H
HELIX
OPERATIONS

Trust Centre

Security and assurance information for Helix Operations.

Helix is being built for client-side project assurance, contractor evidence, HSE, QA, project controls, reporting and asset operations. This page gives IT teams a clear view of current controls, roadmap items and review requirements.

Current assurance position

Security posture
Pilot-ready
External certification roadmap active
Tenant model
Multi-tenant
Organisation-scoped access
Hosting
Cloud SaaS
Region recorded per client
Enterprise path
SSO / dedicated
Available as higher-assurance option

Access

Named users, project roles, module entitlements and platform-admin boundaries.

Data

Organisation-scoped records, audit metadata and export/retention controls under development.

Infrastructure

Managed cloud hosting with client-specific region and assurance settings.

Evidence

Tenant isolation and monitoring evidence can be generated now; backup proof and penetration testing are the next major proof points.

Current controls

Authenticated access

Workspace data is behind Supabase Auth. Protected application flows verify the signed-in user before loading tenant data.

Tenant isolation

Client data is scoped by organisation membership, module entitlements, role checks and Supabase Row Level Security policies. Platform admins can generate an exportable tenant-isolation evidence run for IT review.

Role based access

Platform admins configure organisation users, module access, project visibility and role permissions from controlled admin screens.

Audit trail direction

Security-sensitive workflows such as user access, licences, module settings, reports, actions, QA, HSE and operations changes are designed to keep audit metadata.

Production monitoring

Health checks and application monitoring events are captured so support conversations can reference evidence instead of guesswork.

Temporary upload policy

Resume, import and formatter workflows are designed to avoid unnecessary retention of source files and to support delete-after-processing patterns.

HTTPS delivery

Public and authenticated Helix web traffic is served over HTTPS on the production domain.

Security roadmap to enterprise procurement readiness

1

Now

Security overview, trust page, client security FAQ, tenant-isolation evidence register, monitoring and go-live checklist.

2

Next

External penetration test, vulnerability management cadence, backup/restore evidence and scheduled uptime monitoring evidence.

3

Then

Formal privacy/DPA/MSA pack, client data retention schedule, security questionnaire responses and incident response drill.

4

Enterprise

SOC 2 readiness, ISO 27001 pathway, SSO/SAML option, dedicated environment option and client-specific security schedule.

Recommended IT review steps

  1. 1Review https://www.helixops.com.au, /trust, /security and /privacy.
  2. 2Allowlist helixops.com.au and www.helixops.com.au for browser access.
  3. 3If the firewall inspects API calls, allow the Supabase endpoint provided during onboarding.
  4. 4If the URL is flagged incorrectly, submit a false-positive/category-change request to the blocking security vendor.

Client security FAQ

Where is data hosted?

Helix uses managed cloud application and database providers. Client-specific data region and hosting region are recorded in Licensing & Security during onboarding.

How is client data separated?

Tenant data is linked to an organisation record and protected by organisation-scoped access checks. Platform-admin cross-tenant access is restricted to administration workflows.

Can Helix work beside SAP or existing systems?

Yes. The recommended pattern is read-only import first, reconciliation second, and governed write-back only once the client approves mapping and controls.

Who can access support data?

Support access should be named, limited, auditable and only used for administration, configuration or support requested by the client.

What happens when a user leaves?

Organisation admins can remove or disable access. Future enterprise hardening should include enforced periodic access reviews.

What happens after a security concern?

The operating model should follow a documented incident response process with triage, containment, client communication and breach-assessment steps.