Security and trust

Built for documents that need evidence, validity, owners, and review.

Helvabase makes the trust layer visible: what source supports an answer, whether the proof is still valid, what remains unresolved, and who approved the output.

Proof state before generation

Users see source freshness, parser warnings, evidence validity, missing metadata, and caveats before a draft is trusted.

Secrets stay server-side

Snipara credentials, OAuth secrets, and email credentials are configured as server-only environment variables.

Snipara remains source of truth

Helvabase stores workflow state around Snipara rather than duplicating document indexing or retrieval.

AES-256-GCM evidence encryption

Managed-proof files are encrypted at rest with AES-256-GCM, production key enforcement, authenticated downloads, and private storage paths.

Encrypted evidence backups

Evidence backups are encrypted and restore-smoked during operational verification so proof files can be recovered without exposing raw customer material.

Sealed submission snapshots

Managed-proof snapshots freeze evidence versions, hashes, artifacts, review state, blockers, and a generated PDF manifest for submission review.

No Helvabase model training

Customer documents are used to operate the requested workspace workflow, not to train Helvabase-owned models.

Deletion and retention controls

Pilot workspaces can request source removal and workspace deletion; production retention periods are handled as part of customer onboarding.

Subprocessor review

DPA, subprocessor, and data-location details are prepared for buyer review before sensitive production onboarding.