TENDER
Sign inStart free
A chrome yacht cleat with cream rope locked off and a rose-gold padlock on the rail, blue sea beyond
Security

Straight answers on data, AI and what we will never do.

Short version: your data is stored in Australia, AI analysis runs through OpenAI and Anthropic under no-training arrangements, your tender documents are private to your account, and Helm never submits anything on your behalf. The detail, with nothing rounded up:

Where your data lives

Your account, business profile, watchlist and pipeline are stored in an Australian data-centre region, and the application runs on Australian hosting. Three categories of data leave Australia in transit to processors: payment details go to our payment processor; text being scored or drafted is processed by our AI providers, OpenAI and Anthropic, in the United States; and the email we send you goes through our email delivery provider, whose sending infrastructure is offshore, which means your name and email address pass through it and sit in its delivery logs for 30 days. We store none of those three offshore ourselves. The processors are named on the legal page, as the law requires; this page stays at the level of what and where, on purpose. This is the same statement our legal page makes, because there is only one version of the truth.

STORED IN AUSTRALIAAustralian data-centre regionaccount · business profile · watchlist · pipelineThe applicationAustralian hostingIN TRANSIT ONLY · NOTHING STORED OFFSHOREPayment processorpayment details, in transitAI providers, United Statestext being scored or drafted, no trainingEmail delivery provider, offshorethe email we send you; logs keep name and address 30 days
Stored in Australia: your account, business profile, watchlist and pipeline, and the application itself. In transit only, to three processors: payment details to the payment processor; text being scored or drafted to the AI providers in the United States; the email we send you through the delivery provider, whose logs hold your name and address for 30 days. Helm stores none of those three offshore. Processors are named on the legal page.

What the AI sees, and what it never does

  • What is sent: your capability statement and profile facts, and the text of tenders being scored or drafted, are sent to our AI providers, OpenAI and Anthropic, for analysis. That is the whole list.
  • No training: our API usage is not used to train OpenAI's or Anthropic's models, per each provider's API data-usage terms.
  • No invention: drafted text must trace to your profile, the tender's own documents, or stay behind a visible [CONFIRM: ...] marker. Compliance matrices quote your documents verbatim with file and page. An automated audit runs against every release.
  • Itemised scores: every match score is a sum of labelled parts you can read on the tender page. A relevance score is never a win probability and we never call it one.

Your tender documents

Documents you upload live in a private bucket, are served only through your authenticated session, are never shared across accounts, never enter anyone else's matching, and are deleted 90 days after the bid is decided, and no later than twelve months after the tender closes, with an email fourteen days before. For grant rounds still undecided at twelve months, the pre-purge email arrives fourteen days before deletion; download the bid archive if you need it. You bring your own copies under your own portal registration; Helm never fetches portal documents for you.

How accounts and systems are protected

  • Two-factor sign-in on every account. Every account sets up a code from an authenticator app within seven days of opening, and signing in then needs it. The Helm admin area will not open without it in every session, and never trusts a remembered device.
  • Encrypted in transit and at rest. Every connection to Helm is encrypted, and the database and document storage that hold your data are encrypted at rest.
  • Access kept small. Only the people who operate Helm can reach the systems that run it, through key-based access. We look at the content of your workspace only when you ask us to help, or when keeping the service running requires it.
  • Backups. The database and stored documents are backed up every night and kept in Australia on a rolling basis of about two weeks, and restoring from them has been tested. An encrypted archive copy is also made periodically and kept away from the server for disaster recovery.
  • If something goes wrong. If a breach is likely to cause serious harm, we notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires, and we tell you what happened and what we did.

Reporting a security issue

If you believe you have found a vulnerability in Helm, email our contact page with "Security report" in the subject line, and include what you found, where, and how to reproduce it. We acknowledge reports within 5 business days and keep you updated until it is fixed.

We will not take legal action against research done in good faith that stays within these limits: use only your own account or test data, do not access, change or keep other people's data, do not degrade the service for anyone else, and give us reasonable time to fix the issue before telling anyone. We do not run a paid bug bounty. The same contact is published in machine-readable form at /.well-known/security.txt.

What Helm will never do

  • No automated submissions. Helm prepares; you submit. A tool that lodges government tenders on your behalf is a liability you should not accept from anyone.
  • No bid/no-bid verdicts. Helm states evidence and gaps; the pursue decision is yours.
  • No republishing of procurement officers' personal contact details. Whatever the SEO upside.
  • No data from restricted portals. Helm indexes sources whose terms permit it, shows the licence line on every record, and asks first everywhere else.

Provenance on every record

Every tender in Helm carries a source line: which portal, under what licence, read when, with a link back to the original. Counts are labelled: "indexed" and "on live feeds" are different numbers and we show both. Sample data is labelled as sample data.

Certifications

None yet claimed. Helm is an early-stage product and we will not decorate this page with a roadmap dressed as an achievement. When a certification is audited and held, it will appear here with its scope and date. Ask us anything specific through the contact form.

Questions a careful buyer should ask any provider

  • Which portals permit your provider's data model, and can they show you the terms?
  • Are the counts on the homepage live records or an archive?
  • Are the dashboard numbers real data or a labelled sample, and if unlabelled, why?
  • Where does AI processing run, and does the marketing claim match the privacy policy?

We are happy to answer all four about Helm, in writing, any time.