# Helmhouse > Helmhouse builds private native apps (iPhone, backed by the engineer's Mac or connected directly to systems of record) around the work an engineering team owns. Tagline: "Leave the desk. Keep command." Contact: contact@helmhouse.io. Helmhouse turns a team's runbook into a "run-app": a purpose-built native product that brings live context, approved access, diagnosis and guarded actions into one place, so engineers and service owners can investigate and act from their phone. ## What Helmhouse builds - **Type A, the Personal Bridge**: one engineer, every tool. A private companion app that connects the tickets, code, telemetry, coding agents and access already living on the engineer's Mac (Jira, GitHub, Datadog, Claude Code, AWS SSO, VPN). Example: a ticket becomes a loaded coding-agent session in one tap. - **Type B, the Service Cockpit**: one system, every answer. A domain-specific console for the people responsible for one critical service (health, approvals, delivery, fleet, code, diagnosis), built around its operating questions rather than vendor boundaries. ## Capabilities - Connect context: join tickets, code, reviews, telemetry and local repos so the next step starts with context assembled. - Focus attention: a consequence-ranked queue of approvals, failures and expiring decisions. - Explain consequence: trace a failure through environments, versions, customers, messages and queues to its impact. - Guard actions: approve or reject deployments, run or retry pipelines, renew access, start sessions, connect tunnels, with confirmation where risk demands it. - Compare reality: requested vs deployed versions, commits, checks, configuration drift, shareable briefs. - Work through failure: loading, offline, expired-access and partial-data states designed around the operator's next safe move. ## Trust models - **Mac-mediated (Type A)**: work credentials stay on the Mac; the phone stores no tokens; Helmhouse's relay routes end-to-end sealed frames it cannot read or forge. - **Phone-direct (Type B)**: the app signs in to systems directly; credentials live only in its private Keychain group; a native VPN reaches internal resources; no Helmhouse backend sits in the data path. - Principles: least authority, native security (Keychain, device identity, network extensions), auditable writes, honest documented boundaries. ## Links - [Homepage](https://helmhouse.io/): overview, the two app types, capabilities and trust models - [Full text](https://helmhouse.io/llms-full.txt): complete page copy in plain text - Contact: contact@helmhouse.io ## Company Private native software for engineering departments. Copyright 2026 Helmhouse.