Security & Data Protection
Version 1.0 · Effective 2026-10-01 · Awaiting final legal review
In short: How your information is protected, in plain English — and how to report a problem.
What we do
Encryption in transit (HTTPS) and at rest by our hosting provider. Every business's data is separated at the database level, so one customer can never read another's. Access is role-based and least-privilege; secret keys stay on the server. Rate limits and abuse checks protect sign-in and the free review. Administrative access is permission-controlled and logged. Backups are maintained by our hosting provider. We have a written incident-response process and will notify affected customers as the law requires.
What we do not claim
Handled does not currently hold SOC 2, ISO 27001, HIPAA or any other certification, and does not claim to.
Reporting a security issue
Please email [to be confirmed: privacy email] with “Security” in the subject. We welcome good-faith reports, will not take action against researchers who follow this policy, and ask you not to access other people's data or disrupt the service.