Proof state before generation
Users see source freshness, parser warnings, evidence validity, missing metadata, and caveats before a draft is trusted.
Security and trust
Helvabase makes the trust layer visible: what source supports an answer, whether the proof is still valid, what remains unresolved, and who approved the output.
Users see source freshness, parser warnings, evidence validity, missing metadata, and caveats before a draft is trusted.
Snipara credentials, OAuth secrets, and email credentials are configured as server-only environment variables.
Helvabase stores workflow state around Snipara rather than duplicating document indexing or retrieval.
Managed-proof files are encrypted at rest with AES-256-GCM, production key enforcement, authenticated downloads, and private storage paths.
Evidence backups are encrypted and restore-smoked during operational verification so proof files can be recovered without exposing raw customer material.
Managed-proof snapshots freeze evidence versions, hashes, artifacts, review state, blockers, and a generated PDF manifest for submission review.
Customer documents are used to operate the requested workspace workflow, not to train Helvabase-owned models.
Pilot workspaces can request source removal and workspace deletion; production retention periods are handled as part of customer onboarding.
DPA, subprocessor, and data-location details are prepared for buyer review before sensitive production onboarding.