Trust center
The procurement-grade detail behind the security posture.
The one-pager on /security tells procurement Helmsway ships SOC 2 / ISO 27001 / ISO 42001 controls on day one. This page is the deeper artifact — control families, audit cadence, data handling and residency, sub-processors, vulnerability disclosure, and the SOC 2 packet on request — so a security reviewer can close the assessment without leaving the site.
- SOC 2 Type II
- ISO 27001
- ISO 42001
- GDPR-aware
SOC 2, ISO 27001, ISO 42001 are not three audits beside each other — they are Helmsway's single AI-system governance story, told from the angle a security reviewer recognises. SOC 2 audits the operational controls on the platform; ISO 27001 audits the information security management system behind them; ISO 42001 audits the AI management system that governs the models which pull the levers. The three cards below split that story into the three frames a security questionnaire reaches for.
- SOC 2
SOC 2 — Type II
Operational controls across the platform — the Trust Services Criteria a security reviewer looks for in the SOC 2 letter.
- ISO 27001
ISO/IEC 27001
Information security management system — Annex A controls, statement of applicability, surveillance audit trail.
- ISO 42001
ISO/IEC 42001
AI management system — the AIMS controls that govern every model that pulls a lever.
Request our latest report.
The full packet — SOC 2 Type II letter, ISO 27001 statement of applicability, ISO 42001 AI risk register, GDPR DPA + sub-processor list, data-flow diagram — ships on a mutual NDA under one business day. Send a note and the security contact comes back to you directly.
Replies land with the security contact, not a sales sequence.