Trust Center
Built for the scrutiny of regulated institutions
HelmXP is purpose-built for credit unions, community banks, and nonprofits. Every security control, compliance certification, and data practice is documented here for your procurement team, your examiner, and your board.
Trust Center sections
Compliance
SOC 2 Type II status, ISO 27001 progress, NCUA examination posture, and the compliance frameworks applicable to each industry pack.
Security
Encryption in transit and at rest, authentication architecture, penetration test summary, bug bounty program, and postmortem history.
Privacy
Data residency options, retention schedules, subject-access request process, GDPR and CCPA posture, and DPA and BAA templates.
Subprocessors
Every third-party service that processes customer data on HelmXP's behalf, with 30-day advance notice on changes.
SLA
99.9% uptime commitment (99.95% Enterprise), service-credit schedule, subsystem status definitions, and historical availability.
AI Transparency
Model selection rationale, prompt-isolation architecture, citation enforcement, human-in-the-loop requirements, and AI opt-out options.
Procurement inquiries
Need the CAIQ Lite, SIG Lite, or a custom security questionnaire? Contact security@helmxp.com. Responses within two business days.