Application security
- CSRF validation for state-changing forms
- Prepared database statements
- Rate limiting and idempotency controls
Understand what is built into HelpoSoft Cloud, what customers configure, what connected providers control and which evidence belongs in an enterprise procurement review.
Each area explains controls, responsibilities, evidence to request and claims that still depend on the live Cloud environment or connected provider.
HelpoSoft Cloud, customer administrators and connected providers each control different parts of the operating system. Procurement should assign an owner to every layer.
| Area | Control model | Review focus |
|---|---|---|
| Identity and access | Built-in + customer configured | MFA, OIDC, roles, sessions and access review |
| Data governance | Shared responsibility | Data categories, retention, exports, deletion and providers |
| Reliability | Cloud operated + contract specific | Monitoring, queues, backups, incidents and recovery evidence |
| AI governance | Customer approved + provider dependent | Knowledge, modes, handoff, provider data and quality review |
| Integration security | Shared + provider dependent | Scopes, credentials, signatures, retries and revocation |
| Procurement | Evidence required | Questionnaire, architecture, terms, service levels and acceptance |
The control catalogue is deliberately specific about feature boundaries and customer responsibility.
Open security overviewA useful review should cover service scope, architecture, data flows, providers, security measures, service levels, recovery, incidents, AI use, integrations, legal terms and exit responsibilities.
Use the security questionnaire, assign owners, test a limited workspace and record conditions before production.
Open questionnaireRequest evidenceStart with live chat and tickets. Add AI, messaging, multi-site control and service operations when your team is ready.