Security and data handling
What each door sends. What never leaves.
Plain answers, no badges. Helprism has no SOC 2 or ISO report yet. This page lists exactly what we receive from each door of coding-agent sync (beta), what we keep, and what the intake refuses. It is written from the code, not from a policy template.
Questions for a security review: write to us.
By door
Agent skill — helprism-sync via the MCP server (beta; Pro · Business)
Sent to Helprism: the one-line impact note, the change class and its reason; the finished article drafts and the ids of the articles they change; the paths of the files the change touched, at most 500, and the ref label a reviewer sees, such as PR #27.
Never sent: the diff (your model reads it on your machine); file contents or source code; your conversation with the agent.
GitHub App — merged PRs and pushes to the default branch (beta; Business)
Sent to Helprism: changed file paths from the GitHub API, and the repository name; the PR title, description and commit messages, fenced code stripped and diff-shaped text dropped, used only to derive the summary. Permissions asked: pull_requests:read, contents:read, issues:write, metadata:read.
Never sent: patches (the App reduces GitHub's file listings to paths inside the request); a GitHub token (Helprism stores the installation id, not a token); anything from repositories you did not grant.
CLI — @helprism/cli in GitHub Actions or any CI (beta; Business)
Sent to Helprism: file paths touched in the range, up to 500; commit messages, the newest 100 at up to 1,000 characters (a body that looks like a diff keeps only its subject); the ref, and in Actions the compare URL.
Never sent: diffs (the CLI never runs git diff or git show); file contents. --dry-run prints the whole payload so you can check before anything leaves.
What we keep
- Change events — title, ref, file paths, the derived summary, the class and impact note, and the outcome: suggested, no change, or failed.
- Suggestions — the proposed article text, its rationale, and the decision: accepted, edited, rejected with the reason, or awaiting approval.
- Verification per article — the label it was verified against and the date. Readers see only the date; the label stays inside your dashboard.
- What the intake refuses — any body with diff, patch or content keys, multi-line paths, or diff-shaped text. It answers 400 Helprism never accepts code and stores nothing.
Keys and roles
- API keys start with hp_, are generated by the workspace owner in Settings → API, and show once. Generating a new key stops the old one.
- A Pro key opens the sync tools and read access; a Business key inherits owner-level permissions. Keys work on Pro and Business only.
- 100 requests a minute per key; ask_knowledge has its own 20 a minute.
- Roles: owners approve and manage billing, admins manage content and invites, editors write. On Business, a content approval workflow keeps editors' changes in review until an owner or admin approves.
Where it runs
- Site, dashboard and help centers on Vercel; custom domains get SSL through Vercel
- Backend and data on Supabase: Edge Functions and Postgres
- Billing on Stripe Checkout and the Stripe customer portal; card details never touch Helprism
- Email through Resend. AI answers, the onboarding wizard and server-door detection call OpenAI when those features are on
- GitHub only when a workspace owner connects the App
Not yet: no SOC 2 or ISO report, no penetration-test summary to share. If your review needs a specific answer, ask and we will give it plainly. Ask a question.
Questions reviewers ask
Does Helprism see my source code?
No. The agent door sends file paths, a title, a one-line impact note and finished article prose; the CLI sends paths and commit messages; the GitHub App reads the pull request's file list, title and description and keeps paths and the title. POST /v1/changes rejects any body that carries a diff, a patch or file contents with 400 CODE_NOT_ACCEPTED, and Helprism never fetches the contents of a file from your repository.
What does the GitHub App store?
The change event: its source, a reference (the PR number or commit sha, with a link), the title, the file paths and the derived change facts, plus what it produces. GitHub's file listing carries a patch per file; it is reduced to paths inside the webhook request and never stored, returned or logged. The PR description is used only as input while the change is processed (fenced code stripped, dropped if what remains still looks like a diff) and is deleted with the queue row when processing ends. No GitHub token is stored: installation tokens are minted per request and cached in memory for at most an hour.
Does Helprism send anything to an AI provider?
For the CLI and GitHub App doors, detection runs on Helprism's server and calls OpenAI with the change facts (title, file paths, commit messages or the PR description) and the published article text it compares them with. For the agent door, judging and drafting happen inside your own coding agent, with the model you already use; Helprism's server receives only the finished report. The AI answer bot and the onboarding wizard also call OpenAI when you use them. No diff or file contents can reach any of these, because the intake rejects them first.
What can a Pro API key do?
The sync scope only: POST /v1/changes with source "agent", the suggestion routes (list, get, resolve), read-only GET /v1/articles, GET /v1/articles/:id and GET /v1/categories, the feature map (GET and POST /v1/features) and POST /v1/knowledge/ask. Every other route answers 402 with a plan message. A Business key opens all of /v1, including the CLI door and the GitHub App. Keys work on Pro and Business only.
Can the sync tools publish to my help center without a person?
No. Reports land as suggestions in the Changes inbox, and a person accepts, edits or rejects each one. With the approval workflow on, an accept by an editor or by an API key becomes awaiting approval until an owner or admin approves it. resolve_suggestion can accept from the terminal, but the skill tells the agent to do that only when you ask.
Is Helprism sync production-ready?
No, it is a beta. Expect some missed updates and the occasional false alarm. The data rules on this page hold for every door regardless, and the server enforces them, not the client.