Information Security Policy

1. Purpose and Scope

This Information Security Policy describes the administrative, technical, and physical safeguards that HAVOK Consulting LLC, operating the HELIX brand and platform ("HELIX," "HAVOK," "we," "us," or "our"), uses to protect information processed in connection with HELIX services. It applies to HELIX personnel, systems, processes, and third-party services used to deliver the platform and related professional services.

This policy is intended to support the HELIX Master Services Agreement, HELIX Platform Terms of Service, HELIX Privacy Policy, HELIX Data Processing Addendum, and HELIX Acceptable Use Policy. If this policy conflicts with a signed agreement, the signed agreement controls. Security measures may differ by service, system, customer configuration, and third-party provider capability.

2. Security Governance

2.1 Security Program

HELIX maintains a risk-based information security program designed to preserve the confidentiality, integrity, and availability of systems and information. The program is scaled to the nature of HELIX operations and the sensitivity of the information processed.

2.2 Roles and Accountability

Security responsibilities are assigned to authorized personnel. Management is responsible for approving security priorities, allocating reasonable resources, and overseeing corrective actions. Personnel are responsible for following applicable policies and promptly reporting suspected incidents or weaknesses.

2.3 Risk Management

HELIX evaluates material security risks associated with platform operations, customer data, personnel access, integrations, and third-party providers. Risks are prioritized based on likelihood, potential impact, data sensitivity, and operational dependency.

3. Asset and Data Management

3.1 Asset Inventory

HELIX maintains reasonable awareness of material systems, applications, accounts, devices, and third-party services used to support the platform and business operations. Critical assets are identified for enhanced protection and recovery planning.

3.2 Data Classification

Information is handled according to sensitivity and business need. Customer Data, credentials, authentication secrets, security configurations, payment-related information, and nonpublic business information receive heightened protection.

3.3 Data Minimization and Retention

HELIX seeks to collect, access, and retain only information reasonably necessary to provide services, comply with law, maintain security, resolve disputes, and support business operations. Retention practices may depend on customer instructions, legal obligations, technical limitations, and third-party provider requirements.

4. Identity and Access Management

4.1 Least Privilege

Access to systems and information is limited to authorized personnel with a legitimate business need. Access permissions are designed around the principle of least privilege and may be role-based where supported.

4.2 Authentication

HELIX uses password controls and, where supported and appropriate, multi-factor authentication for administrative, production, financial, and other sensitive accounts. Shared credentials are discouraged and restricted when feasible.

4.3 Access Reviews and Termination

Access is reviewed periodically or when role changes warrant review. Access for departing personnel is removed or disabled promptly based on risk and operational feasibility. Privileged access may be subject to additional oversight.

4.4 Customer Access

Customers are responsible for managing Authorized Users, passwords, roles, permissions, connected applications, and account recovery information. Customers must promptly notify HELIX of suspected unauthorized access and must not share credentials publicly or across unrelated users.

5. Personnel Security

5.1 Confidentiality

Personnel with access to confidential information are subject to confidentiality obligations through agreements, policies, or professional duties.

5.2 Security Awareness

Personnel receive security guidance appropriate to their roles. Topics may include phishing, password hygiene, handling of confidential information, incident reporting, and safe use of third-party and AI tools.

5.3 Background and Role-Based Controls

Where appropriate and legally permitted, HELIX may conduct screening or role-based diligence for personnel in sensitive positions. Contractors and service providers are expected to follow security requirements appropriate to their access.

6. Endpoint, Network, and Infrastructure Security

6.1 Device Security

Company-managed or approved devices used to access sensitive systems should use supported software, screen-lock controls, malware protection where appropriate, and timely security updates. Lost or stolen devices must be reported promptly.

6.2 Network Protection

HELIX uses available provider and platform controls to reduce unauthorized access, including firewalls, access restrictions, secure configuration, and monitored administrative access where supported.

6.3 Secure Configuration

Systems are configured using reasonable security practices. Unnecessary services, accounts, and permissions are removed or disabled when practical. Default credentials are changed when applicable.

6.4 Segmentation and Isolation

HELIX relies in part on the logical separation, tenancy controls, and infrastructure safeguards of licensed third-party platforms. Customer environments may be logically separated through provider architecture, permissions, and account boundaries rather than dedicated physical infrastructure.

7. Encryption and Secrets Management

7.1 Encryption in Transit

HELIX uses encrypted communication protocols, such as TLS, when supported by the relevant platform or provider, to protect information transmitted over public networks.

7.2 Encryption at Rest

Customer Data and operational data may be encrypted at rest by underlying hosting, platform, storage, or service providers. Availability and implementation of encryption depend on the applicable provider and service configuration.

7.3 Credentials and Secrets

API keys, tokens, passwords, and other secrets are stored and shared using reasonable protective measures. Secrets should not be embedded in public repositories, exposed in customer-facing content, or transmitted through insecure channels when safer alternatives are available.

8. Application and Change Security

8.1 Secure Development and Configuration

Custom code, scripts, automations, integrations, and configurations are developed or implemented using reasonable care appropriate to their purpose and risk. Production changes should be tested or reviewed to the extent practical before release.

8.2 Change Management

Material changes to production systems, integrations, permissions, or security configurations are documented or otherwise controlled through approved operational processes. Emergency changes may be implemented promptly to reduce risk, followed by review when practical.

8.3 Vulnerability Management

HELIX monitors material security advisories and provider notifications relevant to its systems. Vulnerabilities are prioritized based on severity, exploitability, exposure, and business impact. Remediation timing may depend on third-party provider fixes and technical feasibility.

8.4 Testing

HELIX may conduct configuration reviews, functional tests, vulnerability checks, or other security testing. Customers may not perform penetration testing, scanning, or security research against HELIX or third-party systems without prior written authorization.

9. Logging, Monitoring, and Detection

9.1 Logging

Where supported, HELIX and its providers maintain logs or audit records for security-relevant activity, including authentication events, administrative changes, communications activity, integrations, and system errors.

9.2 Monitoring

HELIX may monitor platform activity, system health, provider alerts, account behavior, and security signals to detect misuse, fraud, unauthorized access, or operational failure. Monitoring practices are proportionate to risk and available provider capabilities.

9.3 Alerting and Escalation

Material security alerts are evaluated and escalated based on severity, affected systems, potential data impact, and business continuity concerns.

10. Incident Response

10.1 Incident Management

HELIX maintains procedures for identifying, assessing, containing, investigating, remediating, and documenting suspected security incidents. Response activities may involve internal personnel, legal counsel, insurers, customers, law enforcement, and third-party providers.

10.2 Customer Notification

Where required by law or an applicable HELIX Data Processing Addendum, HELIX will notify affected customers of confirmed incidents involving Customer Data without undue delay after obtaining sufficient information to provide meaningful notice. Initial notices may be supplemented as facts become available.

10.3 Cooperation

Customers must provide timely information and cooperation reasonably necessary to investigate incidents involving their users, credentials, integrations, devices, or configurations. Customers remain responsible for incidents caused by their own systems, users, or failure to follow security requirements.

11. Business Continuity, Backup, and Recovery

11.1 Resilience

HELIX seeks to maintain reasonable continuity of critical services through provider redundancy, account recovery processes, backups, documented procedures, and operational workarounds, as appropriate to the service.

11.2 Backups

Backup availability, frequency, retention, and restoration capabilities vary by platform and provider. Customers must maintain independent copies of information they are legally or operationally required to preserve and should use available export functions where appropriate.

11.3 Recovery

HELIX prioritizes restoration based on safety, security, customer impact, service criticality, technical dependencies, and provider availability. No specific recovery time or recovery point objective applies unless expressly stated in a separate written agreement signed by an authorized representative of HAVOK.

12. Third-Party and Subprocessor Security

12.1 Vendor Review

HELIX uses third-party services for hosting, communications, payments, AI, analytics, support, productivity, and related functions. HELIX considers the nature of the service, data involved, provider reputation, contractual protections, and available security information when selecting material vendors.

12.2 Contractual and Technical Controls

Where appropriate, HELIX uses contractual confidentiality, data protection, security, and incident-notification terms. HELIX also configures available access, authentication, and data-sharing controls to reduce unnecessary exposure.

12.3 Provider Dependency

Because HELIX is built on licensed third-party technology, security and availability depend in part on provider controls, infrastructure, updates, and response processes. HELIX does not independently control or guarantee third-party systems.

13. Artificial Intelligence Security

13.1 Approved Use

AI services may be used to generate, transform, classify, summarize, or assist with content and operations. Personnel and customers must use AI features only for authorized purposes and must avoid submitting credentials, highly sensitive data, or regulated information unless the applicable service and agreement expressly support that use.

13.2 Human Review

AI-generated output must be reviewed before material reliance, publication, or use in decisions affecting legal rights, safety, employment, credit, healthcare, or other high-impact matters.

13.3 Prompt and Output Protection

Prompts, outputs, and AI configurations may contain confidential information or HELIX Work Product and must be handled accordingly. Customers are responsible for the content they submit to AI features and for verifying output accuracy and compliance.

14. Physical Security

HELIX primarily relies on reputable cloud and software providers for physical data center security. For offices and work locations under HELIX control, reasonable measures may include controlled access, secure storage, visitor awareness, and protection of devices and records.

15. Customer Security Responsibilities

Security is a shared responsibility. Customers must:

Use strong, unique passwords and enable multi-factor authentication where available.

Limit user access and promptly remove users who no longer require access.

Keep devices, browsers, integrations, and connected systems reasonably secure and updated.

Protect API keys, phone numbers, domains, payment accounts, email services, and other connected resources.

Review workflows, automations, permissions, communications, and AI outputs before production use.

Maintain independent backups or exports where business or legal needs require them.

Notify HELIX promptly of suspected compromise, fraud, or unauthorized activity.

Comply with the HELIX Master Services Agreement, HELIX Platform Terms of Service, HELIX Acceptable Use Policy, HELIX Data Processing Addendum, and applicable law.

16. Compliance, Reviews, and Evidence

16.1 Reviews

HELIX may review this policy and related controls periodically and after material changes, incidents, or legal developments. Identified improvements are prioritized based on risk and operational feasibility.

16.2 Customer Requests

Subject to confidentiality, security, legal, and third-party restrictions, HELIX may provide reasonable information about its security practices to customers. HELIX is not required to disclose information that could compromise security, reveal another customer’s information, expose confidential provider details, or create material risk.

16.3 Audits and Certifications

Unless expressly stated in writing, HELIX does not represent that it holds any particular security certification or that the Services satisfy a customer-specific regulatory framework. Customers are responsible for determining whether the Services are suitable for their compliance requirements.

17. Exceptions and Enforcement

Exceptions to this policy require approval from authorized HELIX management and must be documented where material. Violations may result in access restriction, suspension, termination, corrective action, or other remedies available under applicable agreements and law.

18. Policy Updates

HELIX may update this policy to reflect changes in law, technology, security practices, provider requirements, or business operations. Material updates may be communicated through the platform, website, email, account notice, or other reasonable means. The current published version applies unless a signed agreement states otherwise.

19. Contact and Security Reporting

Customers and users should report suspected security incidents, vulnerabilities, or unauthorized access promptly using the support or security contact method provided in their account, agreement, invoice, or on the HELIX website. Reports should include sufficient detail to support investigation and should not include unnecessary sensitive information.

COMPANY

CUSTOMER CARE

Get Started

Copyright 2026. HAVOK Consulting LLC. All Rights Reserved.