Blog

Frequently Asked Tech Questions

HelmGuard Team

Blog

Frequently Asked Tech Questions

HelmGuard Team

In this article

No headings found on page

Request a demo

By clicking the submit button, you agree to HelmGuards' Privacy Policy

Request a demo

By clicking the submit button, you agree to Helmguards' Privacy Policy

Introduction

This FAQ answers the questions that risk, compliance and security leaders most often ask when evaluating HelmGuard's technology.

What is the underlying architecture?

HelmGuard is built as an Agentic GRC platform, where Agents are able to reason over organisational context, interact with data and systems, and execute defined actions.

The architecture separates the reasoning layer, organisational knowledge, tools/actions and governance controls, allowing Agents to perform work while remaining controllable and auditable.

Which AI models does HelmGuard use?

HelmGuard can use different underlying AI models from providers such as Anthropic, OpenAI, Google DeepMind and Mistral.

This allows model selection to be based on the task, including considerations such as capability, cost, latency, privacy and performance. It also allows for redundancy if any one provider experiences reliability issues.

The Agent is the product — the underlying model is a component.

Where is our data held?

HelmGuard customer data is held in secure, access-controlled cloud infrastructure, with data residency and processing locations agreed with the customer as part of the service. Current options include the UK and the USA, with plans to expand to other regions including the EU and APAC.

HelmGuard can support requirements around data residency, access controls, encryption and segregation, with the applicable hosting and processing locations documented contractually and through our security and data-processing documentation.

Customer data is only accessible to authorised users and services required to deliver the platform, with access governed by defined permissions and monitored through audit controls.

For customers with specific regulatory or contractual data-residency requirements, HelmGuard can define the applicable hosting and processing arrangements as part of the implementation and contractual process.

Do you train models on our data?

Customer data is not used for model training.

HelmGuard’s data-processing and contractual arrangements define how customer data is handled, stored and processed. We have contractual Zero Data Retention (ZDR) agreements with all of our third-party AI providers.

This means that customer data sent to these AI providers is processed only to deliver the requested service and is not retained after processing or used by the provider for training, product development or any other purpose. Once processing is complete, the provider does not retain the customer data in its systems, subject to any narrowly defined exceptions explicitly covered by the applicable contractual terms.

Can Agents access our systems?

Yes.

Agents can connect to relevant enterprise systems and information sources through integrations and controlled tools.

Access can be restricted according to the Agent's role and the actions it is permitted to perform.

How are Agent permissions controlled?

Agents operate within defined permissions and guardrails.

Controls can be applied around:

  • Data access

  • Available tools

  • Permitted actions

  • Approval requirements

  • User roles

  • Escalation rules

An Agent should only be able to do what it has been authorised to do.

How does HelmGuard manage hallucinations and incorrect reasoning?

HelmGuard is designed around evidence-based execution rather than unsupported AI responses.

Controls can include:

  • Cited evidence and sources

  • Confidence assessment

  • Defined thresholds

  • Human escalation

  • Restricted actions

  • Expert benchmarking

  • Testing against known outcomes

  • Monitoring for changes in performance

The goal is not to assume an Agent is always correct. It is to make its performance measurable, controlled and governable.

What happens if an Agent fails?

Agents can make mistakes, just like people and traditional software can. The important thing is to design the system so that a mistake does not automatically become a business decision or action.

HelmGuard uses multiple layers of protection, including:

  • Validation — check outputs before they are used or acted upon.

  • Approval gates — require human approval for higher-risk actions.

  • Exception handling — identify when an Agent is uncertain or encounters something outside its normal operating parameters.

  • Escalation — route higher-risk or unusual situations to the appropriate person.

  • Permission boundaries — limit what each Agent can access, change and execute.

  • Audit trails — record what the Agent did, what information it used and why.

  • Model back-up and failover — Agents can use different models and providers, so if a model is unavailable, underperforms or encounters an issue, another suitable model can be used.

The objective is to ensure that an Agent failure becomes a controlled exception that can be identified, managed and corrected, rather than an uncontrolled business action.

How does HelmGuard handle data privacy and security?

HelmGuard applies security and privacy controls across both the platform and Agent activity, recognising that Agentic GRC introduces additional considerations around data access, processing and execution.

Our controls cover a number of different areas including:

  • Data residency and processing locations

  • Encryption in transit and at rest

  • Identity, authentication and access controls

  • Logical tenant isolation

  • Data retention and deletion

  • Subprocessors and third-party AI providers

  • Audit logging and activity monitoring

  • Agent permissions and tool access

  • AI model and data-processing arrangements

  • Customer data ownership and confidentiality

These controls are supported through HelmGuard's security architecture, policies and contractual arrangements, and can be reviewed as part of the procurement and due-diligence process.

HelmGuard is ISO 27001, SOC 2 Type II and UK Cyber Essentials Plus certified.

Further details of HelmGuard's security posture, certifications, policies and supporting documentation are available through our Trust & Security Portal.

How does HelmGuard integrate with our existing technology?

HelmGuard is designed to operate across the existing technology landscape rather than require every piece of GRC data to be manually copied into a new system.

Agents can interact with relevant systems, retrieve information, perform work and write outputs back where appropriate.