At its core Helios is model-agnostic: every implementation defines its own information models. Your organization’s reality — not a vendor’s fixed data model — decides what exists in the platform and how it connects.
Each model supports the common attribute types, with pre-defined values and restrictions where control matters. Validation lives in the model, so quality is enforced at the point of entry — from any source.
Use relationships to describe how your data is actually connected: which person holds which clearance for which project, which system processes which information, which supplier delivers which component. Connect your HR, document, cloud and OT models into one graph — that connectedness is what lets a single control verify several regulations at once, and criticality derive from information classification.
Models can include taxonomies — governed, often hierarchical classification structures such as information-classification levels, organizational units, asset categories and control frameworks. Objects reference taxonomy values instead of free text, so classification stays consistent across every source and can drive derivation: a system’s criticality follows from the classification of the information it handles. Taxonomies are governed like everything else in Helios — changes go through approval and land in the audit trail.
The information model is not documentation — it is configuration. It drives API endpoints, data ingestion mappings, forms, processes and visualization. Change the model and the platform follows, in your own environment, without vendor development.
Governance, risk and security information in one connected graph, running in your own environment.
Contact information