Skip to content
Register interest
Records from Gmail, Google Drive, Calendar, HubSpot, GitHub and a finance database travel to Helios, which sits between them and Claude, ChatGPT, Cursor and in-house agents. As each record passes through, Helios passes it, masks its sensitive fields, or blocks it, depending on what each person's agent may see.

Early access for enterprise teams

One governed layer between your company's data and every AI tool.

Connect Google Workspace, your CRM, GitHub and internal databases once. Every AI tool gets only what each person may see.

What is Helios?

Helios is a governed access layer between a company's data sources and the AI tools its people use. Each source is connected once. Claude, ChatGPT, Cursor and in-house agents connect to Helios over MCP (Model Context Protocol) or REST and act as the signed-in person, receiving only the records and fields that person's role allows. Every call is audited.

Last updated

Why do AI tools need a governed layer?

Every AI tool your company adopts asks for the same thing on day one: a key to your data. The keys multiply faster than anyone can review them.

48separate grants when each tool connects directly, each with its own review and revocation
14connections through Helios, governed by one set of role policies

Every tool holds its own key

Each AI tool asks for its own OAuth grant to Gmail, Drive or the CRM. Eight tools and six sources is 48 grants, each reviewed, rotated and revoked separately.

No tool knows your org chart

A grant opens everything the account can see. Nothing stops a recruiting agent from reading payroll threads or a sales copilot from pulling HR notes.

Source APIs pay for the sprawl

Every tool polls the same mailboxes, calendars and pipelines on its own schedule, and Google and HubSpot start answering with rate-limit errors.

How does Helios work?

Four steps, done once per company. After that, adding an AI tool takes one URL and a sign-in.

  1. Connect each source once

    People sign in with their company account and approve each source a single time. Helios stores every grant encrypted and never hands it to an AI tool.

  2. Bring the policies you already have

    Roles come from your Google Workspace directory and Jamf. Start from eight role templates, adjust them, and assign them by dragging. Admin changes always win over automatic ones.

  3. Connect any AI tool by URL

    Add one MCP address to Claude, ChatGPT, Cursor or your own agent and sign in with OAuth. Agents that cannot speak MCP use the REST API or a bootstrap link.

  4. Every answer filtered and audited

    Each record is passed, masked or blocked according to the person's role before it leaves Helios. Every call is written to one audit trail with the person, agent and account.

What does each AI agent actually see?

Every role policy has an access level. Each class of data, from contact details to deal values, is passed, masked or blocked at each level before it leaves Helios. Pick an agent to compare.

Whose agent is asking

HubSpot contact

as returned to the support rep's agent

Name
Dana W.
Masked
Email
d•••@northwind.com
Masked
Phone
+1 ••• ••• 0142
Masked
Deal value
$100k to $250k
Masked
Notes
Asked for a payment plan
Passed

What's in Helios

Built for data that lives in SaaS tools and belongs to individual people.

Acts only as the signed-in person

No service accounts, bot identities or shared keys. An agent can never see more than the person it works for.

Content screened by meaning

Payslips, medical matters and personal threads are blocked. One-on-ones and HR discussion arrive tagged private. If screening is unavailable, nothing is relayed.

Policies from your org chart

Titles and departments from the Google directory and Jamf groups map people to role policies automatically, daily and for every new joiner.

Three switches on every tool

A tool runs only when the role policy, the person's own setting and the calling token all allow it. Each is set by a different person for a different reason.

hubspot.search_deals runs

Pass, mask or block each field

Contact details, deal values, account numbers and IDs are passed, masked or blocked by access level before data leaves Helios.

One read, many subscribers

A source is read once and served to every agent allowed to see it, so load on Google, HubSpot and internal APIs grows with sources, not agents.

Events, not polling

Agents subscribe to new mail, calendar changes, shared files, chat mentions, pull requests and failed builds, delivered by signed webhook or queue. The event sources are set up for each deployment.

Discovery that scales

Agents call find_server, then find_tools for that server. About 500 tokens of tool definitions, however many sources you connect.

How do agents connect?

Over MCP (Model Context Protocol) or REST. Agents see four tools: find_server, find_tools, call_tool and call_write_tool. That is about 500 tokens of definitions, however many sources you connect.

An agent finding and using a CRM toolMCP
# Connect once, from any MCP client
$ claude mcp add --transport http helios https://helios.yourcompany.com/mcp

# 1. Find the server that can answer
find_server  { "query": "deals closing this quarter" }
→ [{ "id": "srv_7f2", "name": "hubspot-sales" }, { "id": "srv_c40", "name": "finance-dw" }]

# 2. Ask that server for tools
find_tools   { "server_id": "srv_7f2", "query": "deals by close date" }
→ [{ "name": "hubspot.search_deals" }, { "name": "hubspot.get_deal" }]

# 3. Run it, as the signed-in person
call_tool    { "name": "hubspot.search_deals", "arguments": { "close": "this_quarter" } }
→ { "deals": 14, "masked": ["amount"], "blocked": { "not_relevant": 2 } }

What will your security team ask?

The short answers. We share the full architecture during discovery.

Identity
MCP clients sign in with OAuth 2.1 and PKCE. Access tokens are ES256-signed and last one hour. Revoking a connection stops it on its next request.
Credentials
Source grants are encrypted at rest and never leave Helios. Agent tokens are stored only as SHA-256 hashes and shown once.
Data handling
Screening and masking happen before data leaves Helios. When the screening service cannot decide, the result is blocked rather than relayed.
Audit
Every call records the person, the agent or app, the account that acted, the tool, masked arguments, duration and outcome. Filter by any of them.

Helios vs. connecting each AI tool directly

How access works when each AI tool connects to each source directly, compared with connecting through Helios
AspectConnecting each AI tool directlyThrough Helios
CredentialsEvery tool holds its own grant to every sourceEach source connected once; tools never hold a grant
Access policyWhatever the account can seeRole policies from your directory, enforced on every call
Sensitive fieldsReturned in fullPassed, masked or blocked by access level
AuditScattered across vendors, if it existsOne trail: person, agent, account, tool and result
Load on source APIsGrows with every toolOne read serves every allowed subscriber
Adding an AI toolNew grants, new review, new policy workOne URL and a sign-in
Revoking accessPer tool, per sourceOne switch, effective on the next request

Frequently asked questions

What is Helios?

Helios is a governed access layer between a company's data sources and the AI tools its people use. Each source is connected once. Claude, ChatGPT, Cursor and in-house agents connect to Helios over MCP (Model Context Protocol) or REST and act as the signed-in person, receiving only the records and fields that person's role allows. Every call is audited.

How is Helios different from an MCP gateway?

An MCP gateway routes agent calls to services. Helios also decides what each person may see: it acts as the signed-in person, applies role policies imported from your directory, masks or blocks sensitive fields, and audits every call. It is built for data that lives in SaaS tools and belongs to individual people.

Which data sources does Helios connect to?

Helios connects to the sources each company uses. Helios already connects Google Workspace (Gmail, Calendar, Drive, Chat, contacts and the directory), HubSpot CRM and GitHub. Each enterprise deployment is set up for that company's own sources, such as other CRMs, marketing platforms and internal databases.

Which AI tools work with Helios?

Any MCP client that supports OAuth sign-in, including Claude, ChatGPT and Cursor, plus your own agents. Agents that cannot use MCP can call the REST API or follow a bootstrap link.

How does field-level masking work?

Every role policy has an access level, and every class of data has an action at each level: pass, mask or block. A support rep's agent might see a contact as "Dana W." with a masked phone number, while the account owner's agent sees the full record and an external partner's agent sees nothing.

Who decides what each AI tool can see?

Admins assign role policies, which can be imported from the Google directory and Jamf. Each person can switch tools off for the agents acting for them, and each connection can be narrowed further. A tool runs only when all three allow it, and admin decisions always override automatic ones.

Does Helios reduce load on Google, HubSpot and internal APIs?

Yes. Helios reads each source once and serves the result to every agent allowed to see it, so the number of calls grows with the number of sources rather than the number of AI tools.

How do we get access?

Helios is in early access for enterprise teams. Register interest with the sources and AI tools you want to connect first, and the Techjays team will arrange a discovery call to scope your deployment: which sources and AI tools to connect, and whether Helios runs on your premises or as a managed service.

Register interest

We're onboarding a small number of enterprise teams. Tell us what you would connect first, and we'll come back with a deployment plan for your sources and AI tools.

  • A deployment plan for the sources and AI tools you name
  • The full architecture for your security review
  • A reply from the Techjays team at your work email

We only contact work addresses.

What would you connect first? (optional)
Which AI tools do your people use? (optional)

We use these details only to contact you about Helios.