// 05 FAQ

The questions
you'll get asked.

Straight answers to the questions engineering leadership, security, procurement and management are likely to ask before evaluating Helmcode.

Engineering leadership

Are we replacing our current AI provider?

No. The evaluation covers one workload. Most teams that adopt Helmcode keep their existing provider for the work that needs a frontier model and move the high-volume work where a smaller open model performs well enough. Deciding that is exactly what the POC is for.

How much engineering work is the integration?

The base URL and the API key, if your code already speaks the OpenAI-compatible API. Any compatible SDK, agent framework or editor works unchanged. The effort in a POC goes into the evaluation harness, not into the integration.

Will the quality be good enough?

Open models reached the frontier some time ago, and around 99% of what a team runs today is work they handle: classification, extraction, summarising, retrieval, code, internal assistants. For the small remainder that genuinely needs a closed frontier model, you keep using one through the same platform and the same API. Nothing forces you to choose.

What happens if the service is down?

We run the platform and the datacenters it sits in, and we monitor both continuously so that failures are caught before they reach your traffic. The commitment is contractual: 99.9% uptime on Scale and above, with priority support and penalties if we miss it. Uptime terms depend on the plan and the deployment model, so ask for the numbers of the one you are evaluating.

Security and legal

Where is our data processed?

Inside the EU, on EU-owned and EU-operated infrastructure, never routed to a US hyperscaler region. On dedicated and on-premise deployments it runs on hardware reserved for you or inside your own datacenter, which can be air-gapped.

Are prompts or outputs stored anywhere?

No. Inference is processed in memory and discarded. What is retained is API key metadata and aggregate request and token counters for billing. No prompt, completion, document or line of code is persisted, and nothing you send is used to train or fine-tune a model.

Does this make us compliant with GDPR and the AI Act?

No provider can make you compliant, and anyone who says otherwise is describing something they do not control. Conformity is assessed on your system and your use case. What the architecture does is supply technical evidence your own assessment needs: EU-only processing, zero retention, no training on your data and a traceable stack. The obligations and their dates are in the Helmcode AI Act guide.

Which certifications do you hold?

ISO 27001, ENS and SOC 2 are all in progress, and none of them is held yet. What is available today are the security reports Google has produced on the infrastructure, which we share on request. Nothing in this kit lists a certification we do not hold: one that turns out to be aspirational is the fastest way to lose a security review, and your reviewers will check.

Procurement

How does the pricing work?

A flat monthly rate per API key rather than per token, from 399 euros a month. Rate limits apply per key on requests per minute and concurrency, not on total tokens processed, so the line on the budget does not move with usage.

What do we sign, and what can we review first?

A Data Processing Agreement is available ready to sign, along with a security overview and the sub-processor list. Ask for the enterprise pack early: a review that starts in week one of a POC finishes with it, and a review that starts after it delays the decision by a month.

What is the lock-in?

The models are open weight and the API is the interface the ecosystem implements, so the model and the integration both outlive the contract. What does not move with you is the serving stack, which means a change of provider requires re-measuring latency, throughput and output quality. The portability module states this in full.

Management

Why now?

Because the cost of the evaluation is one workload and four weeks, and the cost of not having done it is discovering your per-token bill at the moment a feature succeeds. The decision this kit asks for is an experiment, not a platform commitment.

How do we know it worked?

You have one workload in production on Helmcode, its quality is at or above what you measured before, its latency is inside the target you already had, and it costs less per unit of work with a bill that does not move. If any of those does not hold, you know which one and by how much, which is also worth having.

Who at Helmcode do we deal with?

The same people who operate the platform. Helmcode is an infrastructure team before it is a sales organisation, so the answers you get during an evaluation come from the people who would run your deployment.

// enterprise

Need something for your internal review?

We can provide additional security documentation, architecture information and procurement material as your evaluation progresses.

Request the enterprise pack

Enterprise Security Pack

  • DPA
  • Security Overview
  • Subprocessor information
  • Architecture & Data Flow

// direct line

Questions about any of this?

Write to Pedro. He handles enterprise evaluations and answers the technical, security and commercial questions himself.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.