Helix
ProductUse casesPricingDocsAPISecurityCareersAbout
Log inStart free
Start free

Trust & Posture

Security at Helix

How we protect your code, your cloud credentials, and your users' data. Honest about what we do, honest about what we don't.

Encrypted credentials

Cloud provider tokens, API keys, and MCP credentials are stored encrypted per team using AES-256-GCM and only decrypted inside the agent runtime for the duration of a task. Keys are never logged, returned to the client, or exposed in diff output.

Sandbox isolation

Every Helix run executes inside an isolated sandbox (Daytona container or equivalent). Sandboxes are single-tenant, ephemeral, and destroyed after the task completes. Code and environment variables from one team cannot be accessed by another.

Authentication & RBAC

Sign-in is handled by Supabase Auth with email/password and OAuth (GitHub) flows. Team access is gated by role-based access control — Owner / Developer / Viewer — enforced at every API route. Promotion to Owner requires an explicit, separately authorised endpoint.

Provider isolation

Helix connects to your existing cloud accounts. We do not host your applications or data. Each MCP server invocation uses the team's own credentials and scopes, so a leak is limited to the permissions you grant.

Secret scrubbing

Agent logs, messages, and tool outputs pass through a secret-scrubbing pipeline that removes API keys, JWT-shaped strings, passwords, and private keys before storage or display. Secrets are never written to persistent sandbox storage.

Data location

The Helix control plane and audit data are hosted on infrastructure you configure. By default the dashboard uses a self-hosted Supabase instance so your conversation history, credentials, and usage data stay under your control. Helix is the control plane, not the data host.

Auditability

Every privileged action — credential write, deploy, rollback, MCP tool call, domain mutation, account deletion — produces a structured audit log entry. Rate limits are applied to sensitive endpoints to slow down credential-stuffing or enumeration.

Autonomy levels & approval gates

Helix operates at a configurable autonomy level. Read-only operations are wide; destructive or state-changing actions require explicit user approval. Enterprise plans can enforce additional approval chains, scheduled windows, and mandatory reviewer sign-off.

Usage admission control

Every Helix task passes through admission gates that enforce your plan's daily, weekly, and monthly quotas for queries, sandbox compute, provider API calls, and storage. Overages are blocked with a clear rate-limit response instead of silently running up bills.

Cron & service-role hardening

Internal cron routes (sandbox reaping, usage aggregation, background task sweeps) are gated by a shared secret validated against the request's Authorization header in constant time. Postgres functions they call are SECURITY DEFINERand granted only to service_role, so a leaked anon key cannot trigger them.

Data retention

In-app notifications are deleted after 60 days by a daily retention job. Sandbox filesystems are ephemeral and destroyed on task completion. Audit logs are retained for the lifetime of the team and can be exported on request. Account deletion is irreversible and purges all teams, projects, credentials, and conversation history.

Subprocessors

Critical subprocessors: Supabase (auth + Postgres), Cloudflare (CDN, DNS, Turnstile), GitHub (source control), Daytona(sandbox compute). Your cloud resources live in the providers you connect (AWS, Vercel, Fly, Railway, Coolify, Cloudflare, GCP, etc.) and are not subprocessed through Helix. We disclose changes to this list on the changelog before they take effect.

Compliance posture

Helix operates in compliance with the GDPR for international users and the Nigerian Data Protection Regulation (NDPR). Our control plane is self-hosted by default, giving teams direct control over data residency and access. We are working towards SOC 2 Type II attestation to support enterprise deployments.

Customers handling regulated data (financial services, health, public sector) are served best by our Enterprise plan— we run the agent control plane while your data stays on infrastructure you control, in the jurisdiction you choose.

We sign Data Processing Agreements (DPAs) on request for paid plans. Email legal@launchverse.app and we'll route a draft within two business days.

Responsible disclosure

Found a vulnerability? Email security@launchverse.app with a description, reproduction steps, and the impact you assess. We commit to:

  • Acknowledge receipt within 2 business days.
  • Provide an initial triage and severity assessment within 5 business days.
  • Coordinate a fix and public disclosure within 90 days, or sooner if a fix lands earlier.
  • Credit you in the changelog if you want public attribution.
  • Not pursue legal action against good-faith security research that respects user data and avoids service disruption.

We don't currently run a paid bounty programme. We do send Helix swag and platform credit for valid reports.

Have a security question we haven't answered? security@launchverse.app.

See also: Privacy Policy · Terms of Service · Changelog

One AI engineer for every cloud. Helix connects to your repos and providers, then writes, tests, migrates, fixes, and deploys — all from natural language.

Product

  • Helix Agent
  • Use Cases
  • Pricing
  • Security

Company

  • About Us
  • Careers
  • Contact
  • Changelog

Resources

  • Documentation
  • API Reference
  • Support
  • FAQ
  • Status

Legal

  • Terms of Service
  • Privacy Policy
  • Security
Helix

© 2026 Helix.

All systems normal