Skip to content
HelpoSoft 3.12.2 Cumulative recovery restores the complete Cloud marketing dependency chain and protects mixed-version upgrades. Release notes
HelpoSoft
Explore HelpoSoft Cloud

Products, integrations, guidance and enterprise assurance.

Trust Center

Understand the controls, boundaries and evidence behind HelpoSoft Cloud security.

Review the HelpoSoft Cloud application-security, identity, data-protection, tenant-scope and monitoring controls that support an enterprise deployment.

Public assurance overviewCloud Security ControlsUpdated July 31, 2026
Claim boundary

Security is evaluated as a system of application controls, operating procedures, customer configuration and connected-provider safeguards—not as a collection of unsupported badges.

01

Application protection

Requests that change state use CSRF validation. Database access uses prepared statements. Public form submissions are rate limited, and integration callbacks require supported verification controls.

  • CSRF validation
  • Prepared database statements
  • Rate limiting
  • Idempotency controls
  • HTTPS-only public callbacks
02

Identity and access

Workspace administrators can apply TOTP MFA, OpenID Connect, custom roles, session limits and trusted-device revocation. Production safety still depends on correct customer configuration and periodic access review.

  • TOTP MFA
  • OIDC with PKCE
  • Least-privilege roles
  • Session revocation
  • Trusted-device review
03

Data protection

Workspace-scoped queries, protected provider secrets, hashed tokens, private attachments and retention workflows reduce unnecessary exposure. Contracted encryption and storage details must match the live Cloud environment.

  • Workspace scope
  • Encrypted provider secrets
  • Hashed API tokens
  • Private attachments
  • Retention workflows
04

Operational security

Security events, queue health, application monitoring, backup processes and incident workflows support investigation and recovery. Evidence must be reviewed against the active service agreement.

  • Security event history
  • Queue and migration health
  • Backup process
  • Incident workflow
  • Change review
Evidence checklist

Verify the live service—not only the marketing page.

The exact evidence should match the customer’s data, integrations, regions, criticality and approved Cloud agreement.

Application-security review summary
Identity and access-control configuration
Data-flow and integration inventory
Backup and recovery evidence
Incident-response ownership
Recent material security changes
Responsibility

Assign an owner to every assurance layer.

Built into HelpoSoft

Application and workspace controls that exist in the product.

Configured by the customer

Roles, users, SSO, retention, channels, AI policy and integration scopes.

Operated by HelpoSoft Cloud

Contracted application operations, releases, monitoring and recovery processes.

Dependent on providers

Email, messaging, voice, AI, CRM and billing-provider safeguards and availability.

Questions procurement asks

Keep the answer precise and evidence-backed.

Public explanations define the review framework. Contractual commitments belong in the approved service documents.

No. Certifications and audit reports should be claimed only when completed, current and applicable to the contracted service.

No. Access, retention, integrations, data sensitivity and regulatory requirements differ by organization.

Request the current service architecture, provider list, security measures, recovery evidence, incident terms and contract-specific commitments.
Enterprise evaluation pathContinue from page content to verifiable Cloud controls.
Product statusIntegration statusTrust CenterSecurity questionnaire
One customer support workspace

Bring every support conversation into one intelligent, accountable operation.

Start with live chat and tickets. Add AI, messaging, multi-site control and service operations when your team is ready.