Trust
Trust, the honest version
An RMM agent is among the most privileged software an MSP installs. Here is exactly what we do to deserve that access, and what we do not claim yet.
The honest starting point
Helios is a young company, and an RMM agent is one of the most privileged pieces of software an organisation can install. We think the right response to that is not a page of borrowed logos, it is telling you plainly what we do, what we do not do yet, and letting you judge. Helios does not yet hold its own SOC 2 or ISO 27001 certificate, and we will not imply otherwise.
What we bring instead is the thing a certificate is supposed to prove. The people who build and run Helios have spent years inside large organisations that hold both: we have personally implemented SOC 2 and ISO 27001 control environments, operated under them daily, and sat on the receiving end of the recurring external audits that keep them honest. The controls on this page are not guesses at what auditors want. They are the habits that survive audits, applied here from day one, and formal certification for Helios itself is a milestone we are working towards, not an aspiration we are deferring.
Platform security
- Two-factor authentication is mandatory for every administrator account, not optional. Passkeys (WebAuthn) are supported for phishing-resistant sign-in, with TOTP as the baseline.
- Strict tenant isolation. Every query in the platform is scoped to your MSP's tenant. Your clients' data is never visible to another tenant, and platform staff cannot browse tenant data through the product.
- Encrypted credential vault. Client credentials you store are encrypted at rest with a key held outside the database, and every reveal is written to an access log you can read.
- Audit logging. Sign-ins, credential reveals and administrative actions are logged.
- Regular security review. The platform undergoes recurring internal security audits covering tenant isolation, authentication and the agent command path. Issues found are fixed before this page tells you about the process.
The agent
- Outbound only. The Helios agent connects out to the platform over HTTPS. It opens no inbound ports and needs no firewall holes.
- Visible actions. Every script run, patch install and remediation the platform performs on a device is recorded against that device where your technicians can see it.
- You control autonomy. Helio's ability to act is set per client: suggest only, act with technician approval, or act autonomously. Fixes Helio writes itself always require a technician's approval before they run.
Your data
- Hosted in EU data centres with Hetzner, a German infrastructure provider, with daily infrastructure-level backups.
- Encrypted in transit everywhere: browser to platform, agent to platform, platform to integrations.
- Yours to take. Your clients, devices, tickets and alerts are accessible over the Helios API, so your data is never hostage to your subscription.
- AI with boundaries. AI features run on Anthropic's Claude models. You can bring your own API key so AI traffic runs under your own agreement, and AI usage on platform keys is capped and metered per tenant.
Commercial trust
- Monthly billing, cancel any time from your own billing page. No phone call, no notice window, no multi-year auto-renewal.
- Flat pricing, published. What you would pay is on the pricing section, not behind a sales call.
- We run an MSP on it. Helios manages our own MSP's clients every day. When something is not good enough, we feel it before you do.
Questions we want you to ask
Ask us how tenant isolation is enforced. Ask what happens to your data when you cancel. Ask what Helio is allowed to do without a human. Email hello@heliosmip.com and you will get a straight answer from the people who built it, because there is nobody else here to hand you to.