Helix Bank
Six weeks of audit evidence, rebuilt as a four-day export
Helix needed every security-relevant event to stay inside the EU, and needed to prove it to a regulator. The proof used to take a team of four six weeks. It now takes one person four days.
- Sector
- Retail banking
- Estate
- AWS + on-prem · 3,180 workloads · EU-only residency
- Regions
- eu-central-1, eu-west-3
- Plan
- Enterprise
- Customer since
- September 2023
- 4 daysAudit evidence packwas 6 weeks, four people, twice a year
- 100%Events never leaving the EUdedicated ingest, BYO-KMS, contractual residency
- 0DORA findingsoperational resilience review, January 2026
- 13 moHot retentionqueryable without a restore job
The regulator did not want a dashboard. They wanted to see the rule, the raw event it matched, and a signed statement that the event never crossed a border. Aegis is the first tool we have bought that could produce all three from one query.
Helix is a 1.4-million-customer retail bank with a hybrid estate and a regulator that reads carefully. Their problem was never detection coverage. It was that every good answer they had lived in a different system, and assembling those answers into something a supervisor would accept took four people six weeks, twice a year.
The residency requirement came first
Before anything else, Helix needed a hard guarantee: no security event — not a hash, not a sampled copy, not a metric derived from one — leaves the European Union. That ruled out most of the market, where “EU region” means the query layer runs in Frankfurt and the control plane does not.
What Helix bought instead is a dedicated ingest deployment in eu-central-1 with failover
to eu-west-3, encrypted under keys in Helix’s own KMS, with the residency written into
the contract rather than the marketing page. Aegis staff cannot read the data; support
sessions are screen-share only, initiated by Helix, and logged into the same event stream
as everything else.
What the evidence pack actually contains
A DORA operational resilience review wants to know that you detect a defined set of scenarios, that the detection works, and that you would notice if it stopped working. Helix answers that with three exports, all generated from the console:
- Coverage. Every detection, its source file, its Git history, and which of the seventeen mandated scenarios it maps to. Because detections are YAML in Helix’s own repository, the change history is already signed by the engineer who made it.
- Efficacy. Every situation opened in the period, with time-to-page, time-to-ack, and the raw normalised events that produced it. No sampling, no rollup.
- Liveness. The heartbeat record for every sensor and log source, at one-minute resolution, including the four outages Helix had and how long each one lasted.
The third one is the one auditors like and vendors hide. Helix had a 41-minute gap in on-prem flow collection in August. It is in the pack, with the ticket number.
The number that moved
January’s review closed with zero findings. The more useful measurement is that Marta’s team spent four days on it instead of six weeks — and the four days were spent reading the output rather than assembling it.