Security & Trust Center

Enterprise-Grade Security & Privacy by Design

Helm is built on battle-tested, state-of-the-art infrastructure designed to protect your financial metrics with institutional-grade encryption and privacy controls.

Read-Only IntegrationsAES-256 EncryptionSOC 2 Type II Backend

This page is maintained by Helm (PactAI) to answer common security and privacy questions about the product. Certifications noted below apply to our underlying cloud infrastructure providers (Supabase, AWS); Helm is not itself an independently certified auditor.

Architecture

Your data security architecture

Four layers of protection working in concert — from the network edge down to the database row.

Bank-Grade Encryption

All data moving to and from Helm travels through encrypted TLS 1.3 tunnels. At rest, database storage and cached metrics are protected using 256-bit AES encryption — the same standard required by major financial institutions.

Institutional Cloud Infrastructure

Helm runs on enterprise-tier PostgreSQL architecture managed by Supabase and hosted inside Amazon Web Services (AWS) data centers. Your data benefits from multi-region physical security, automatic point-in-time backups, and 24/7 biometric facility protection.

Strict Row-Level Data Isolation

We enforce PostgreSQL Row-Level Security (RLS) directly at the database layer. Your organization's metrics are mathematically isolated to your workspace — no other account, user, or organization can query or access your records.

Zero AI Model Training

Your financial metrics belong solely to you. Data ingested into Helm is never sold, shared, aggregated, or used to train public or commercial AI models.

Integrations

Read-only by guarantee, not by convention

Helm is a lens on your data — never a set of hands inside it.

100% Read-Only Sync
We never touch your books
QuickBooks Desktop • Shopify
Direct OAuth 2.0 Authentication

You log in directly through Intuit / QuickBooks and Shopify's official portals. Helm never sees or stores your bank or accounting passwords — only a short-lived, revocable access token.

Zero Write Access

Helm only requests read permissions to analyze financial reports and transactions. We cannot edit, delete, or create records in your general ledger, storefront, or bank feed.

Instant Disconnect

Revoke access at any time with a single click from inside Helm settings — or directly from your Intuit / Shopify account portal. Cached data can be purged on request.

Compliance

Compliance & industry standards

Helm inherits and operates within the following recognized frameworks. Independent certifications belong to the named providers; Helm is not itself an audit firm.

SOC 2 Type II

Our database and hosting provider (Supabase on AWS) is audited annually under SOC 2 Type II for security, availability, and confidentiality controls.

ISO/IEC 27001

Underlying AWS infrastructure is certified against ISO/IEC 27001 — the international standard for information security management systems.

GDPR-Aligned Practices

Data-subject rights (access, export, deletion) are honored on request. Cardholder data never touches Helm — payment processing is handled by Stripe, a PCI DSS Level 1 provider.

Ready when you are.

Connect your read-only integrations and start turning your operating data into decisions — with security built in from the first sync.

Start Free — No Card🔒 Learn more about our Read-Only Security Guarantee

Have a security question or need a signed DPA? Email admin@pactai.app.