Security contact

Security contact

Secure intake for vulnerability disclosures, security questions, and DPA / sub-processor requests from EPCI prospects, existing partners, and security researchers.

Who this page is for

Who this page is for

The intake below is the same-named path that an EPCI buyer, an existing partner, or an outside researcher uses to reach Helmspur's engineering owner. Each audience gets the same timeline and the same reply path.

  • Prospects — EPCI prospects evaluating Helmspur on a live project and needing a security review as part of procurement.
  • Partners — Existing partners and suppliers who need to flag a finding against the live system or request a walkthrough of a specific control.
  • Researchers — Outside researchers running a coordinated vulnerability disclosure against the hosted service.
  • Auditors — Auditors and assessors mapping a control question back to the file path that backs it in this repo.
When to use this page

When to use this page

Send a finding or a question through this intake when it falls into one of the named intents below. Pick the closest match in the project-type field; the engineering owner reads every submission the same business day.

  • Q
    Security question — a control walkthrough, a transport / framing / CSP question, or a clause in this page that does not line up with the code.
  • CVD
    Coordinated vulnerability disclosure — a private report against the hosted service. The engineering owner replies with a confirmation and a tracking channel within one business day.
  • DPA
    DPA request — a Data Processing Addendum, a sub-processor list pull, or a transfer-mechanism question for the engineering-tooling trust boundary.
  • S/P
    Sub-processor list request — the categories of sub-processors in scope and the data each category receives. Same reply path as a DPA request.
  • GEN
    General security inquiry — anything in the trust story that a reviewer wants clarified before procurement.

Before filing, see the live list of who actually handles the data — Helmspur's current sub-processor list. /security/sub-processors

Helmspur

How a security submission is handled

How a security submission is handled

  • Inbox. The submission lands in a priority-leaning inbox on the same address — the engineering owner who ships the trust story and the framework scoreboard.
  • Reply. Replies go out by hand, not by auto-ack — so the first response a sender sees is a substantive reply, not a ticket number.
  • Tracking. There is no public tracker token handed back. The submission is acknowledged by reply and progresses by the same reply channel.
  • Logging. The submission is logged once in the same Helmspur inbox as the sales brief and the public contact form — together with the submitting address, the company, the project type, and the message body.
Helmspur

Security intake

Secure intake for vulnerability disclosures, security questions, and DPA / sub-processor requests from EPCI prospects, existing partners, and security researchers.

Reader's checklist

This intake reuses the installed contact-form module. The submission lands on POST /api/contact (src/app/api/contact/route.ts), persists to the framework-owned ContactMessage table in prisma/schema/contact.prisma, and best-effort notifies the founder through the platform email proxy (src/lib/email/send.ts, src/lib/email/templates.ts). The form island itself is src/components/custom/contact-form.tsx — a module-owned client component. Admin-only viewing of inbound rows lives at /dashboard/contact-form behind better-auth requireAdmin().