Security review FAQ

Eight answers for a vendor-risk review.

Short, source-grounded answers to the questions EPCI buyers and security reviewers ask about Helmspur's data flows, control posture, and documentation.

Last reviewed: 2026-08-26
/security/faq
Reviewer questions

The facts to have before the review.

Last reviewed: 2026-08-26

01
Vendor review
Where is app data hosted, and which region applies?

App data is hosted in the Polsia platform's EU/EEC platform-default region. Stripe payment metadata may be processed across regions according to Stripe's published list. Raw .ifc bytes are parsed in memory and are not persisted.

02
Vendor review
How many sub-processors are currently in scope?

There are two entries: Polsia platform and Stripe, Inc. via Polsia Connect. Better-auth, the email proxy, and the analytics beacon are not separate vendors in this deployment; they sit under the platform entry.

03
Vendor review
What is the breach-notification SLA?

Helmspur will notify an affected customer within one business day after Helmspur confirms a customer-impacting incident, by email to the primary customer contact on file. The incident-response page sets out the intake and limitations; the security contact also handles coordinated vulnerability disclosures, with a response within one business day.

04
Vendor review
What is the encryption posture?

The documented posture is HTTPS-only transport, a same-origin upload path, and in-memory disposal of raw IFC bytes. At-rest database encryption is a platform/hosting-tier concern; this app does not claim a separate application-level at-rest scheme.

05
Vendor review
Is Helmspur aligned with AIUC-1, or certified?

AIUC-1 is treated as a public use-case framework/readiness mapping around the single Polsia AI-proxy egress, not as a certification. No third-party AIUC-1 attestation is claimed, and no AI call site is in production today.

06
Vendor review
Where is the GDPR legal-basis mapping?

The documented roles are controller for user/auth data and processor for uploaded project content. The repo documents data flows, scoping, and purpose limitation, but it does not contain a complete Article 6 legal-basis matrix or formal Article 30, DPIA, or transfer-mechanism artifacts. Do not infer a legal basis from code; request the compliance artifact through the security intake.

07
Vendor review
Does Helmspur hold ISO certification?

Helmspur holds no ISO 27001 or ISO 42001 certificate and has no external third-party sign-off. The framework page labels the posture partial/in-scope/readiness; that describes shipped controls, not an attestation.

08
Vendor review
How do I request a live DPA?

Use the DPA request option on the security contact page or email Helmspur. The same intake covers DPA and sub-processor requests.

Not certified

Up-front disclaimer

No third-party auditor has attested to ISO 27001, ISO 42001, SOC 2, or AIUC-1 alignment.

This page describes the controls shipped in the code — not a control attestation. The names «ISO/IEC 27001», «ISO/IEC 42001», «SOC 2», «GDPR», and «AIUC-1» are used to anchor the description to the public frameworks and the regulation that buyers ask about. Helmspur does not hold an ISO certificate, a SOC 2 Type I or Type II report, an AIUC-1 attestation, or any equivalent third-party sign-off as of this writing. GDPR is a legal obligation rather than a certification regime — the GDPR section on this page describes the data-handling posture, not a certified compliance level.

If a claim below doesn't match the code in this repo, that's a bug — please flag it at contact@helmspur.com.