Help4 Net

Compliance and security baseline

Help4 Net is built with a documented control baseline for security, privacy, and incident response. This page is the public summary of our current compliance posture.

Last reviewed: August 20, 2026. Latest public packet: help4-cdn-compliance-public-2026-08-20.zip.

This is not a legal attestation report. It is a control and operations summary to support customer review workflows.

59 pass5 manual-evidence warnings and 0 technical failures in the current program check
11 activeAll POP heartbeat, cache, synthetic, and parity checks passing
30,957Block-enabled CVE entries in current threat-intel state
0Active CDN heartbeat security alerts in final check

Current baseline coverage

SOC 2 control baselineDocumented control mapping across access, monitoring, change, and risk mitigation controls.
Tenant API access controlSite-scoped credentials use show-once secrets, hashed storage, DNS-derived non-MX source authorization, explicit reset/revoke, and an exact-IP Enterprise admin option.
HIPAA-oriented operations baselineAdministrative, physical, and technical safeguard operating model with BAA boundary workflow.
Global privacy operations matrixOperational alignment guidance for US state privacy, EU/UK, AU, and planned expansion regions.
Continuous CVE monitoringRecurring internet CVE feed scans run on schedule to detect new high-risk vulnerability releases.
Virtual patch workflowThreat-intel ingest can trigger staged WAF virtual patch rollout while origin patch windows are in progress.
Bypass prevention and origin lockdownPublic traffic is expected to route through Help4 POPs, with origin-security warnings visible until origin HTTPS/TLS is verified.
Incident and breach runbookDefined incident lifecycle, containment actions, and notification timer matrix.
Data retention and deletion standardRetention classes, deletion controls, and legal hold handling model.
Readiness reportingProgram-level compliance audit reviewed August 20, 2026; the latest virtual-patch evidence is dated July 26, 2026.

Latest evidence refresh

The current public packet includes the August 20, 2026 compliance program audit, the governance-register baseline, and the latest included fleet health and WAF virtual patch evidence records, each explicitly dated.

Audit resultCompliance program audit recorded 59 passes, 5 manual-evidence warnings, and 0 technical failures.
Threat coverageCurrent threat-intel state records 32,086 CVE entries with 30,957 block-enabled protections.
POP parityAll 11 POPs are active and passing fresh cache, synthetic, origin-parity, and virtual-patch distribution checks.

Readiness is not an attestation. Draft governance baseline rows do not constitute owner-approved access reviews, risk assessments, vendor/subprocessor due diligence, RoPA or legal records, or signed BAA evidence; those five manual evidence areas remain warnings. ePHI is prohibited until required service-specific BAA coverage is verified.

Customer review support

For deeper diligence workflows, we provide customer-specific compliance documentation through secure support channels.

Security review packetControl descriptions, operational baselines, and readiness snapshot.
Legal artifact workflowContractual/legal documents are shared through authorized channels only.
Technical control walkthroughLive walkthrough of edge, routing, logging, and incident controls by request.
Origin lockdown reviewBypass-prevention checklist for customer onboarding, direct-origin exception review, and end-to-end TLS warning clearance.

Contact support through Help4 Network for client-specific compliance requests.