Skip to content

Trust Center

Compliance

This page states HelmXP's compliance posture as of 2026-05-22. Items marked as “planned” are in our roadmap; we do not claim them as current certifications.

Certification status

SOC 2 Type II

In progress

Evidence collection is underway with Schellman. The audit window covers our production environment on Azure. Report expected in Wave B1.

Auditor: Schellman

ISO 27001

Planned — Wave B2

Gap assessment is scheduled. Certification is a Wave B2 objective, dependent on SOC 2 Type II completion.

HIPAA BAA

Available under NDA

HelmXP does not process PHI in its standard configuration. A Business Associate Agreement template is available under NDA for institutions that require one for their own compliance posture.

GDPR

Posture documented

HelmXP processes data on behalf of the hub (controller). Our Data Processing Agreement governs the relationship. Data residency is currently US East; EU hosting is planned in Wave B1.

CCPA / CPRA

Posture documented

HelmXP is a service provider under CCPA. We do not sell or share personal information. The hub controls deletion and subject-access rights; we honor those within 30 days.

Questions about our compliance posture or requesting copies of reports? security@helmxp.com

Framework coverage

The table below maps HelmXP's controls to common frameworks. “Covered” means the control area is implemented in production today. “Planned” means it is on our roadmap.

FrameworkControl areaStatusNote
NIST CSF 2.0IdentifyCovered
NIST CSF 2.0ProtectCovered
NIST CSF 2.0DetectCovered
NIST CSF 2.0RespondCovered
NIST CSF 2.0RecoverPlannedDisaster recovery runbook planned Wave B1
SOC 2Security (CC)CoveredEvidence collection in progress
SOC 2Availability (A)CoveredSLA targets: 99.9 % uptime
SOC 2Confidentiality (C)Covered
SOC 2Privacy (P)CoveredMapped to GDPR + CCPA postures above
CIS Controls v8Basic hygiene (CIS 1–6)Covered
CIS Controls v8Foundational (CIS 7–16)Covered
CIS Controls v8Organizational (CIS 17–18)PlannedGovernance program planned Wave B2

Internal compliance documentation

Detailed control mapping documents, risk registers, and evidence packages are available to prospective enterprise customers under NDA. Contact security@helmxp.com to request access.