Trust Center
Documents
Compliance questionnaires, agreement templates, and security documentation available for download. Some documents require you to identify yourself before access is granted; the details you provide are logged for audit purposes.
- CAIQ Lite (Consensus Assessment Initiative Questionnaire)Public
Pre-completed CAIQ Lite v4 documenting security controls posture against the CSA Cloud Controls Matrix. Suitable for vendor security assessments.
- SIG Lite (Standardised Information Gathering)NDA required
Pre-completed SIG Lite questionnaire covering security, privacy, and compliance domains. Suitable for prospect due-diligence review.
- Data Processing Agreement templatePublic
Standard DPA for institutions requiring a GDPR- or CCPA-compliant data processing agreement. Countersigned by HelmXP on request.
- Business Associate Agreement templateNDA required
BAA template for institutions requiring a HIPAA Business Associate Agreement. HelmXP does not process PHI by default; this BAA is available for institutions with specific compliance posture requirements.
- AI Transparency StatementPublic
What AI systems HelmXP uses, what data is sent, zero-training commitments, redaction practices, and hallucination handling — in full.
- Penetration test summary (most recent)NDA required
Executive summary of the most recent third-party penetration test — scope, methodology, finding counts by severity, and remediation status. Full report available under MSA.
- Bug bounty policyPublic
Responsible disclosure and bug bounty programme rules, scope, and reward structure.
- Security whitepaperPublic
Comprehensive technical overview of the security architecture: encryption, multi-tenant isolation, authentication, audit logging, infrastructure controls, and incident response.
Questions about any of these documents? Contact security@helmxp.com. For enterprise agreement templates or to initiate MSA countersigning, contact sales@helmxp.com.