Skip to content
HelpoSoft 3.12.2 Cumulative recovery restores the complete Cloud marketing dependency chain and protects mixed-version upgrades. Release notes
HelpoSoft
Explore HelpoSoft Cloud

Products, integrations, guidance and enterprise assurance.

HelpoSoft Cloud Trust Center

Review security, privacy, reliability, AI and integration assurance in one place.

Understand what is built into HelpoSoft Cloud, what customers configure, what connected providers control and which evidence belongs in an enterprise procurement review.

This Trust Center does not claim certifications, uptime targets or recovery objectives that have not been independently completed and approved for the contracted service.
Security controls
Privacy and data
Reliability
AI governance
Responsibility matrix

Trust depends on more than the application.

HelpoSoft Cloud, customer administrators and connected providers each control different parts of the operating system. Procurement should assign an owner to every layer.

Built-in or operatedCustomer configuredProvider dependentEvidence required
AreaControl modelReview focus
Identity and accessBuilt-in + customer configuredMFA, OIDC, roles, sessions and access review
Data governanceShared responsibilityData categories, retention, exports, deletion and providers
ReliabilityCloud operated + contract specificMonitoring, queues, backups, incidents and recovery evidence
AI governanceCustomer approved + provider dependentKnowledge, modes, handoff, provider data and quality review
Integration securityShared + provider dependentScopes, credentials, signatures, retries and revocation
ProcurementEvidence requiredQuestionnaire, architecture, terms, service levels and acceptance
Core Cloud controls

Start with the product controls, then verify the operating evidence.

The control catalogue is deliberately specific about feature boundaries and customer responsibility.

Open security overview

Application security

  • CSRF validation for state-changing forms
  • Prepared database statements
  • Rate limiting and idempotency controls

Identity and access

  • TOTP MFA and recovery codes
  • OpenID Connect with PKCE
  • Custom roles and least-privilege permissions

Data protection

  • Workspace-scoped application access
  • Protected provider secrets and hashed tokens
  • Private attachments and signed delivery

Tenant and site scope

  • Workspace ownership checks
  • Visible site-level operational scope
  • Separate client workspaces where isolation is required

AI governance

  • Approved knowledge sources
  • Draft, assisted and automatic modes
  • Provider and budget controls

Cloud operations

  • Managed application releases
  • Monitoring and queue-health review
  • Backup and recovery process

Integration security

  • Dedicated identities and minimum scopes
  • Webhook signature or token validation
  • Idempotency and bounded retries

Assurance boundaries

  • No unsupported certification claims
  • Customer configuration remains in scope
  • Provider dependencies are documented
Procurement package

Request evidence that matches your actual deployment.

A useful review should cover service scope, architecture, data flows, providers, security measures, service levels, recovery, incidents, AI use, integrations, legal terms and exit responsibilities.

Service architecture and scopeSecurity and privacy measuresProvider and integration inventoryBackup and recovery evidenceIncident and support processApproved Cloud order and DPA
Enterprise evaluation pathContinue from page content to verifiable Cloud controls.
Product statusIntegration statusTrust CenterSecurity questionnaire
One customer support workspace

Bring every support conversation into one intelligent, accountable operation.

Start with live chat and tickets. Add AI, messaging, multi-site control and service operations when your team is ready.