A small on-site server room with port cranes beyond. Illustrative.

SECURITY AND DEPLOYMENT

AI should fit your security boundary, not ask you to move it.

Charter parties, tariffs, crew data, claims and terminal operations are sensitive. The platform runs in your cloud tenant, your port or yard data centre, or onboard. Engines hold no credentials. Nothing is committed without a named person.

Review deployment requirements

Helmwize does not ask you to move the security boundary. Deployment options are customer cloud tenant, port or yard data centre, onboard edge node, hybrid, restricted network, or Helmwize managed. Standards posture is designed to map to NIST AI RMF, SP 800-207, ISO 27001/42001, IMDA agentic framework, IACS E26/E27. We will publish pen test, architecture documentation, sub-processors, incident policy and certifications as we earn them. We do not claim those certifications today.

A small on-site server room with port cranes beyond. Illustrative.

Deployment

Where can it run?

Deployment options

Customer cloud tenant. Still from the reel.

Customer cloud tenant

Inside your estate.

Port or yard data centre. Still from the reel.

Port or yard data centre

On site.

Onboard edge node. Still from the reel.

Onboard edge node

On the vessel.

Hybrid. Still from the reel.

Hybrid

Split by sensitivity.

Restricted network. Still from the reel.

Restricted network

No public internet required for the runtime.

Helmwize managed. Still from the reel.

Helmwize managed

Only where you choose it.

Principles

What are the security principles?

Security principles

Identity first. Still from the reel.

Identity first

Who is acting is always known.

Least privilege. Still from the reel.

Least privilege

Read before write.

Explicit action boundary. Still from the reel.

Explicit action boundary

Staged, not committed.

Human accountability. Still from the reel.

Human accountability

Nothing is committed without a named person.

Encryption, secrets, isolation, minimisation. Still from the reel.

Encryption, secrets, isolation, minimisation

Engines hold no credentials.

Model governance, logging, evaluation, incident handling, retention. Still from the reel.

Model governance, logging, evaluation, incident handling, retention

Every production workflow has acceptance tests.

Autonomy

What may the software do, and what is prohibited?

Autonomy tiers
TierMeaning
ObserveRead only.
RecommendA recommendation you can inspect.
DraftA local draft. Nothing is sent.
Act with approvalA named person commits.
Bounded automationInside an explicit boundary.
ProhibitedThe AI never has more authority than the person using it.

Standards

What will we publish as we earn it?

Pen test, architecture documentation, sub-processors, incident policy, certifications. Designed to map to NIST AI RMF, SP 800-207, ISO 27001/42001, IMDA agentic framework, IACS E26/E27. None of those are claimed as held today.

FAQ

Questions

Where does our data live?

The platform runs in your cloud tenant, your port or yard data centre, or onboard.

Who can act?

Nothing is committed without a named person. Engines hold no credentials.

Do you have SOC 2 or ISO 27001?

We will publish certifications as we earn them. We do not claim them today.

Start

Review deployment requirements

Review deployment requirements