One moment.
One moment.
Last updated: May 21, 2026
HelmXP is built for credit unions, which means it is built to be NCUA examiner-defensible. Security is a first-class requirement, not an afterthought — every architectural decision was made with isolation, auditability, and least-privilege access in mind.
For CFOs doing vendor due diligence: this article covers the security posture. For a detailed data handling FAQ or to request a security questionnaire response, contact security@helmxp.com.
| Standard | Status |
|---|---|
| SOC 2 Type 1 | Target: within 6 months of first paying customer |
| SOC 2 Type 2 | Target: within 18 months of first paying customer |
| Annual third-party penetration test | Planned at GA |
| NCUA examiner access role | Available on Growth and Enterprise plans |
SOC 2 reports are made available to customers and prospects under NDA. Contact security@helmxp.com to request a report once available.
HelmXP runs on AWS. All components are in a private VPC with no inbound public ports except the load balancer.
*.helmxp.comEvery significant action in HelmXP is written to an append-only Logbook:
Logbook entries cannot be deleted or modified. Retention is 7 years by default, matching NCUA record-keeping expectations.
HelmXP uses the Anthropic Claude API for AI drafting. Key properties:
HelmXP operates a responsible disclosure program. To report a vulnerability, email security@helmxp.com with the subject line "Vulnerability report." We respond to all reports within two business days.