Tagline

Frequently asked questions

Can clients request a Data Processing Agreement (DPA)?

Yes. Enterprise clients operating in jurisdictions with specific data transfer requirements can request a DPA. Contact info@whitehelmet.com.

Does WhiteHelmet use my data to train its AI?

No. WhiteHelmet does not use client-uploaded project data to train AI models without explicit written consent.

What happens to my data if I cancel my subscription?

Your data remains accessible during any post-cancellation grace period defined in your contract. After this period, data is securely deleted unless otherwise agreed. Contact your account manager for specifics.

Can WhiteHelmet outputs be used in regulatory submissions?

WhiteHelmet's AI-generated outputs, including compliance analyses, reports, and observations, are intended to support internal decision-making. They do not constitute certified professional or legal advice. Clients are responsible for verifying outputs with qualified professionals before formal submissions.

How is my data protected against breaches?

WhiteHelmet uses end-to-end encryption, role-based access controls, multi-factor authentication, and continuous monitoring. In the event of a confirmed breach, affected clients are notified in accordance with applicable law.

What cybersecurity standards does WhiteHelmet comply with?

WhiteHelmet follows OWASP methodology for global security standards and adheres to the National Cybersecurity Authority (NCA) requirements in the Kingdom, and is SOC 2 Type II certified, independently audited based on the AICPA's Trust Services Criteria covering Security, Availability, and Confidentiality.