A real archive with mobile storage shelves and organized records
Trust Center

Full compliance. Sovereign by design.

How Helios Brain protects your data, governs its intelligence and gives you control over where and how the platform runs. What the system provides and guarantees, described plainly.

A Living World Model for Decisions and Discovery.

Helios Brain is an enterprise Living World Model and intelligence platform designed to build and maintain evolving computational representations of real-world environments, organisations and problems. It combines observations, knowledge, state, relationships, constraints, uncertainty, dynamics and outcomes to help authorised users understand current conditions, explore alternative and counterfactual futures, support decisions and experiments, and continuously improve its representations from observed outcomes.

Depending on the applicable deployment and configuration, the Platform may provide decision support, discovery, simulation, forecasting, analysis, governed agentic workflows and connected-system execution capabilities.

01Observe02Understand & infer state03Frame the problem04Represent the world05Model dynamics & causality06Explore interventions & possible worlds07Verify08Act or experiment09Observe outcomes10Learn

Helios Decision

Use the World Model to understand the present state, examine interventions, run simulations and counterfactuals, compare options, support decisions and, where permitted, carry out governed execution.

Helios Discovery

Use the same World Model for observation and hidden-state inference, hypothesis generation, identification of relationships and patterns, candidate models, experimental design, evaluation of outcomes and scientific research discovery.

Helios maintains computational representations of relevant aspects of reality based on available observations, supplied information, inferred state, assumptions and models. Such representations may be incomplete, uncertain or subject to change and are updated as additional evidence and observed outcomes become available.

Built for the frameworks that govern you.

Applicability depends on your use case and implementation. Your legal, security and governance teams remain part of every assessment.

01 / Personal data & individual rights

GDPR

Lawful processing, data-subject rights, safeguards around consequential decisions and appropriate technical and organisational measures are built into the design and the Data Processing Agreement.

02 / AI governance

EU AI Act

System purpose, risk classification, documentation and human oversight are assessed per implementation. Helios acts as provider of the Helios AI system offered under its brand.

03 / Financial-sector resilience

DORA

For relevant financial-sector engagements, operational resilience, ICT risk and third-party responsibilities shape implementation and contractual requirements.

04 / Cybersecurity responsibilities

NIS2

Security controls, operating responsibilities and incident processes are configured to fit the organisation and its applicable obligations.

05 / Certified infrastructure partners

ISO 27001

Our cloud and infrastructure partners operate ISO 27001 certified information-security management. Helios's own certification program is in progress.

06 / Evidence & decision history

Accountability

Assumptions, alternatives, approvals, provenance and observed outcomes are kept available for review, so a decision can be inspected and challenged.

These frameworks describe the standards Helios is built to meet and is assessed against for your implementation. Certifications held by Helios directly are pursued on an ongoing basis and are not represented here as already granted.

Your data. Your region. Your control.

Helios can run where your requirements demand. The deployment type, hosting provider, primary data region and customer-controlled components are set per customer in the Order Schedule.

Helios Managed Cloud

A fully managed deployment operated by Helios on European cloud infrastructure, with tenant isolation and configurable data-residency boundaries.

Private Customer Cloud / BYOC

Bring your own cloud. Run Helios inside your own cloud account and network boundary so the data plane stays under your control.

Customer-controlled components

Self-hosted or customer-controlled components where specified in the Statement of Work, including customer-provided models and endpoints that have been approved technically and contractually.

Your data stays in Europe.

All Client Data is stored and processed within the European Economic Area (EEA). Core infrastructure runs in EU regions, for example Frankfurt and Ireland, and connected AI and platform services are configured for European data residency. No Client Data is stored outside the EEA. The specific region is confirmed per customer in the Order Schedule.

Access is enforced before the model, not after.

Verified controls that protect Client Data across the data path. Specific infrastructure controls may depend on the applicable deployment.

Tenant-aware access controls

Role-based and attribute-based access controls (RBAC and ABAC) govern what each authorised user can see and do.

Permission filtering before the model

Access permissions are applied before restricted information is included in the model context, where supported by the applicable data path. The access-control layer filters the context made available to the model, rather than only instructing it not to disclose.

Database-level tenant isolation

PostgreSQL Row-Level Security and tenant-scoped policies enforce isolation of Client Data at the database layer.

Authenticated sessions

Authenticated sessions with token expiry validation (JWT) protect access to the platform and its APIs.

Isolated execution environments

Agent and code workloads run inside isolated runtime environments, with workload isolation at the execution-environment and infrastructure boundary.

Provenance & output validation

Grounding, provenance and output-validation capabilities help distinguish supported answers from unsupported ones.

Logging & audit

Logging and audit capabilities record relevant activity to support review, monitoring and accountability.

Configurable policy & safety controls

Safety, policy, content-screening and governance controls are configurable per deployment, use case and sensitivity level.

NK Law is our external Data Protection Officer.

Helios Brain has appointed NK Law as its external Data Protection Officer, operating independently from its role as legal counsel. The DPO may be contacted at dpo@heliosbrain.com regarding the processing of personal data, data-protection rights and other matters within the DPO's statutory responsibilities.

Helios does not use Client Data to train, fine-tune or improve any shared, cross-customer or general-purpose foundation model.

Learning within Helios does not necessarily constitute training or fine-tuning of a foundation model. The Platform may update customer-specific state, memory, representations, parameters, relationships, rules, workflows and other isolated intelligence structures based on authorised observations and outcomes. Client Data is not used to train shared or cross-customer foundation models unless separately and expressly agreed in writing.

Categories of data subjects
  • Employees and contractors of the customer
  • Authorised users
  • Customers and end users
  • Suppliers
  • Business partners
  • Representatives and professional contacts
  • Other individuals whose information is lawfully present in the Customer Data
Categories of personal data
  • Identification and contact data
  • Professional and employment information
  • Account and access identifiers
  • Business communications and documents
  • Operational and system data
  • Transaction and business records
  • Audit and activity information
  • Other data the customer lawfully processes through the agreed service

The standard service is not deemed to accept Article 9 GDPR special-category data or Article 10 data automatically. Such processing is permitted only after specific assessment and, where required, written approval, a lawful basis, a DPIA, appropriate deployment architecture, appropriate subprocessors and additional technical and organisational measures. This matters in particular for healthcare, biometrics and other regulated use cases.

The DPO is engaged, where required, in

Data Protection Impact Assessments (DPIAs)

New high-risk use cases

Processing of special-category data

Material changes to privacy architecture

New subprocessors with material privacy impact

International data transfers

Significant changes to retention

Privacy and security incidents

Data-subject requests

Profiling and surveillance use cases

New deployments that materially increase privacy risk

A short, living Subprocessor Schedule.

A small set of core subprocessors runs the standard European deployment. Everything else is grouped by function and activated only when a specific feature is enabled.

ProviderServiceData processedRegion
Amazon Web ServicesHosting, containers, storage, networkingClient Data, files, logs, application dataEU (EEA) region
SupabaseManaged PostgreSQL, persistence, storageClient Data, state, metadata, application recordsEU (EEA) region
AnthropicLarge-language-model inferencePrompt, context and output for routed requestsEU data residency
OpenAILLM and multimodal inferencePrompt, context and output for routed requestsEU data residency
PineconeVector database and semantic retrievalEmbeddings, metadata, vector queriesEU (EEA) region
LangfuseLLM observability and tracingPrompts, outputs, traces, technical metadataEU Cloud (Ireland)
DaytonaAgent execution and sandboxesFiles, generated code, task and workspace dataEU region

Additional services, activated only when a feature is enabled

AI model inference

A specific model is selected for the deployment

Safety & content screening

Guardrails and screening are enabled

Web search & retrieval

Web research is invoked

Enterprise system connectors

An integration is enabled (EU tenant where used)

Voice

Voice functionality is enabled

Document processing

Document parsing or transformation is enabled

Specific providers within each category are activated only for the relevant deployment, run under EU data residency where the provider supports it, and the full list is available on request under NDA. Stripe is used for billing as a payment provider and does not receive the operational Client Data of the World Model. Software components used inside the platform (for example solvers, graph and inference libraries, and self-hosted services) are not subprocessors, as no Client Data is sent to a third party through them.

Intelligence that stays governed.

Autonomy levels are configured per use case. Helios prepares and proposes; consequential actions follow the approvals and controls you define.

Human oversight

Helios can analyse, propose, simulate and prepare actions. Actions with significant legal, financial, human or operational impact are subject to the required approvals and customer-configured governance. Legitimate low-risk automated workflows do not each require human approval.

Action lifecycle

We distinguish between a recommendation, a proposed action, a simulated action, an approved action and an executed action. Human approval, policy controls and verification mechanisms apply according to the configured use case.

Simulation is not fact

Simulated, inferred or synthetic data and outputs are distinguishable from observed data where material. Simulation outputs support scenario analysis, discovery and decision exploration and do not constitute observed facts or guarantees of future outcomes.

Configurable safety

The Platform provides configurable safety, policy, content-screening and governance controls. Applicable controls, detection categories, sensitivity levels and enforcement actions may vary by deployment. No automated detection mechanism guarantees identification or prevention of all prohibited or harmful activity.

Prohibited use

Autonomous lethal targeting or weapon engagement

Unlawful weapons applications

Malicious cyber intrusion or exploitation

Unlawful mass surveillance or social scoring

Unlawful biometric identification

Fraudulent impersonation or deceptive synthetic media

Unlawful re-identification

Fully autonomous high-impact decisions where the law requires meaningful human oversight or other safeguards

Legitimate non-lethal use cases such as logistics, cybersecurity, resilience, planning, simulation and resource allocation are assessed separately.

What are you trying to achieve?

Bring the objective. Bring the constraints. Let’s explore the path together.

You define the outcome. Helios finds the path.