Type II — current attestation · Valid through Q4 2026

Framework · SOC 2

SOC 2 — operational controls across the platform.

SOC 2 Type II covers the operational controls Helmsway runs on the production rail — the controls a security reviewer pulls at the next assessment. This page walks the three control territories in scope, the evidence an auditor reads, and how to request the latest SOC 2 Type II report.

SOC 2 Type II audits the operational controls running the platform that pulls levers and journals them. Three control territories make up the in-scope systems: access control over every privileged path, change management on every release, and monitoring that runs 24/7 against every action. The same controls the production rail runs, with named owners, an evidence-graded sampling cadence and a quarterly auditor window — operational security isn't a slide deck behind an NDA.

Audit cadence

Annual Type II window with quarterly sampling — the same evidence ledger the auditor samples is appendix-grade per release. A named Big-Four-affiliated auditor signs each letter.

Data in scope · platform feed

What data lands on the SOC 2 boundary.

Helmsway's SOC 2 boundary covers the data the platform ingests from the merchant's connectors — orders, inventory, reviews, ad spend, shelf prices — and the audit-ledger rows those pickups produce. The boundary never crosses into merchant-side data the brand hasn't surfaced through a connector itself, and the platform's GDPR-aware data layer pins every row to the customer region. The /integrations/shopify landing walks the data-source detail end to end so a reviewer can read the connector scope in the same assessment pass.

Latest SOC 2 report

Request our latest SOC 2 report.

The full SOC 2 Type II letter, the auditor's sampling cadence, the evidence ledger and the next audit window ship on a mutual NDA under one business day. Send a note and the security contact comes back to you directly.

Replies land with the security contact, not a sales sequence.

See it on your store

See it on your store →

Skip the questionnaire — book a Scale-tier demo and watch the helm pull a lever on your Shopify store.

See it on your store →

SOC 2 Type II covers the operational controls Helmsway runs on the production rail — the controls a security reviewer pulls at the next assessment. This page walks the three control territories in scope, the evidence an auditor reads, and how to request the latest SOC 2 Type II report.

← Back to trust center