Trust, the honest version
An RMM agent is among the most privileged software an MSP installs. Here is exactly what we do to deserve that access, and what we do not claim yet.
The honest starting point
Helios is a young company, and an RMM agent is one of the most privileged pieces of software an organisation can install. We think the right response to that is not a page of borrowed logos, it is telling you plainly what we do, what we do not do yet, and letting you judge. Helios does not yet hold its own SOC 2 or ISO 27001 certificate, and we will not imply otherwise.
What we bring instead is the thing a certificate is supposed to prove. The people who build and run Helios have spent years inside large organisations that hold both: we have personally implemented SOC 2 and ISO 27001 control environments, operated under them daily, and sat on the receiving end of the recurring external audits that keep them honest. The controls on this page are not guesses at what auditors want. They are the habits that survive audits, applied here from day one, and formal certification for Helios itself is a milestone we are working towards, not an aspiration we are deferring: Cyber Essentials is being completed this year, with ISO 27001 targeted next.
Platform security
- Two-factor authentication is mandatory for every administrator account, not optional. Passkeys (WebAuthn) are supported for phishing-resistant sign-in, with TOTP as the baseline.
- Strict tenant isolation. Every query in the platform is scoped to your MSP's tenant. Your clients' data is never visible to another tenant, and platform staff cannot browse tenant data through the product.
- Encrypted credential vault. Client credentials you store are encrypted at rest with a key held outside the database, and every reveal is written to an access log you can read.
- Audit logging. Sign-ins, credential reveals and administrative actions are logged.
- Regular security review. The platform undergoes recurring internal security audits covering tenant isolation, authentication and the agent command path. Issues found are fixed before this page tells you about the process.
- Sessions you can kill. A password reset revokes every existing session for that account, on every device, and "sign out everywhere" does the same on demand. A stolen token dies the moment the account holder acts, not when it happens to expire.
- Breach notification. If we ever suffer a breach affecting your data, we tell you without undue delay and within 72 hours of confirming it, with what we know and what we are doing about it. That commitment lives in the Data Processing Agreement, not just on this page.
The agent
- Outbound only. The Helios agent connects out to the platform over HTTPS. It opens no inbound ports and needs no firewall holes.
- Signed and verified on every platform. Windows agent binaries are code-signed through Microsoft Azure Trusted Signing, with our publisher identity vetted by Microsoft. macOS agent binaries, including the remote-control component, are Developer ID signed and notarised by Apple. Linux agent releases carry a detached GPG signature you can verify against our published signing key. Agent updates are SHA-256 verified against the signed release manifest and fail closed: a tampered or corrupted update does not install.
- Visible actions. Every script run, patch install and remediation the platform performs on a device is recorded against that device where your technicians can see it.
- You control autonomy. Helio's ability to act is set per client: suggest only, act with technician approval, or act autonomously. Fixes Helio writes itself always require a technician's approval before they run.
Your data
- Hosted in EU data centres with Hetzner, a German infrastructure provider. Daily infrastructure-level backups are paired with verified nightly database backups: every archive is integrity-checked when it is written, and restores are actually tested on a schedule, because a backup nobody has restored is not a backup.
- Deliberately separated infrastructure. Each of our products runs as its own isolated stack with its own TLS edge and its own datastore, behind a routing layer that keeps them apart. A problem in one cannot reach into another.
- Encrypted in transit everywhere: browser to platform, agent to platform, platform to integrations.
- Yours to take. Your clients, devices, tickets and alerts are accessible over the Helios API, so your data is never hostage to your subscription.
- Kept only while you use it. Cancel and nothing is deleted straight away: your data stays exportable over the API through a wind-down period, then it is removed. Ask us to delete it sooner and we do.
- AI with boundaries. AI features run on Anthropic's Claude models. You can bring your own API key so AI traffic runs under your own agreement, and AI usage on platform keys is capped and metered per tenant.
Who else touches your data
We keep the list of sub-processors short and name every one. Data on the platform is processed only by:
- Hetzner (Germany): hosting and infrastructure.
- Anthropic: the Claude models behind Helio. Bring your own API key and AI runs under your own agreement instead of ours.
- Stripe: payment processing. Card details go straight to Stripe and never touch our servers.
- Brevo: delivery of transactional and notification email we send out.
- IONOS (EU): our domain and DNS, and the mailbox that receives inbound support and ticket email.
That is the entire list, and we tell you before we add to it. Integrations you switch on yourself, such as Microsoft 365, Xero, QuickBooks, Datto, Dell and Lenovo, run under your own accounts and authorisation; we reach them only as you direct, never on our own.
Commercial trust
- Monthly billing, cancel any time from your own billing page. No phone call, no notice window, no multi-year auto-renewal.
- Flat pricing, published. What you would pay is on the pricing section, not behind a sales call.
- We run an MSP on it. Helios manages our own MSP's clients every day. When something is not good enough, we feel it before you do.
- Don't take our word for anything. We're listed on G2 and SourceForge, where nobody can edit what customers say about us.
Responsible disclosure
If you believe you have found a security vulnerability in Helios, we want to hear about it directly and we will treat you as a colleague, not a threat. Email security@heliosmsp.io with enough detail to reproduce the issue. We will acknowledge your report promptly, keep you informed while we investigate, fix confirmed issues as a priority, and credit you for the find if you would like us to. We ask that you give us reasonable time to remediate before any public disclosure, and that testing avoids accessing other tenants' data. A machine-readable version of this policy lives at /.well-known/security.txt.
Reporting misuse
A tool this capable can be abused, so there is a clear way to tell us when it is, and it is open to anyone, not just our customers. If you believe Helios is being used to reach a computer without permission, yours or someone else's, report it at /report-abuse with no account needed, or email security@heliosmsp.io. It reaches a person straight away and we act on it: a confirmed bad actor is cut off and their agent is removed from the machine, not just frozen in place.
Questions we want you to ask
Ask us how tenant isolation is enforced. Ask what happens to your data when you cancel. Ask what Helio is allowed to do without a human. Email hello@heliosmsp.io and you will get a straight answer from the people who built it, because there is nobody else here to hand you to.