Developer reference
Security and privacy
Understand the identity, ownership and data boundaries behind Helm’s private financial views.
Helm uses provider authentication, admission controls, owned sessions, scoped API tokens and server-mediated financial access. Public product pages and guides are readable without a financial session.
Read the boundaries
- Identity and ownership explains provider sessions and admitted access.
- Data access explains API, origin and resource checks.
- Destructive actions distinguishes deletion, correction and import undo.
For everyday sign-in and logout tasks, use session guidance. Read the public privacy page for the product’s privacy explanation.
Keep support reports private
Share the safe error code, request identifier and the action that failed. Do not publish tokens, password-reset links, full statements or another person’s account records.
An account number or source file can remain sensitive even if the balance is fictionalized. Review attachments before sending them.
Integration credentials
Use a minimum-scope user API token held server-side. Do not expose a service-role key or grant broad database access to simplify integration.
Session and availability
Private views stay concealed until owned identity is verified. Provider failure is unavailable, not permission to reveal a retained account. An API failure also must not turn into invented zero balances.
See client lifecycle for implementation behavior and token management for integration access.