Framework · SOC 2
SOC 2 — operational controls across the platform.
SOC 2 Type II covers the operational controls Helmsway runs on the production rail — the controls a security reviewer pulls at the next assessment. This page walks the three control territories in scope, the evidence an auditor reads, and how to request the latest SOC 2 Type II report.
SOC 2 Type II audits the operational controls running the platform that pulls levers and journals them. Three control territories make up the in-scope systems: access control over every privileged path, change management on every release, and monitoring that runs 24/7 against every action. The same controls the production rail runs, with named owners, an evidence-graded sampling cadence and a quarterly auditor window — operational security isn't a slide deck behind an NDA.
Audit cadence
Annual Type II window with quarterly sampling — the same evidence ledger the auditor samples is appendix-grade per release. A named Big-Four-affiliated auditor signs each letter.
- TSC · S
Security
The Common Criteria — protects information and systems against unauthorised access, disclosure and damage. RBAC, MFA, just-in-time admin and the append-only audit ledger all journalise here.
- TSC · A
Availability
The system stays up and operational under the agreed service level. Redundancy across regions, platform-side error budgets and 24/7 monitoring on every lever commit the operational rail to the uptime promise.
- TSC · C
Confidentiality
Information marked confidential is protected through its full lifecycle. Envelope-encrypted at rest, TLS 1.2+ in transit, key rotation on the documented cadence, key custody split between security and platform teams.
- TSC · PI
Processing integrity
Levers execute inside the merchant rail and write back to the audit ledger. Every change journals the input signal, the decided action, the guardrail that approved it, and the resulting effect on the bill — so a reviewer traces any processed output back to the data and the decision against the named corridor.
- TSC · P
Privacy
Personal data is collected only via the merchant's own connector, classified at ingest, retained no longer than the named policy window, and purged on DPA exit. The GDPR-aware data layer — per-region residency, EU SCCs, contractual no-cross-replication — is the system that backs this category.
- AC
Access control
RBAC, MFA and just-in-time admin on every privileged path, with segregation of duties between who authorises and who executes. Every privileged action is journalised in the append-only audit ledger with who/what/against-which-guardrail, so a SOC 2 reviewer traces any access back to the principal against the named owner.
- CM
Change management
Versioned releases with who/what approval gates before code lands on the production rail. Lever changes move on a change ticket with peer review; the change window, the approvers and the evidence pointer per release all journalise into the audit ledger at the deploy event.
- M
Monitoring
24/7 detection and alerting on every privileged action, a weekly control-review sweep against refused-move reasons, and a monthly vendor-risk review that updates the sub-processor list. Continuous evidence-ledger entries carry who saw what and what they did — the same cadence the SOC 2 auditor samples next.
Data in scope · platform feed
What data lands on the SOC 2 boundary.
Helmsway's SOC 2 boundary covers the data the platform ingests from the merchant's connectors — orders, inventory, reviews, ad spend, shelf prices — and the audit-ledger rows those pickups produce. The boundary never crosses into merchant-side data the brand hasn't surfaced through a connector itself, and the platform's GDPR-aware data layer pins every row to the customer region. The /integrations/shopify landing walks the data-source detail end to end so a reviewer can read the connector scope in the same assessment pass.
Request our latest SOC 2 report.
The full SOC 2 Type II letter, the auditor's sampling cadence, the evidence ledger and the next audit window ship on a mutual NDA under one business day. Send a note and the security contact comes back to you directly.
Replies land with the security contact, not a sales sequence.
- ISO 27001
ISO/IEC 27001
Information security management system — Annex A controls, statement of applicability, surveillance audit trail.
- ISO 42001
ISO/IEC 42001
AI management system — AIMS controls, dataset lineage, prompt-injection guardrails, human oversight.
See it on your store
See it on your store →
Skip the questionnaire — book a Scale-tier demo and watch the helm pull a lever on your Shopify store.
SOC 2 Type II covers the operational controls Helmsway runs on the production rail — the controls a security reviewer pulls at the next assessment. This page walks the three control territories in scope, the evidence an auditor reads, and how to request the latest SOC 2 Type II report.
← Back to trust center