Trust centre
Security posture, in plain English.
Helix is built for UK fintechs. Our security model is structurally simple: raw behavioural data never leaves the device, the app runs on the Cloudflare global edge, and production data services live in AWS eu-west-1 (Ireland).
On-device processing
Behavioural signal is processed on the user's handset. Only structured risk metadata leaves the device.
UK/EEA data residency
Application served from the Cloudflare global edge. Production data services (database, auth, storage, backups) run on Supabase in AWS eu-west-1 (Ireland), covered by the UK–EU adequacy decision.
Encryption
TLS 1.3 in transit. AES-256-GCM at rest. Webhook payloads HMAC-SHA-256 signed with per-tenant secrets.
Secrets & keys
Customer SDK keys are high-entropy random tokens stored only as SHA-256 hashes; raw values are shown once and can be revoked instantly. Service secrets are held as encrypted environment secrets in our hosting platform, never in source code.
Network controls
Public API is rate-limited per key. CSP, HSTS, and a strict security-headers policy are applied to every response.
Auditability
Every privileged action is recorded in an append-only audit log scoped to the tenant. Exportable on request.
Sub-processors
We use a minimal set of UK/EU-resident sub-processors:
- Cloudflare (global edge)App hosting, CDN
- Supabase (AWS eu-west-1, Ireland)Database, auth, storage, backups
- Postmark / Resend (EU)Transactional email
- Stripe (UK)Billing
Compliance & reporting
- UK GDPR & DPA 2018 — full alignment, ROPA maintained.
- ICO — registered data controller (ZA829102).
- SOC 2 Type II — audit in progress for 2026.
- Penetration testing — annual third-party engagement, summary letter on request.