Badge entry, cameras, and escorted visits
Controlled equipment areas use badge-controlled entry and continuously recording camera coverage. Visitors are scheduled and escorted, and the service record identifies who may request work on each machine.
Security & reliability
Helixrack LLC secures and operates the physical environment and facility-side network handoff. Customers secure the systems and workloads running on their hardware.
Controlled equipment areas use badge-controlled entry and continuously recording camera coverage. Visitors are scheduled and escorted, and the service record identifies who may request work on each machine.
A 30 kVA double-conversion UPS and permanent 30 kW diesel generator support the protected load through an automatic transfer switch. Facility inlet and humidity targets are monitored; none of these controls is an application-uptime guarantee.
The facility record identifies the customer port, addressing method, transfer meter, and acceptance check. Customers control host firewall policy, remote-management exposure, and application services.
The shipment reference, visible condition, chassis identity, test state, rack assignment, authorized physical work, removal instruction, and carrier release remain connected in the custody record.
State-changing physical work requires an authorized contact, exact target, permitted action, stop condition, and observable completion check. The operator pauses when the observed state does not match the request.
Shared responsibility
Facility access, power and cooling systems, rack position, facility-side cabling, receiving, and the network handoff.
Firmware, OS, accounts, encryption, firewall policy, application security, backups, data handling, and recovery.
Regulated, audited, high-density, or unusual deployments require review before shipping. Colocation alone does not make a workload compliant.
Compliance scope
The published service does not include a SOC 2, PCI DSS, HIPAA, ISO, Tier, or similar third-party certification. A customer with contractual, audited, regulated, or data-location requirements must identify them before shipping and confirm its own control set.
Send the affected URL or service, reproduction steps, impact, observed time, and a safe way to reply. Do not access customer systems, retain customer data, or include secrets in the first message.
Email a security reportYou may test the public Helixrack website only when the activity is lawful, uses your own accounts and data, avoids service degradation, and stops after demonstrating the issue. Do not test customer systems, facility networks, mail infrastructure, form relays, third-party services, physical controls, or social-engineering scenarios without separate written authorization.
Helixrack does not operate a public bug-bounty program. We will review a good-faith report, preserve the reporter's contact preference, and coordinate disclosure when a confirmed issue requires remediation. This policy does not authorize access that would otherwise be unlawful.
For a suspected compromise of customer-owned hardware, first protect customer-controlled accounts, keys, firewall policy, and backups. Contact Helixrack when a facility-side port action, physical observation, or authorized power action is needed, and identify the server, impact, first observed time, and requested protective step.
Describe it before shipping so both sides can confirm the boundary.