Security
Built with security in mind.
This page describes the security principles guiding how we build our products. We only describe controls that are actually in place — where something is still in progress, we say so plainly.
Data Security
Business data is treated as sensitive. We design our systems so that customer data is separated between accounts and is not exposed by default.
Authentication
Access to HelixNova products is designed around standard, modern authentication practices.
Authorization
Permissions are designed to be scoped, so a user can only reach the data and actions relevant to their role.
Infrastructure
We aim to run our services on reputable, well-maintained infrastructure providers and to keep dependencies up to date.
Payments
Where payment processing is used, we intend to rely on established, PCI-compliant payment providers rather than handling card data directly.
Monitoring
As our products move toward production use, we plan to add monitoring to help us detect and respond to issues quickly.
Backups
We plan to maintain regular backups of production data as our products reach general availability.
Incident Response
We are developing a process for responding to and communicating about security incidents.
Privacy
See our Privacy Policy for details on what data we collect and how it is used.
HelixNova does not claim any third-party security certifications or completed security audits. If you have a specific security question, contact us at admin@helixnova.agency.