Help4 Net

Compliance and security baseline

Help4 Net is built with a documented control baseline for security, privacy, and incident response. This page is the public summary of our current compliance posture.

Last reviewed: October 2, 2026. Latest public packet: help4-cdn-compliance-public-2026-10-02.zip.

This is not a legal attestation report. It is a control and operations summary to support customer review workflows.

59 pass5 manual-evidence warnings and 0 technical failures in the current program check
10 servingSeptember 27 authenticated fleet closeout; three POPs remain non-public security holds
UnmeasuredCurrent source-of-truth rule counts pending a complete authenticated collection
UnmeasuredNo current aggregate alert count is represented without a complete authenticated collection

Current baseline coverage

SOC 2 control baselineDocumented control mapping across access, monitoring, change, and risk mitigation controls.
Tenant API access controlSite-scoped credentials use show-once secrets, hashed storage, DNS-derived non-MX source authorization, explicit reset/revoke, and an exact-IP Enterprise admin option.
HIPAA-oriented operations baselineAdministrative, physical, and technical safeguard operating model with BAA boundary workflow.
Global privacy operations matrixOperational alignment guidance for US state privacy, EU/UK, AU, and planned expansion regions.
Continuous CVE monitoringRecurring internet CVE feed scans run on schedule to detect new high-risk vulnerability releases.
Virtual patch workflowThreat-intel ingest can trigger staged WAF virtual patch rollout while origin patch windows are in progress.
Bypass prevention and origin lockdownPublic traffic is expected to route through Help4 POPs, with origin-security warnings visible until origin HTTPS/TLS is verified.
Incident and breach runbookDefined incident lifecycle, containment actions, and notification timer matrix.
Data retention and deletion standardRetention classes, deletion controls, and legal hold handling model.
Readiness reportingProgram-level compliance audit reviewed October 2, 2026; the latest virtual-patch evidence is dated July 26, 2026.

Latest evidence refresh

The current public packet includes the October 2, 2026 compliance program audit, the governance-register baseline, and dated fleet-readiness and virtual-patch evidence records. Each record states its own scope and date.

Audit resultCompliance program audit recorded 59 passes, 5 manual-evidence warnings, and 0 technical failures.
Threat coverageThe packet retains virtual-patch evidence dated July 26, 2026. Current source-of-truth rule counts are not restated without a complete authenticated collection.
Fleet readinessSeptember 27 closeout evidence verified ten serving POPs with fresh authenticated control evidence; Atlanta, New York, and Palo Alto remain non-public security holds.

Readiness is not an attestation. Draft governance baseline rows do not constitute owner-approved access reviews, risk assessments, vendor/subprocessor due diligence, RoPA or legal records, or signed BAA evidence; those five manual evidence areas remain warnings. ePHI is prohibited until required service-specific BAA coverage is verified.

Customer review support

For deeper diligence workflows, we provide customer-specific compliance documentation through secure support channels.

Security review packetControl descriptions, operational baselines, and readiness snapshot.
Legal artifact workflowContractual/legal documents are shared through authorized channels only.
Technical control walkthroughLive walkthrough of edge, routing, logging, and incident controls by request.
Origin lockdown reviewBypass-prevention checklist for customer onboarding, direct-origin exception review, and end-to-end TLS warning clearance.

Contact support through Help4 Network for client-specific compliance requests.