Security

Last updated: 4 September 2026

Security is the product

FirstHelm exists because autonomous systems need governance. Security is not a layer we bolt on — it is the reason the platform exists.

Architecture

FirstHelm is built on isolation and least-privilege principles. Agent actions never execute directly on the platform — they are gated: proposed, evaluated against constraints, and either approved, blocked, or escalated to a human. The control plane and your agent runtimes are separate by design.

Data security

  • In transit: TLS 1.2 or higher for all connections.
  • At rest: AES-256 encryption for stored data.
  • Secrets: API keys and credentials encrypted at rest with envelope encryption and regular key rotation.

Access control

Role-based access limits what each team member can see and do. Optional SSO is available for Enterprise plans. Per-operator permissions scope actions to the teams and missions a user owns — and every human action is audited too, not just the agents'.

Human-in-the-loop by design

Approvals, interventions, and kill switches are first-class primitives. No high-risk agent action proceeds without a human decision, and any agent or mission can be paused, redirected, or killed instantly.

Auditability

Activity and decision logs are immutable. The full audit trail — agent actions, approval decisions, and interventions — is exportable as CSV or JSON on demand for compliance and incident review.

Incident response

We follow a documented incident-response process. Security incidents affecting customer data are notified to affected customers within 72 hours of confirmation, with a post-mortem published thereafter.

Responsible disclosure

Report vulnerabilities to contact@firsthelm.dev. We acknowledge reports within 48 hours and work with reporters on remediation and disclosure.

Business continuity

Encrypted backups are taken regularly with target Recovery Time (RTO) and Recovery Point (RPO) objectives aligned to each service tier.

Data residency

Customer data is hosted in the UK/EEA by default. See the Compliance page for regulatory detail.

© 2026 FirstHelm Technologies Ltd · The human-first control layer for autonomous AI