// security & compliance

Know where
your data goes.

A clear view of how Helmcode processes inference data, where models run and what your security team can review before putting a workload into production.

// data flow

What happens to a request?

The data path depends on the model you choose.

// retention

What Helmcode retains

For Helmcode-operated open models. On a third-party frontier model the provider serving it decides what it retains.

Processed transiently

  • Prompt and context
  • Model routing and inference
  • Completion streamed back to the application

Stored for platform operation

  • API key metadata
  • Aggregate request and token counters

Not stored

  • Prompts
  • Completions
  • Documents
  • Source code

// deployment

Choose where your open-model workloads run.

The same Helmcode inference stack can support different infrastructure requirements.

  1. Shared EU infrastructure

    Managed by Helmcode.

    The fastest path to production for workloads that can run on shared European infrastructure.

    • EU infrastructure
    • Zero inference-content logs
    • Managed by Helmcode
  2. Dedicated

    Reserved infrastructure for your organisation or workload.

    Use dedicated compute when you require stronger isolation, predictable capacity or custom infrastructure requirements.

    • Reserved hardware
    • Network isolation
    • Custom SLA
  3. On-premise

    Run the Helmcode stack inside your own infrastructure.

    For workloads where inference must remain within your network or datacenter.

    • Customer-controlled infrastructure
    • No data movement outside your environment
    • Air-gap capable

// controls

Controls built into the platform.

These are the controls that exist today. Where your review needs something that is not on this list, ask, and you will get an answer about what exists rather than a page that implies it.

Encryption in transit
TLS 1.3 on API connections.
Scoped API keys
Keys are managed at workspace level and can be revoked from the Helmcode console.
Per-key controls
RPM and concurrency limits can be configured per API key.
Network isolation
Dedicated and on-premise environments support isolated deployments.
Zero inference-content logs
Prompts and completions for Helmcode-operated open models are processed in memory and discarded.
No training on customer data
Customer prompts, documents and source code do not enter Helmcode training datasets.

// documentation

Give your security team the evidence.

You shouldn't have to evaluate an infrastructure provider from marketing claims alone.

For enterprise evaluations, Helmcode can provide the documentation required for a deeper technical, legal and procurement review.

Request the Enterprise Security Pack
  • Data Processing Agreement

    GDPR DPA available for review.

  • Security Overview

    Architecture, controls and data-flow documentation.

  • Subprocessor information

    The parties involved in service delivery and where they operate.

  • Architecture & Data Flow

    A technical view of how requests move through the Helmcode stack.

Need a deeper review?

Data Processing AgreementSecurity OverviewSubprocessor informationArchitecture & Data Flow

Request the Enterprise Security Pack

// direct line

Questions about any of this?

Write to Pedro. He handles enterprise evaluations and answers the technical, security and commercial questions himself.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.