Home / Trust

Trust, the honest version

By the Helios team · Last checked August 2026

An RMM agent is among the most privileged software an MSP installs. Here is exactly what we do to deserve that access, and what we do not claim yet.

The honest starting point

Helios is a young company, and an RMM agent is one of the most privileged pieces of software an organisation can install. We think the right response to that is not a page of borrowed logos, it is telling you plainly what we do, what we do not do yet, and letting you judge. Helios does not yet hold its own SOC 2 or ISO 27001 certificate, and we will not imply otherwise.

What we bring instead is the thing a certificate is supposed to prove. The people who build and run Helios have spent years inside large organisations that hold both: we have personally implemented SOC 2 and ISO 27001 control environments, operated under them daily, and sat on the receiving end of the recurring external audits that keep them honest. The controls on this page are not guesses at what auditors want. They are the habits that survive audits, applied here from day one, and formal certification for Helios itself is a milestone we are working towards, not an aspiration we are deferring: Cyber Essentials is being completed this year, with ISO 27001 targeted next.

Platform security

The agent

Your data

Who else touches your data

We keep the list of sub-processors short and name every one. Data on the platform is processed only by:

That is the entire list, and we tell you before we add to it. Integrations you switch on yourself, such as Microsoft 365, Xero, QuickBooks, Datto, Dell and Lenovo, run under your own accounts and authorisation; we reach them only as you direct, never on our own.

Commercial trust

Responsible disclosure

If you believe you have found a security vulnerability in Helios, we want to hear about it directly and we will treat you as a colleague, not a threat. Email security@heliosmsp.io with enough detail to reproduce the issue. We will acknowledge your report promptly, keep you informed while we investigate, fix confirmed issues as a priority, and credit you for the find if you would like us to. We ask that you give us reasonable time to remediate before any public disclosure, and that testing avoids accessing other tenants' data. A machine-readable version of this policy lives at /.well-known/security.txt.

Reporting misuse

A tool this capable can be abused, so there is a clear way to tell us when it is, and it is open to anyone, not just our customers. If you believe Helios is being used to reach a computer without permission, yours or someone else's, report it at /report-abuse with no account needed, or email security@heliosmsp.io. It reaches a person straight away and we act on it: a confirmed bad actor is cut off and their agent is removed from the machine, not just frozen in place.

Questions we want you to ask

Ask us how tenant isolation is enforced. Ask what happens to your data when you cancel. Ask what Helio is allowed to do without a human. Email hello@heliosmsp.io and you will get a straight answer from the people who built it, because there is nobody else here to hand you to.