Security & reliability

Physical controls, documented authority, and a clear handoff.

Helixrack LLC secures and operates the physical environment and facility-side network handoff. Customers secure the systems and workloads running on their hardware.

Last reviewedSecurity contact[email protected] · subject: Security report
Physical access

Badge entry, cameras, and escorted visits

Controlled equipment areas use badge-controlled entry and continuously recording camera coverage. Visitors are scheduled and escorted, and the service record identifies who may request work on each machine.

Power & environment

UPS, generator, and monitored cooling

A 30 kVA double-conversion UPS and permanent 30 kW diesel generator support the protected load through an automatic transfer switch. Facility inlet and humidity targets are monitored; none of these controls is an application-uptime guarantee.

Network boundary

Assigned port and addressing

The facility record identifies the customer port, addressing method, transfer meter, and acceptance check. Customers control host firewall policy, remote-management exposure, and application services.

Hardware custody

Identity at each state

The shipment reference, visible condition, chassis identity, test state, rack assignment, authorized physical work, removal instruction, and carrier release remain connected in the custody record.

Change control

Target, action, stop, verify

State-changing physical work requires an authorized contact, exact target, permitted action, stop condition, and observable completion check. The operator pauses when the observed state does not match the request.

Shared responsibility

A secure room does not secure an application.

Helixrack controls

Facility access, power and cooling systems, rack position, facility-side cabling, receiving, and the network handoff.

Customer controls

Firmware, OS, accounts, encryption, firewall policy, application security, backups, data handling, and recovery.

Confirm in writing

Regulated, audited, high-density, or unusual deployments require review before shipping. Colocation alone does not make a workload compliant.

Compliance scope

Validate requirements before intake.

The published service does not include a SOC 2, PCI DSS, HIPAA, ISO, Tier, or similar third-party certification. A customer with contractual, audited, regulated, or data-location requirements must identify them before shipping and confirm its own control set.

Security report

Report privately.

Send the affected URL or service, reproduction steps, impact, observed time, and a safe way to reply. Do not access customer systems, retain customer data, or include secrets in the first message.

Email a security report
Read security.txt

Good-faith vulnerability research

You may test the public Helixrack website only when the activity is lawful, uses your own accounts and data, avoids service degradation, and stops after demonstrating the issue. Do not test customer systems, facility networks, mail infrastructure, form relays, third-party services, physical controls, or social-engineering scenarios without separate written authorization.

Helixrack does not operate a public bug-bounty program. We will review a good-faith report, preserve the reporter's contact preference, and coordinate disclosure when a confirmed issue requires remediation. This policy does not authorize access that would otherwise be unlawful.

Customer security events

For a suspected compromise of customer-owned hardware, first protect customer-controlled accounts, keys, firewall policy, and backups. Contact Helixrack when a facility-side port action, physical observation, or authorized power action is needed, and identify the server, impact, first observed time, and requested protective step.

Have a workload-specific requirement?

Describe it before shipping so both sides can confirm the boundary.

Send requirements