Access
Named users, project roles, module entitlements and platform-admin boundaries.
Trust Centre
Helix is being built for client-side project assurance, contractor evidence, HSE, QA, project controls, reporting and asset operations. This page gives IT teams a clear view of current controls, roadmap items and review requirements.
Named users, project roles, module entitlements and platform-admin boundaries.
Organisation-scoped records, audit metadata and export/retention controls under development.
Managed cloud hosting with client-specific region and assurance settings.
Tenant isolation and monitoring evidence can be generated now; backup proof and penetration testing are the next major proof points.
Workspace data is behind Supabase Auth. Protected application flows verify the signed-in user before loading tenant data.
Client data is scoped by organisation membership, module entitlements, role checks and Supabase Row Level Security policies. Platform admins can generate an exportable tenant-isolation evidence run for IT review.
Platform admins configure organisation users, module access, project visibility and role permissions from controlled admin screens.
Security-sensitive workflows such as user access, licences, module settings, reports, actions, QA, HSE and operations changes are designed to keep audit metadata.
Health checks and application monitoring events are captured so support conversations can reference evidence instead of guesswork.
Resume, import and formatter workflows are designed to avoid unnecessary retention of source files and to support delete-after-processing patterns.
Public and authenticated Helix web traffic is served over HTTPS on the production domain.
Security overview, trust page, client security FAQ, tenant-isolation evidence register, monitoring and go-live checklist.
External penetration test, vulnerability management cadence, backup/restore evidence and scheduled uptime monitoring evidence.
Formal privacy/DPA/MSA pack, client data retention schedule, security questionnaire responses and incident response drill.
SOC 2 readiness, ISO 27001 pathway, SSO/SAML option, dedicated environment option and client-specific security schedule.
Helix uses managed cloud application and database providers. Client-specific data region and hosting region are recorded in Licensing & Security during onboarding.
Tenant data is linked to an organisation record and protected by organisation-scoped access checks. Platform-admin cross-tenant access is restricted to administration workflows.
Yes. The recommended pattern is read-only import first, reconciliation second, and governed write-back only once the client approves mapping and controls.
Support access should be named, limited, auditable and only used for administration, configuration or support requested by the client.
Organisation admins can remove or disable access. Future enterprise hardening should include enforced periodic access reviews.
The operating model should follow a documented incident response process with triage, containment, client communication and breach-assessment steps.