Trust & Posture
Security at Helix
How we protect your code, your cloud credentials, and your users' data. Honest about what we do, honest about what we don't.
Sandbox isolation
Authentication & RBAC
Provider isolation
Secret scrubbing
Data location
Auditability
Autonomy levels & approval gates
Usage admission control
Cron & service-role hardening
Authorization header in constant time. Postgres functions they call are SECURITY DEFINERand granted only to service_role, so a leaked anon key cannot trigger them.Data retention
Subprocessors
Compliance posture
Helix operates in compliance with the GDPR for international users and the Nigerian Data Protection Regulation (NDPR). Our control plane is self-hosted by default, giving teams direct control over data residency and access. We are working towards SOC 2 Type II attestation to support enterprise deployments.
Customers handling regulated data (financial services, health, public sector) are served best by our Enterprise plan— we run the agent control plane while your data stays on infrastructure you control, in the jurisdiction you choose.
We sign Data Processing Agreements (DPAs) on request for paid plans. Email legal@launchverse.app and we'll route a draft within two business days.
Responsible disclosure
Found a vulnerability? Email security@launchverse.app with a description, reproduction steps, and the impact you assess. We commit to:
- Acknowledge receipt within 2 business days.
- Provide an initial triage and severity assessment within 5 business days.
- Coordinate a fix and public disclosure within 90 days, or sooner if a fix lands earlier.
- Credit you in the changelog if you want public attribution.
- Not pursue legal action against good-faith security research that respects user data and avoids service disruption.
We don't currently run a paid bounty programme. We do send Helix swag and platform credit for valid reports.
Have a security question we haven't answered? security@launchverse.app.
See also: Privacy Policy · Terms of Service · Changelog