Security Practices

Last Updated:

These Security Practices describe the administrative, physical, and technical safeguards HelmDocs maintains to protect the confidentiality, integrity, and availability of your content and data within our platform.

1. Information Security Program

1.1 Written Program. HelmDocs maintains a comprehensive information security program consisting of policies, standards, and procedures that govern how Customer Content is processed, stored, and protected across our infrastructure.

1.2 Shared Responsibility. Security is a shared responsibility. HelmDocs is responsible for the security of the platform itself — including infrastructure, access controls, and incident response. Customers are responsible for how they configure their workspaces, manage user access, and handle content within HelmDocs.

1.3 Confidentiality of Personnel. All HelmDocs personnel with access to Customer Content are bound by confidentiality obligations and receive appropriate training on data handling and security.

2. Technical and Organizational Controls

HelmDocs implements commercially reasonable controls designed to protect Customer Content from unauthorized access, loss, alteration, and disclosure.

2.1 Patch Management. HelmDocs maintains processes to keep its systems up to date with current security patches, updates, and software versions on a regular cadence.

2.2 Network Security. HelmDocs uses firewalls and network segmentation to protect Customer Content and internal systems from unauthorized access.

2.3 Anti-Malware. HelmDocs deploys up-to-date anti-malware tools on its systems, configured for automatic updates, to detect and mitigate threats.

2.4 Security Testing. HelmDocs regularly tests its security systems, processes, and controls to validate their effectiveness.

2.5 Access Controls. HelmDocs maintains an access control policy governing internal access to Customer Content, which includes:

  • Unique identifiers assigned to all personnel with system access

  • Access restricted to personnel with a documented business need

  • Regular access reviews to remove stale or unnecessary privileges

  • Mandatory use of strong passwords and multi-factor authentication for internal systems

  • Prohibition on sharing credentials among personnel

2.6 Acceptable Use Policies. HelmDocs enforces internal acceptable use and confidentiality policies for all personnel, including mechanisms to detect and log violations.

2.7 Environment Separation. Development and testing environments are kept separate from production systems that contain Customer Content.

2.8 Secure Disposal. HelmDocs follows industry-standard procedures (consistent with NIST SP 800-88 or equivalent) for the secure deletion or destruction of storage media containing Customer Content prior to disposal.

2.9 Remote Access. Access to HelmDocs private infrastructure by personnel requires encrypted VPN connections with multi-factor authentication.

2.10 Encryption. HelmDocs encrypts Customer Content both in transit and at rest using industry-standard encryption methods consistent with NIST or CIS recommendations. All connections to the Service that involve the transfer of Customer Content are encrypted.

3. Third-Party Infrastructure and Vendors

3.1 Vendor Security Standards. Third-party vendors engaged by HelmDocs to support the delivery of the Service are required to maintain security standards substantially equivalent to those described in these Security Practices.

3.2 Cloud Infrastructure. HelmDocs hosts Customer Content on cloud infrastructure (currently Google Cloud) that meets or exceeds ISO 27001 or equivalent certification standards. HelmDocs' cloud providers maintain:

  • Physical security controls and access restrictions at data center facilities

  • Professional environmental controls (HVAC, fire suppression, cabling)

  • Independent annual audits and risk assessments

  • Highly available, redundant infrastructure designed to minimize service disruption

4. Business Continuity and Disaster Recovery

HelmDocs maintains a disaster recovery program covering the recovery of the Service following a significant incident. The program includes:

  • Regular backup procedures for Customer Content, with periodic validation of restoration processes

  • Maintained inventories of critical systems, reviewed at least annually

  • Annual review, testing, and updating of disaster recovery procedures

5. Security Incidents

5.1 Notification. In the event of a confirmed Security Breach affecting Customer Content, HelmDocs will notify the affected Customer in writing without undue delay. Notification will be sent to the billing email address on file. Customers are responsible for keeping their contact information current.

5.2 Response. HelmDocs will investigate and, as appropriate, mitigate or remediate any confirmed Security Breach in accordance with its internal incident response procedures. HelmDocs will share available information with the affected Customer — including the nature of the incident, what data was involved (if known), and remediation steps taken — to assist the Customer in meeting its own legal obligations.

5.3 Additional Assistance. If Customer requires information beyond what HelmDocs provides through its standard incident response process, Customer may submit a written request to its HelmDocs account contact. Such requests will be addressed at Customer's expense.

5.4 Unsuccessful Attempts. Unsuccessful attacks (such as port scans, failed login attempts, or denial-of-service attempts that do not result in unauthorized access) are not Security Breaches and are not subject to breach notification.

5.5 Customer-Caused Incidents. Unauthorized access resulting from a Customer's misconfiguration, compromised user credentials, or the Customer's own disclosure of content does not constitute a HelmDocs Security Breach.

5.6 No Admission. HelmDocs' notification of a Security Breach does not constitute an admission of fault or liability.

6. Audits and Compliance Reporting

6.1 Ongoing Monitoring. HelmDocs conducts internal audits, risk assessments, and monitoring activities on an ongoing basis to evaluate the effectiveness of its security controls.

6.2 SOC 2 Audit. HelmDocs engages independent third-party auditors to perform annual SOC 2 (Type II) assessments of its security controls. Audit reports are treated as HelmDocs Confidential Information and are available to Customers upon written request, subject to applicable confidentiality obligations, no more than once per year.

6.3 Penetration Testing. HelmDocs conducts annual third-party penetration testing of the Service and maintains a continuous vulnerability disclosure program. Penetration test reports are available to Customers upon written request under the same terms as Audit Reports.

6.4 Customer Compliance Requests. If a Customer requires additional security information to meet its own compliance or regulatory obligations, and that information is not available through the above reports, Customer may submit a written request to its HelmDocs account representative describing the specific requirement. HelmDocs will work with Customer in good faith to address such requests. Additional requests of this nature are limited to once per year unless required by law.

7. Definitions

  • "Customer" means the organization or individual that has entered into an Agreement with HelmDocs to access and use the Service.

  • "Customer Content" means any documents, data, files, or other content submitted to the Service by Customer or its Users.

  • "HelmDocs Information Systems" means the systems, networks, and infrastructure used by HelmDocs to provide the Service and process Customer Content.

  • "HelmDocs Personnel" means any employee, contractor, or other individual authorized by HelmDocs to access Customer Content in the course of providing the Service.

  • "Process" means any operation performed on Customer Content, including collection, storage, retrieval, use, or transmission.

  • "Security Breach" means a confirmed unauthorized access to, or accidental or unlawful destruction, loss, or alteration of, Customer Content.

  • "Service" means the HelmDocs SaaS platform and any associated features, tools, or applications made available by HelmDocs under an Agreement.

  • "User" means any individual authorized by Customer to access and use the Service on Customer's behalf.