Groove is now Helply.

We protect your data.

Customer support conversations hold some of the most sensitive context a business has. Helply is built so that data stays isolated, encrypted, and auditable while AI still gets real work done.

This page explains how we handle your data and what we've put in place to keep it safe.

  • SOC 2 Type II complianceSOC 2 Type II
  • GDPR complianceGDPR

Your data isn't training someone else's model.

It stays scoped to you.

Customer data sent to AI providers is never used to train their models. It stays scoped to your tenant and is used only to do the work you ask for.

Every tenant is isolated. Customer data remains scoped to the appropriate tenant and environment, so one customer's data is never visible to another.

Your context is yours. It doesn't leak into a model.

Encrypted in transit and at rest.

Everywhere your data lives.

Whenever your data moves between you and Helply, it's encrypted and sent over HTTPS. Data stored on our systems is encrypted at rest.

Encryption isn't something you turn on. It's the default for every piece of customer data on the platform.

Least-privilege access, for humans and AI.

You can only touch what you're authorized to.

Production systems follow least-privilege access principles. People and AI agents only reach the systems and data they're authorized to use.

Access is reviewed and revoked when it's no longer needed. The fewer keys that exist, the fewer ways in there are.

Access is earned, scoped, and regularly reviewed.

Every AI action is auditable.

You can always see what happened, and why.

AI actions, resolutions, escalations, and signals are logged. When an agent does something on a conversation, your team can trace exactly what it did and the reasoning behind it.

Automation without a paper trail isn't trustworthy. So we keep one.

Independently audited.

SOC 2 Type II and GDPR.

Helply maintains a SOC 2 Type II report covering its security and operational controls. It's available to prospects and customers under NDA through the Trust Center.

We're built to support GDPR, including data processing agreements and documented data-handling procedures. A DPA is available on request.

Independent audits, not just our word for it.

Continuously monitored.

Security shouldn't depend on someone remembering to turn it on.

Encryption.
Customer data is encrypted in transit and at rest.
Access controls.
Least-privilege access, reviewed and revoked when no longer needed.
Continuous monitoring.
80+ controls across infrastructure, application, product, and data security are continuously monitored.
Data control.
Customer data is handled by documented retention, deletion, and access procedures.

Want to know more?

It's all in the Trust Center.

Security controls, SOC 2 audit documentation, subprocessors, and policies all live in one place. Request access and your security team can review everything they need.

Send us your security questionnaire and our team will complete it. The supporting documentation is there to speed the review along.

Have a concern? Need to report something?

Tell us, and we'll act quickly.

If you've noticed abuse, misuse, a suspected vulnerability, or an incident with your account, contact our security team and we'll respond promptly.

If something malicious ever does succeed, we notify affected customers. We don't sit on it.

Contact the security team

Security questions? We've probably answered them.

For anything else, our team can help with your security review.

  • Yes. Helply maintains a SOC 2 Type II report covering its security and operational controls. The report is available to prospects and customers under NDA through the Trust Center.

  • Helply is built to support GDPR requirements, including data processing agreements and documented data-handling procedures. A DPA is available on request.

  • No. Customer data sent to AI providers is not used to train their models. Support data stays scoped to your tenant and is used only to do the work you request.

  • Customer data is encrypted in transit and at rest, access follows least-privilege principles, and security controls are continuously monitored. AI actions are logged so they can be audited.

  • Helply works with established model providers under agreements that prohibit training on customer data. The current list of AI subprocessors is available in the Trust Center.

  • Infrastructure details and hosting regions are documented in the Trust Center.

  • Yes. A current list of subprocessors, along with their purpose and data handling, is maintained in the Trust Center.

  • Yes. Send us your security questionnaire and our team will complete it. Supporting documentation is available in the Trust Center to speed up the review.

  • Email security@helply.com to report a suspected vulnerability, and we will respond promptly.

  • Security controls, audit documentation, subprocessors, and policies are available in the Trust Center. Request access and your security team can review everything in one place.