Last updated: July 28, 2026
Independent firms run on their clients' confidence. Helmsted is built so the systems behind your firm are as disciplined as the advice in front of it, and so you can show your work whenever anyone asks.
How we protect your data
Everything is encrypted in transit with TLS 1.2+ and at rest with AES-256, with managed key rotation across all environments.
LiveWe do not maintain Social Security numbers, tax identification numbers, or account and routing numbers as structured fields. Where an identifier is needed for display it is stored truncated to the last four digits, and third-party credentials such as Plaid tokens are held in an encrypted secrets vault rather than in application tables. When you upload a document, the text we extract from it and the AI-generated summaries derived from it are automatically scrubbed before storage: Social Security numbers, tax IDs, card numbers, and account and license numbers are masked to their last four digits. For text documents this scrubbing is applied before any content reaches a model provider; summaries generated from image uploads are scrubbed before they are stored. The original file you uploaded is kept intact as the source of record, encrypted at rest, access-logged, and deleted with the rest of your firm's data on termination.
LiveWe hold zero-data-retention (ZDR) agreements with each of our AI model providers, currently Anthropic, OpenAI, and xAI. Your prompts and documents are processed in memory, returned, and immediately discarded. Providers never store them and never use them to train models. Self-hosted models run in secure, controlled environments under equivalent protections.
LiveAccess follows least privilege, governed by role-based permissions on every workspace. Multi-factor authentication is enforced for all access to systems that store or process client financial data, individual accounts are used for individual people, and access is reviewed whenever someone joins, changes role, or leaves.
LiveEach firm's data is segregated at the database layer using row-level security, so one firm's data is never exposed to another. Documents shared with CPAs, attorneys, and other outside providers are scoped to the engagement, never firm-wide.
LiveWe notify your firm's designated compliance contact in writing without undue delay, and no later than 72 hours after becoming aware of a confirmed or reasonably suspected incident involving your data. That is the timeline amended Reg S-P requires of service providers, so your firm can meet its own 30-day customer notification obligation.
LiveWe maintain written incident response procedures covering detection, containment, investigation, remediation, and notification.
LiveEvery access to client records and shared documents is captured in append-only audit logs with actor, action, and timestamp, reviewable by your firm's administrators at any time. Logs are retained for at least five years, with the most recent two years immediately accessible, consistent with Rule 204-2 recordkeeping requirements.
LiveBefore engaging a subprocessor we review its security documentation and published attestations (SOC 2 or ISO 27001 where available) and scope its access to the minimum the service requires. Each is bound by a written agreement with data protection obligations no less protective than our DPA, including the obligation to notify us of security incidents. The full list is published in our subprocessor list, and your firm receives at least 30 days' advance written notice of material changes, with the right to object.
LiveWhen your firm leaves Helmsted, raw client data is deleted or de-identified within 30 days of termination, consistent with the disposal requirements of amended Reg S-P.
LiveWhere we stand on certification
Our controls are built to the Trust Services Criteria, and SOC 2 Type II certification is on our roadmap. We will share the report when it becomes available.
PlannedOur information security program follows ISO 27001 practices. Formal certification is on our roadmap following SOC 2.
PlannedOur safeguards, disposal, and incident response practices are built to support your firm's obligations as a covered institution, including service provider oversight and the 72-hour notification chain.
Designed to supportOur data practices are designed to meet GDPR and CCPA obligations, including data subject rights, deletion, and export.
Designed to complyDiligence documents
Retain these alongside your executed DPA in your firm's WISP vendor documentation. This page is updated as our compliance program matures; for anything else, write to security@helmsted.ai.