HeliumOS Information Security Exhibit
EFFECTIVE SINCE
October 9, 2026
LAST UPDATED
October 9, 2026
This HeliumOS Information Security Exhibit (this “Exhibit”) is incorporated into the HeliumOS Terms and Conditions posted at helium.com/legal/heliumos (the "Terms") and describes the safeguards referenced in Section 10.5 of the Terms. Capitalized terms used but not defined in this Exhibit have the meanings given in the Terms.
1. Security Program
1.1 Program. Nova Labs maintains a written information security program comprising administrative, technical, and physical safeguards appropriate to its size, the nature of the Services, and the sensitivity of Customer Data, designed with reference to the SOC 2 Trust Services Criteria.
1.2 Security Lead. Nova Labs designates a security lead responsible for oversight and implementation of the program.
1.3 Review. Nova Labs reviews the program at least annually.
1.4 Updates. Nova Labs may update the program, provided that updates do not materially reduce the overall protection of Customer Data.
2. Personnel Security
2.1 Background Checks. Nova Labs conducts background checks, where permitted by Applicable Law, for personnel who will have access to Customer Data.
2.2 Confidentiality. Nova Labs personnel with access to Customer Data are bound by written confidentiality obligations no less protective than those in the Agreement.
2.3 Training. Nova Labs will provide security awareness training to personnel with access to Customer Data and will refresh it at least annually.
2.4 Offboarding. When any individual’s employment or engagement ends, Nova Labs promptly revokes that individual’s access to Customer Data and production systems.
3. Access Control
3.1 Least Privilege. Nova Labs applies least-privilege and role-based access principles when granting personnel access to production systems and Customer Data.
3.2 Unique Accounts. Each authorized individual is assigned a unique account. Shared or generic accounts are not permitted for access to Customer Data.
3.3 Multi-Factor Authentication. Multi-factor authentication is required for all administrative access to production systems and for any access to Customer Data.
3.4 Access Reviews. Nova Labs conducts access reviews at least annually to verify that access rights remain appropriate and to revoke access that is no longer required.
3.5 Logging. Administrative access events are logged in accordance with Section 9.
4. Customer Account Security
4.1 Platform Controls. The Services provide role-based access controls that allow Customer to assign permissions to its Authorized Users. API keys are scoped by environment (production or sandbox) and may be revoked by Customer at any time. Webhooks are cryptographically signed so that Customer can verify their authenticity.
4.2 Customer Responsibility. Customer is responsible for safeguarding its credentials, API keys, and access tokens, and for configuring user roles and permissions within the Services, as set forth in Section 3.2 of the Terms.
5. Encryption
5.1 Encryption in Transit. Customer Data transmitted over public networks is encrypted using TLS 1.2 or higher. For RADIUS traffic, Nova Labs supports RadSec or IPsec where supported by Customer Systems. Where Customer elects to use RADIUS over UDP without RadSec or a VPN, Customer accepts the associated risk.
5.2 Encryption at Rest. Customer Data at rest is encrypted using AES-256 or an equivalent standard.
5.3 Key Management. Cryptographic keys are managed through the key management services of Nova Labs' hosting providers or Nova Labs' own key management controls, with access restricted to authorized personnel on a least-privilege basis.
6. Infrastructure and Network Security
6.1 Hosting. The Services are hosted with the cloud infrastructure providers identified in the Subprocessor List, and Customer Data is stored at rest in facilities located in the United States, in accordance with Section 10.10 of the Terms.
6.2 Network Controls. Nova Labs maintains firewalls and security groups to restrict network traffic to authorized connections. Production environments are segregated from development and sandbox environments.
6.3 Segregation of Customer Data. Customer Data is logically segregated so that one customer’s data is not accessible to another customer. Production Customer Data is not used in development or testing environments except where approved in writing and subject to equivalent safeguards.
6.4 Hardening and Patching. Nova Labs applies system hardening standards and remediates known vulnerabilities on a risk-based timeline, with critical vulnerabilities targeted for remediation within thirty (30) days and high-severity vulnerabilities within ninety (90) days of identification.
7. Secure Development
7.1 Lifecycle. Nova Labs maintains a secure development lifecycle for the Services that includes: (a) peer code review before deployment to production; (b) automated dependency scanning and vulnerability scanning integrated into the development pipeline; and (c) change management procedures requiring documented approvals before production releases, with rollback capability for failed or defective deployments.
7.2 Review. Nova Labs reviews and updates its secure development practices at least annually.
8. Vulnerability Management and Testing
8.1 Scanning. Nova Labs performs regular automated vulnerability scanning of the production Services and supporting infrastructure.
8.2 Penetration Testing. Nova Labs will have an independent third party perform a penetration test of the off-chain HeliumOS Service within twelve (12) months after the effective date of this Exhibit, and at least annually after that.
8.3 Summaries. On Customer’s written request, no more than once in any twelve (12) month period, Nova Labs will provide an executive summary of its most recent penetration test. The summary is Nova Labs' Confidential Information.
8.4 Tracking. Nova Labs tracks identified vulnerabilities through remediation in accordance with the timelines in Section 6.4.
9. Logging and Monitoring
9.1 Logs. Nova Labs collects and maintains security-relevant logs for the production Services, including authentication events, administrative access, and configuration changes.
9.2 Protection and Retention. Logs are protected against unauthorized modification or deletion and are retained for at least ninety (90) days, except that logs containing Customer Data are retained as described in the applicable Product Schedule.
9.3 Monitoring. Nova Labs maintains monitoring and alerting capabilities designed to detect anomalous or unauthorized activity in the production environment.
10. Business Continuity and Resilience
10.1 Backups. Nova Labs performs encrypted backups of Customer Data at least daily. Backups are stored in a separate availability zone or region within the United States.
10.2 Restoration Testing. Nova Labs tests backup restoration procedures at least annually.
10.3 Continuity Planning. Nova Labs maintains a business continuity and disaster recovery plan, tested at least annually. Recovery objectives for the production Services are a recovery point objective (RPO) of twenty-four (24) hours and a recovery time objective (RTO) of forty-eight (48) hours.
10.4 Authentication Path. WOX is designed to fail closed as described in Section 6.5 of the Terms.
11. Incident Response
11.1 Plan. Nova Labs maintains a documented incident response plan that is tested at least annually through tabletop exercises or simulations.
11.2 Scope. The incident response plan addresses identification, containment, eradication, recovery, and post-incident review of Security Incidents.
11.3 Notice. Nova Labs shall notify Customer of Security Incidents in accordance with Section 10.6 of the Terms and the DPA.
12. Vendor and Subprocessor Management
12.1 Due Diligence. Nova Labs conducts security due diligence on each Subprocessor before engagement and periodically thereafter.
12.2 Contracts. Before a Subprocessor processes Customer Data, Nova Labs enters into a written agreement with it imposing security and confidentiality obligations no less protective of Customer Data than those in this Exhibit.
12.3 AI Model Providers. Third-party AI model providers used in connection with the Services are contractually restricted from using Customer Data to train or improve their models.
13. Physical Security and Endpoint Controls
13.1 Facilities. Nova Labs is a fully remote company and does not operate its own data centers. Physical security of production infrastructure is provided by Nova Labs' cloud hosting providers, whose facilities maintain SOC 2 Type II or ISO/IEC 27001 attestations or equivalent.
13.2 Endpoints. Nova Labs personnel devices that access Customer Data are company-managed or subject to endpoint security controls that include full-disk encryption, automatic screen lock, and endpoint protection software.
14. Data Disposal
14.1 Deletion. Nova Labs deletes Customer Data in accordance with Section 10.9 of the Terms using methods designed to render the data unrecoverable.
14.2 Media Sanitization. Deletion of Customer Data stored on infrastructure managed by Nova Labs' cloud hosting providers relies on those providers’ media sanitization processes, which are designed to prevent recovery of deleted data from physical storage media.
15. Assessments
15.1 Questionnaires. On Customer’s written request, no more than once in any twelve (12) month period, Nova Labs will respond to Customer’s reasonable security questionnaire within a commercially reasonable time.
15.2 Reports. On request and subject to confidentiality obligations, Nova Labs will provide its SOC 2 Type II report covering the Services, once Nova Labs obtains one.
15.3 Audits. Audit rights are governed by Section 10 of the DPA.