Security
Last updated September 22, 2026
Helian is built for regulated teams. This page summarizes the controls that protect your quality records. For how responsibility is allocated, see the Terms of Service.
Hosting and encryption
Data is hosted in the United States. Connections to the service use TLS. Stored data is encrypted at rest by the hosting providers. Database and file storage include provider-managed backups.
Access controls
A user signs in with an email address and a password. Multi-factor authentication is required before a user can use the platform. A session ends after 60 minutes of inactivity. Repeated failed sign-ins lock the account.
Each organization's data is isolated, and users can only access their own organization's records. Roles and record assignments control who can create, change, approve, and sign. Only the assigned account holder can apply that record's electronic signature.
Helian access to customer data
Helian personnel access customer data only when needed to operate, secure, or support the service.
21 CFR Part 11 approach
Helian provides audit trails, electronic signatures, and access controls designed to support 21 CFR Part 11.
- Audit trails are computer-generated and time-stamped. They record who took an action, what changed, and when. When a field changes, the previous value is recorded with the new one. Users cannot edit or delete audit trail entries.
- An electronic signature shows the signer's printed name, the date and time, and the meaning of the signature, such as approval or review. It is stored with the record it applies to. Users cannot edit or delete an executed signature, or move it onto another record.
Incident notification
We will notify affected customers without undue delay after we confirm a security incident affecting their data.
AI features
Helian does not use customer content to train its models. A person must review AI output before it is used in a quality record.
Health information
Do not enter protected health information. Helian does not offer a Business Associate Agreement. Complaint Handling is a quality record for the customer's quality system, not a medical-record system.
Data Processing Agreement
Our Data Processing Agreement is available on request at support@helian.ai.
Contact
Report a security vulnerability to security@helian.ai.
Questions: support@helian.ai