Helios control plane
Allowlist and deployment health only
Tenant approval, deployment identity, version, and heartbeat stay with Helios.
Privacy
This page explains product data boundaries for regulated financial environments, not the website privacy notice.
Helios control plane
Tenant approval, deployment identity, version, and heartbeat stay with Helios.
Client data plane
Raw messages, normalized payloads, events, timelines, exports, and secrets stay inside the client Azure environment.
App separation
The public website, the Helios pilot app, and external partner deployments should not be treated as the same operating surface.
Banks, asset managers, hedge funds, and similar institutions need sensitive communications evidence to remain under clear custody boundaries. For regulated teams, deployment isolation matters more than allowlisting alone.
DecisionTrail runs with deployment isolation by default. No shared data layer and no message storage in Helios infrastructure.
The product must preserve tenant-scoped auth, deployment identity, review auditability, and narrative exports inside the environment that actually owns the data.