Security & compliance
A plain-language look at how Helmdesk keeps one tenant's data separate from another's, and how we protect data in transit.
Tenant isolation, enforced by the database
Every tenant-scoped table has row-level security policies that check the requesting connection’s tenant before returning or writing a single row. This runs inside Postgres itself, not just in application code — a bug in a controller can’t leak another organization’s tickets, because the database refuses the query at a lower layer than the application.
Encrypted in transit
All traffic to Helmdesk — the dashboard, the client portal, custom domains, and the API — is served over TLS, including automatically-issued and renewed certificates for tenant custom domains.
Least-privilege database access
The running application connects to Postgres as a dedicated, non-superuser role that can only do what the app needs to do. Schema migrations run under a separate, more privileged role used only for that one-off task — the two are never the same connection.
Rate limiting on public endpoints
Login, the contact form, and other unauthenticated endpoints are rate-limited per IP address to slow down credential-stuffing and abuse, enforced consistently across every server instance.
Backups
Automated, scheduled backups are on our infrastructure roadmap and not yet fully in place. If this matters to your evaluation right now, ask us directly — we'd rather tell you the honest current state than let a generic trust page imply more than what's actually running today.
Data at rest
Your data lives on our hosting provider's infrastructure. We haven't published a specific at-rest encryption claim here because we want this page to only state what we've actually verified — ask us if this is a specific requirement for your organization and we'll give you a direct answer.
Reporting a vulnerability
If you believe you've found a security issue in Helmdesk, please email security@helmdesk.carather than filing a public issue. We'll acknowledge reports and keep you updated as we investigate.
More detail
See our Privacy Policy for what data we collect and which third-party processors we use.