Home / Trust
Trust

How this company is controlled.

Short statements, each one checkable. Where we cannot evidence a claim, the claim is not made — including the ones that would look better if we did.

Security

Public isolation
This website is static content served from an edge network. It holds no database, runs no application code, and has no route — direct or proxied — into internal systems. Public reachability of our internal control plane is zero by construction, not by policy alone.
Credentials
No credentials, keys or tokens are present in this website, its source, or its client bundle. There is no login and no admin surface here.
Payments
Payments are handled by our processor on their infrastructure. Card data never reaches this site or our servers.
Vulnerability reporting
Email support@helmsystemsllc.io with “security” in the subject. We acknowledge receipt and will tell you what we find. We do not run a paid bounty programme.
Incident contact
The same address, marked “incident”. For an active engagement, the agreement names a direct escalation path.

AI workforce — stated honestly

HELM operates a workforce of specialised AI agents alongside human engineers. We describe this plainly rather than obscuring it, because a customer buying assurance is entitled to know what produced the work.

What they are
Software agents with defined roles, bounded authority, and no legal personality. They are not employees, officers, or representatives of the company.
What they may do
Work inside an explicit authority envelope: analyse, measure, draft, verify, and propose. Proposals are not actions.
What they may not do
Sign, spend, bind the company, accept legal terms, alter their own authority, or act outside their envelope. Technical capability is never treated as permission.
Who is accountable
A human. Every external commitment, contract and public statement is made by a person, and the company’s members are answerable for it.
Verification
Agent-produced results are verified by a different office than the one that produced them. The producer never certifies its own output.
No workforce count is published. A number that moves daily and cannot be reconciled to a canonical definition is worse than no number, so we publish none.

Data handling

What we collect here
Only what you send us: contact details, correspondence, and payment information processed by our processor. There are no advertising trackers and no marketing cookies on this site.
Customer data in an engagement
Governed by the engagement agreement, which sets what may be accessed, where it may be processed, how long it is retained, and how it is destroyed. Default is minimum necessary access.
Sensitive material
We do not require access to your secrets, credentials or production data to perform assurance. Where evidence must be captured, it is captured in sanitised form or by hash.
Retention
Engagement evidence is retained for the contractual term plus the period required for professional records; enquiry correspondence is deleted on request where no legal obligation requires retention.
Privacy detail
Privacy policy.

System status

This website is the only public system HELM Systems LLC operates. There is no public API, no customer portal and no service-level commitment at this time, and therefore no status page: a status page for a single static site would be theatre.

If you are an active engagement customer, system status for your engagement is communicated directly under your agreement.

Claims discipline

What we publish
Only statements we can trace to evidence. The proof page lists, explicitly, the things we cannot evidence and therefore do not claim.
What we never do
Publish a customer name without written authorisation, describe an internal prototype as a product, or imply a registration, certification or relationship that does not exist.
If we get something wrong
We correct it in public on the same page it appeared on. Corrections are additive: the original statement is not quietly deleted.