Security & privacy

We treat your data the way we’d want ours treated.

Helpable is built so the boring-but-important things are right by default: EU hosting, encryption everywhere it should be, GDPR posture from day one, and a hard rule that your data never trains anyone’s models.

EU-hosted by default

All customer data — articles, conversations, visitors — lives on EU-based infrastructure. No cross-Atlantic transfer for the data that matters.

GDPR by default

Helpable is GDPR-compliant out of the box. We sign Data Processing Agreements with every paying customer and respect data-subject requests through your dashboard.

Encryption in transit and at rest

Every connection uses TLS 1.2+. Data at rest in our managed Postgres is encrypted with AES-256. OAuth tokens for integrations like Slack are encrypted with a per-tenant key before they hit the database.

Your data is not used to train models

We never use your articles, conversations, or visitor data to train AI models — ours or anyone else’s. Calli AI answers from your knowledge base only, with a source link to the article it used.

Workspace-scoped permissions

Every API call is scoped to the workspace that owns the data. Verified variables in the widget ensure customers only see their own data — even when the same widget is embedded for thousands of accounts.

Sensible defaults you can tighten

Help centers are private until you publish them. Articles are draft until you schedule them. Integration secrets are write-only after they’re saved. Team invites expire. Nothing is shared until you say so.

FAQ

Common questions

Do you train AI models on my data?

No. Your articles, conversations, and customer data are never used to train Helpable’s models or shared with third-party model providers for training. Calli AI uses your knowledge base only for retrieval-augmented answers at request time.

Where is my data stored?

Helpable is hosted in the European Union on managed Postgres and serverless infrastructure. Data residency for customer content is EU-only by default.

Do you support SSO and SAML?

SSO and SAML are part of the Enterprise plan. Contact sales for setup — it usually takes one working day from when you provide the metadata XML.

How do I report a security issue?

Email security@gethelpable.com with the details. We respond within one working day. Please do not publicly disclose vulnerabilities before we have had a chance to fix them.

Can I get a DPA?

Yes. A signed Data Processing Agreement is available on every paid plan. Drop a note in support and we will send one over.

Need SSO, SAML, or a custom security review?

These ship with Enterprise. Tell us what your security team needs and we’ll set it up.

Talk to sales