SECURITY

Control who can see, decide, and act.

Paid media access carries real budget and business risk. HelmMind is designed around explicit authorization, mandatory MFA, role-based permissions, visible data health, and a traceable decision record.

Control framework

Security controls that stay visible in the operating workflow.

Identity & access

Identity and access controls

  • Mandatory MFA is a default MVP control; optimizer users cannot disable it themselves.
  • Role-based access separates platform, tenant, and optimizer responsibilities.
  • Authentication and security-relevant access are recorded for investigation and support.
  • Users receive only the permissions needed for their role and assigned accounts.
Authorized data

Authorized integrations, not shared passwords

HelmMind uses provider authorization flows or approved imports. The product should never ask a user to paste an advertising-platform password into a HelmMind form.

  • OAuth scopes are shown during authorization.
  • Connection status and freshness remain visible.
  • Customers can disconnect or revoke access through the provider.
  • Tokens and secrets must not appear in screenshots, logs, exports, or support tickets.
Auditable workflow

Every recommendation leaves a decision trail

HelmMind records the recommendation, supporting context, human response, owner, timestamp, and follow-up status. An AI suggestion is not allowed to become an invisible budget action.

  • Approve, edit, reject, and defer remain distinct.
  • Original and edited recommendations stay traceable.
  • Reports preserve decision context.
  • Webhook destinations require controlled administration.
Protection

Protect data through its operating lifecycle

HelmMind separates customer workspaces and limits access to authorized users and service providers. Data-health controls surface missing, delayed, or inconsistent information before it drives a recommendation.

  • HTTPS/TLS is enforced for production traffic.
  • Backups, restore tests, monitoring, and incident procedures match published commitments.
  • Production LLM routes and subprocessors follow Privacy Policy retention and training settings.
Incident response

Investigate, contain, remediate.

We investigate suspected security events, take steps to contain and remediate confirmed incidents, preserve relevant evidence, and notify affected customers or authorities when required by law or contract.

Shared responsibility

Security is shared.

  • Use unique credentials and complete MFA enrollment.
  • Invite only authorized users and review access as roles change.
  • Grant only required platform scopes.
  • Review recommendations and execution authority before approval.
  • Do not send passwords, tokens, or sensitive data through forms or support messages.
  • Report suspicious activity promptly.
Responsible disclosure

Report a potential security issue

Email service@helmmind.ai with a clear description, affected URL or feature, reproduction steps, and supporting evidence. Do not access, modify, retain, or delete data that does not belong to you, disrupt the service, use social engineering, or publicly disclose an issue before we have investigated it.

We will acknowledge the report, assess the issue, request additional information where needed, and share remediation status when appropriate. This page does not authorize security testing or promise a bounty.

Trust begins with visibility

See how permissions, evidence, and approval live together in HelmMind.

Talk to us about your organization’s account-access and operating-control requirements.

Request Demo →