H
HELIX OPERATIONSTrust centreSecurity
Security controls for a private operations workspace.
Helix is designed as an authenticated SaaS workspace for operational data. Security is being treated as a product requirement: tenant isolation, role governance, auditability, retention controls and external assurance evidence.
Platform controls
HTTPS enforced for the production domain.
Authenticated access required for operational workspaces.
Supabase row-level security pattern used for organisation-scoped data access.
Platform-admin tenant-isolation evidence runs can be generated and exported for IT review.
Production monitoring records health checks and application error events.
Role and module permissions controlled by platform and organisation administrators.
Security-sensitive admin actions are designed to be auditable.
Temporary upload workflows are designed to reduce storage of sensitive source files.