Security · Last updated September 24, 2026

Security is foundational.
Not added later.

Helmsted provides data and collaboration tools for independent wealth management. This overview describes the contractual safeguards and current assurance status supporting those services.

AssuranceMonitored by Vanta
Encryption · AES-256 at rest, TLS 1.2+Live
Client data not used to train AI modelsLive
Zero retention with AI providersLive
SOC 2 Type IComplete
SOC 2 Type ICompleteSecurity and Confidentiality · Sensiba LLP
SOC 2 Type IIPlannedReports shared under confidentiality protections
Compliance programVantaContinuous monitoring of controls
Diligence requestsRequest accesssecurity@helmsted.ai · Trust Center access under NDA

How we protect
your data.

01Live
Encryption Client information is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, as required by the DPA.
02Live
Data minimization AI supports informational tools and professional workflows. Adviser and client data is not used to train AI models. Supported text-processing paths mask detected sensitive identifiers; masking is incomplete, and images may contain identifiers when processed. AI providers handle submitted information under the DPA’s protections.
03Live
Model partnerships The DPA requires verified AI-provider arrangements prohibiting model training and providing zero retention of customer inputs and outputs for the services used. Required account and service settings must be maintained. Helmsted retains its own platform records under separate retention terms.
04Live
Access control Access to client information is limited by roles and authorized relationships. Passkey login is available to RIA clients. Users must use individual credentials and required authentication. Personnel access follows applicable access-control policies.
05Live
Data isolation Access is limited to authorized records and relationships. Client-directed sharing with other professionals remains subject to the client’s authority, protected firm materials, and source restrictions.
06Live
Breach notification Helmsted maintains written incident-response and personnel-security policies. We notify affected firms as soon as possible and within the DPA’s 72-hour deadline after its covered trigger, including reasonably suspected incidents. Shorter applicable deadlines remain in effect.
07Live
Incident response Helmsted maintains written procedures to detect, assess, contain, respond to, and recover from incidents and to preserve relevant evidence.
08Live
Audit and recordkeeping Helmsted records significant platform activity and AI-processing metadata for security, troubleshooting, and oversight. Supported document workflows preserve revisions. Available records vary by workflow; retention and export follow the applicable agreement. Contract-covered audit and processing records are retained for at least five years from creation, with the first two immediately accessible. Longer periods and different legal starting events apply where required.
09Live
Subprocessors The DPA requires risk-based Subprocessor diligence and monitoring, limited access, and written protections no less protective than the DPA. Helmsted remains responsible as provided there. See the subprocessor list.
10Optional
Optional integrations Where available, calendar, meeting, and communications integrations are optional and enabled per firm. The providers involved appear on the subprocessor list. Each party handles the notices and consents required for its own recording and communications activities.
11Live
Deletion and disposal Retention, export, and deletion depend on record source, applicable agreements, valid authorizations, and law. Access is limited to authorized records and relationships. Ending one professional relationship does not automatically end other valid relationships or required recordkeeping. The DPA preserves the applicable 30-day firm return-or-delete election. Lawful preservation and source restrictions apply; de-identification does not replace required deletion. Restricted backups follow the applicable retention schedule and restore restrictions.

Where we stand
on certification.

AICPA SOC 2
SOC 2 Type IHelmsted received a clean SOC 2 Type I report from Sensiba LLP, issued September 22, 2026, covering Security and Confidentiality as of September 16, 2026. The report is available to customers and prospective customers under NDA through our Trust Center.Complete
SOC 2 Type IIA Type II examination is planned. Available assurance reports will be shared under appropriate confidentiality protections.Planned
Reg S-P17 CFR §248.30. The DPA addresses safeguards, incident response, Subprocessor oversight, and cooperation with covered firms. Each party remains responsible for its applicable duties.Contractual safeguards
Privacy rightsRequests for access, correction, export, and eligible deletion are handled under applicable law and agreements. Scope and exceptions depend on the information and service.Applicable requirements

Every subprocessor,
named and reviewed.

Risk-based diligence, limited access, and written protections no less protective than the DPA. AI providers operate under required no-training and zero-retention arrangements.View the full list
VercelApplication delivery
RenderApplication hosting
Google CloudCompute
SupabaseDatabase and auth
AnthropicAI processing
OpenAIAI processing
xAIAI processing, where enabled
TypeSafe AIAI processing
Recall.aiMeeting capture, where enabled
E2BExecution environments
CloudflareObject storage
Amazon Web ServicesFeed staging
InngestWorkflow orchestration
ResendEmail delivery
PlaidAccount connections
FirecrawlPublic-web retrieval
VercelApplication delivery
RenderApplication hosting
Google CloudCompute
SupabaseDatabase and auth
AnthropicAI processing
OpenAIAI processing
xAIAI processing, where enabled
TypeSafe AIAI processing
Recall.aiMeeting capture, where enabled
E2BExecution environments
CloudflareObject storage
Amazon Web ServicesFeed staging
InngestWorkflow orchestration
ResendEmail delivery
PlaidAccount connections
FirecrawlPublic-web retrieval

Diligence,
ready when you are.

Retain these documents with your signed Order, incorporated DPA, and Exhibit A snapshot. Public summaries do not reduce contractual duties. Contact security@helmsted.ai for diligence requests.