Trust Center
Security you can check, not just trust.
Helix connects to your website, analytics, CRM, and ad accounts, and can take action on your behalf. This page explains the controls that exist today, in plain language.
14-day trial · No credit card · Approval controls on by default
Access and authentication
Workspace access requires an authenticated account. Sessions are managed by our authentication provider, and each workspace's data is scoped to that workspace. Team members are invited explicitly; there are no anonymous sign-ups into an existing workspace.
Single sign-on and directory-based provisioning are handled as part of Enterprise onboarding — see For Enterprise or contact us for current availability on your plan.
Hosting and data in transit
Helix runs on managed cloud infrastructure. Traffic to the application and API is served over HTTPS, and data is stored in managed, access-controlled databases and object storage rather than on developer machines.
What Helix can and cannot do on your behalf
Autonomy is a setting, not a default. In Review mode, every draft, change, and campaign waits in an approval queue. In Autopilot, Helix acts only inside the guardrails you configure — budget caps, excluded pages, blocked terms, and brand rules.
Every action Helix takes is recorded with the reasoning behind it, so you can review what happened and why. Read How our AI works for the full model.
Integration scopes
Integrations are connected by you and can be disconnected by you at any time. Helix requests the narrowest useful access for each integration and separates read access (analytics, Search Console, CRM records) from write access (publishing, campaign changes). Write actions still pass your approval settings.
See Integrations for what each connection is used for.
AI processing and training
Helix uses third-party AI model providers to generate drafts, analyses, and answers. We do not sell your data, and we do not use your private workspace content to train shared public models.
Model providers process the content required to fulfill a request. Our current subprocessor list is available on request via security@helixcmo.com.
Data ownership, retention, and deletion
You own your data and the content Helix produces for you. You can export or delete your workspace data, and deletion removes it from active systems with a short backup window described in our Privacy Policy. Enterprise customers can agree custom retention.
Cookies and analytics on this website
This marketing site uses essential cookies plus Google Analytics. You can decline analytics from the banner, and the details are in our Cookie Policy.
Reporting a vulnerability
Please email security@helixcmo.com with steps to reproduce. We'll acknowledge your report and keep you updated while we investigate. We ask that you avoid accessing other customers' data and give us reasonable time to fix issues before public disclosure.
Shared responsibility
We secure the Helix platform and the credentials you entrust to it. You're responsible for who you invite to your workspace, the guardrails you set, the integrations you connect, and reviewing what Helix publishes or spends on your behalf. Your own customers' data remains governed by your agreements with them.
Need our security package for procurement?
Ask on a call and we'll walk your team through it.
14-day free trial. No credit card required.
