For the complete documentation index, see llms.txt. This page is also available as Markdown.

Overview

Enterprise-grade security and privacy for your AI agents

Helvia.ai delivers safe and reliable AI to organizations in regulated industries. The platform is independently audited, engineered for the unique risks of conversational AI, and built for production use at scale. This page covers our certifications, how we protect customer data, and the safeguards built into the AI itself.

Our Approach to Security

Security shapes every product and operational decision at Helvia.ai. Our philosophy is grounded in a few core principles:

  • Privacy by design: Anonymization, encryption, and least-privilege access are core to how the platform is built

  • Full audit trail: Every action in the platform is logged, with role-based access and granular permissions to control who can see and do what

  • No training on customer data: Conversations, configurations, and content remain yours

  • Reliability and backups: Automated backups and disaster-recovery procedures protect against downtime and data loss

  • Responsible AI: Conversational AI introduces new categories of risk, from prompt injection to data leakage through model outputs. We invest in safeguards that anticipate these risks rather than react to them.

  • Continuous validation: Annual external audits, ongoing penetration testing, and an ISO-certified information security management system

Certifications and Compliance

Helvia.ai commits to trustworthy AI, backed by independent certifications for security, privacy and quality.

ISO/IEC 27001

Certified information security management system covering risk, controls, and continuous improvement

GDPR

Full alignment with the EU General Data Protection Regulation

ISO 9001

Certified quality management system ensuring repeatable processes and accountability across the organization

How Security Is Organized

Security at the platform is layered across data, roles, observability, and the AI itself. Use the table below to explore each area:

Area
What it covers
Read more

Data privacy and handling

Encryption at rest and in transit, anonymization, retention, and data minimization

Audit logs and access control

Event logging, role-based access and granular permissions

End-user authentication

Authenticating end users mid-conversation using OIDC

AI safety and guardrails

PII redaction, content validation guardrails, and safe integration with LLM providers

SSO and login

Workspace login options, including single sign-on (SSO) with enterprise identity providers

Observability

Full visibility into LLM input and output for every conversation step

AI Safety and Data Handling

Running an AI agent platform demands safeguards beyond those of a generic SaaS application. The platform protects sensitive information at every stage of the conversation, from user input through model invocation to response delivery.

  • Encrypted transmission: Data is encrypted in transit to and from third-party LLM providers

  • Anonymization before model invocation: Personal data and structured identifiers can be anonymized or pseudonymized before being sent to the LLM

  • Full LLM auditing: Every input sent to and output received from LLM models is logged and reviewable

  • Guardrails against malicious prompts: Build validation steps into your agent workflow to detect malicious commands and prevent unchecked user prompts from reaching the model

Frequently Asked Questions

Where is my data stored?

All our services and databases are operated within the European Union.

Is my data encrypted?

Yes. All data in transit is protected using TLS, and data at rest is encrypted using AES-256. Passwords are hashed using modern, industry-standard algorithms and are never visible to administrators.

Is Helvia.ai Agent Platform GDPR compliant?

Yes. The platform aligns with the EU General Data Protection Regulation and has an appointed Data Protection Officer overseeing compliance. For details on what data we collect and how we process it, see our privacy policy.

Does Helvia.ai use my data to train its AI models?

No. Helvia.ai does not use customer data to train its AI models. Your conversations, configurations, and content remain yours.

Do third-party LLM providers (OpenAI, Azure, Google) train on my data?

LLM integrations run on your own provider accounts and API keys, so data-use and training terms are set directly by your contract with the provider. Review your provider's data-use policy and enable any available opt-outs on your account.

Do you use sub-processors?

Yes. Helvia.ai engages a limited set of sub-processors that support platform operation, each bound by contractual obligations covering data protection and confidentiality. The current list is available on request from dpo@helvia.ai.

How long is my data retained?

Retention is configurable per workspace, with administrators able to set windows for conversations, logs, and exports.

Do you conduct regular security audits?

Yes. Helvia.ai is certified under ISO/IEC 27001:2023 and undergoes annual penetration testing by an independent external provider.

Security Resources

Data Protection Officer

For privacy, GDPR, and data subject requests, contact dpo@helvia.ai

Product and Platform Support

For everything else, see the Support page for the fastest route to our team

Service Status

Check live uptime and active incident reports at service-status.helvia.ai

Last updated