
SECURITY AND DEPLOYMENT
AI should fit your security boundary, not ask you to move it.
Charter parties, tariffs, crew data, claims and terminal operations are sensitive. The platform runs in your cloud tenant, your port or yard data centre, or onboard. Engines hold no credentials. Nothing is committed without a named person.
Review deployment requirementsHelmwize does not ask you to move the security boundary. Deployment options are customer cloud tenant, port or yard data centre, onboard edge node, hybrid, restricted network, or Helmwize managed. Standards posture is designed to map to NIST AI RMF, SP 800-207, ISO 27001/42001, IMDA agentic framework, IACS E26/E27. We will publish pen test, architecture documentation, sub-processors, incident policy and certifications as we earn them. We do not claim those certifications today.

Deployment
Where can it run?

Customer cloud tenant
Inside your estate.

Port or yard data centre
On site.

Onboard edge node
On the vessel.

Hybrid
Split by sensitivity.

Restricted network
No public internet required for the runtime.

Helmwize managed
Only where you choose it.
Principles
What are the security principles?

Identity first
Who is acting is always known.

Least privilege
Read before write.

Explicit action boundary
Staged, not committed.

Human accountability
Nothing is committed without a named person.

Encryption, secrets, isolation, minimisation
Engines hold no credentials.

Model governance, logging, evaluation, incident handling, retention
Every production workflow has acceptance tests.
Autonomy
What may the software do, and what is prohibited?
| Tier | Meaning |
|---|---|
| Observe | Read only. |
| Recommend | A recommendation you can inspect. |
| Draft | A local draft. Nothing is sent. |
| Act with approval | A named person commits. |
| Bounded automation | Inside an explicit boundary. |
| Prohibited | The AI never has more authority than the person using it. |
Standards
What will we publish as we earn it?
Pen test, architecture documentation, sub-processors, incident policy, certifications. Designed to map to NIST AI RMF, SP 800-207, ISO 27001/42001, IMDA agentic framework, IACS E26/E27. None of those are claimed as held today.
FAQ
Questions
Where does our data live?
The platform runs in your cloud tenant, your port or yard data centre, or onboard.
Who can act?
Nothing is committed without a named person. Engines hold no credentials.
Do you have SOC 2 or ISO 27001?
We will publish certifications as we earn them. We do not claim them today.
