm is never sold, shared, aggregated, or used to train public or commercial AI models.
Read-only by guarantee, not by convention
Helm is a lens on your data — never a set of hands inside it.
You log in directly through Intuit / QuickBooks and Shopify's official portals. Helm never sees or stores your bank or accounting passwords — only a short-lived, revocable access token.
Helm only requests read permissions to analyze financial reports and transactions. We cannot edit, delete, or create records in your general ledger, storefront, or bank feed.
Revoke access at any time with a single click from inside Helm settings — or directly from your Intuit / Shopify account portal. Cached data can be purged on request.
Compliance & industry standards
Helm inherits and operates within the following recognized frameworks. Independent certifications belong to the named providers; Helm is not itself an audit firm.
Our database and hosting provider (Supabase on AWS) is audited annually under SOC 2 Type II for security, availability, and confidentiality controls.
Underlying AWS infrastructure is certified against ISO/IEC 27001 — the international standard for information security management systems.
Data-subject rights (access, export, deletion) are honored on request. Cardholder data never touches Helm — payment processing is handled by Stripe, a PCI DSS Level 1 provider.
Ready when you are.
Connect your read-only integrations and start turning your operating data into decisions — with security built in from the first sync.
Start Free — No Card🔒 Learn more about our Read-Only Security GuaranteeHave a security question or need a signed DPA? Email admin@pactai.app.