Trust Center
Compliance
This page states HelmXP's compliance posture as of 2026-05-22. Items marked as “planned” are in our roadmap; we do not claim them as current certifications.
Certification status
SOC 2 Type II
In progressEvidence collection is underway with Schellman. The audit window covers our production environment on Azure. Report expected in Wave B1.
Auditor: Schellman
ISO 27001
Planned — Wave B2Gap assessment is scheduled. Certification is a Wave B2 objective, dependent on SOC 2 Type II completion.
HIPAA BAA
Available under NDAHelmXP does not process PHI in its standard configuration. A Business Associate Agreement template is available under NDA for institutions that require one for their own compliance posture.
GDPR
Posture documentedHelmXP processes data on behalf of the hub (controller). Our Data Processing Agreement governs the relationship. Data residency is currently US East; EU hosting is planned in Wave B1.
CCPA / CPRA
Posture documentedHelmXP is a service provider under CCPA. We do not sell or share personal information. The hub controls deletion and subject-access rights; we honor those within 30 days.
Questions about our compliance posture or requesting copies of reports? security@helmxp.com
Framework coverage
The table below maps HelmXP's controls to common frameworks. “Covered” means the control area is implemented in production today. “Planned” means it is on our roadmap.
| Framework | Control area | Status | Note |
|---|---|---|---|
| NIST CSF 2.0 | Identify | Covered | |
| NIST CSF 2.0 | Protect | Covered | |
| NIST CSF 2.0 | Detect | Covered | |
| NIST CSF 2.0 | Respond | Covered | |
| NIST CSF 2.0 | Recover | Planned | Disaster recovery runbook planned Wave B1 |
| SOC 2 | Security (CC) | Covered | Evidence collection in progress |
| SOC 2 | Availability (A) | Covered | SLA targets: 99.9 % uptime |
| SOC 2 | Confidentiality (C) | Covered | |
| SOC 2 | Privacy (P) | Covered | Mapped to GDPR + CCPA postures above |
| CIS Controls v8 | Basic hygiene (CIS 1–6) | Covered | |
| CIS Controls v8 | Foundational (CIS 7–16) | Covered | |
| CIS Controls v8 | Organizational (CIS 17–18) | Planned | Governance program planned Wave B2 |
Internal compliance documentation
Detailed control mapping documents, risk registers, and evidence packages are available to prospective enterprise customers under NDA. Contact security@helmxp.com to request access.