Short, source-grounded answers to the questions EPCI buyers and security reviewers ask about Helmspur's data flows, control posture, and documentation.
Last reviewed: 2026-08-26
App data is hosted in the Polsia platform's EU/EEC platform-default region. Stripe payment metadata may be processed across regions according to Stripe's published list. Raw .ifc bytes are parsed in memory and are not persisted.
There are two entries: Polsia platform and Stripe, Inc. via Polsia Connect. Better-auth, the email proxy, and the analytics beacon are not separate vendors in this deployment; they sit under the platform entry.
Helmspur will notify an affected customer within one business day after Helmspur confirms a customer-impacting incident, by email to the primary customer contact on file. The incident-response page sets out the intake and limitations; the security contact also handles coordinated vulnerability disclosures, with a response within one business day.
The documented posture is HTTPS-only transport, a same-origin upload path, and in-memory disposal of raw IFC bytes. At-rest database encryption is a platform/hosting-tier concern; this app does not claim a separate application-level at-rest scheme.
AIUC-1 is treated as a public use-case framework/readiness mapping around the single Polsia AI-proxy egress, not as a certification. No third-party AIUC-1 attestation is claimed, and no AI call site is in production today.
The documented roles are controller for user/auth data and processor for uploaded project content. The repo documents data flows, scoping, and purpose limitation, but it does not contain a complete Article 6 legal-basis matrix or formal Article 30, DPIA, or transfer-mechanism artifacts. Do not infer a legal basis from code; request the compliance artifact through the security intake.
Helmspur holds no ISO 27001 or ISO 42001 certificate and has no external third-party sign-off. The framework page labels the posture partial/in-scope/readiness; that describes shipped controls, not an attestation.
Use the DPA request option on the security contact page or email Helmspur. The same intake covers DPA and sub-processor requests.
Up-front disclaimer
No third-party auditor has attested to ISO 27001, ISO 42001, SOC 2, or AIUC-1 alignment.
This page describes the controls shipped in the code — not a control attestation. The names «ISO/IEC 27001», «ISO/IEC 42001», «SOC 2», «GDPR», and «AIUC-1» are used to anchor the description to the public frameworks and the regulation that buyers ask about. Helmspur does not hold an ISO certificate, a SOC 2 Type I or Type II report, an AIUC-1 attestation, or any equivalent third-party sign-off as of this writing. GDPR is a legal obligation rather than a certification regime — the GDPR section on this page describes the data-handling posture, not a certified compliance level.
If a claim below doesn't match the code in this repo, that's a bug — please flag it at contact@helmspur.com.