Secure intake for vulnerability disclosures, security questions, and DPA / sub-processor requests from EPCI prospects, existing partners, and security researchers.
The intake below is the same-named path that an EPCI buyer, an existing partner, or an outside researcher uses to reach Helmspur's engineering owner. Each audience gets the same timeline and the same reply path.
Send a finding or a question through this intake when it falls into one of the named intents below. Pick the closest match in the project-type field; the engineering owner reads every submission the same business day.
Before filing, see the live list of who actually handles the data — Helmspur's current sub-processor list. /security/sub-processors
How a security submission is handled
Secure intake for vulnerability disclosures, security questions, and DPA / sub-processor requests from EPCI prospects, existing partners, and security researchers.
Reader's checklist
This intake reuses the installed contact-form module. The submission lands on POST /api/contact (src/app/api/contact/route.ts), persists to the framework-owned ContactMessage table in prisma/schema/contact.prisma, and best-effort notifies the founder through the platform email proxy (src/lib/email/send.ts, src/lib/email/templates.ts). The form island itself is src/components/custom/contact-form.tsx — a module-owned client component. Admin-only viewing of inbound rows lives at /dashboard/contact-form behind better-auth requireAdmin().