← Legal & Trust Center

Security & Data Protection

Version 1.0 · Effective 2026-10-01 · Awaiting final legal review

In short: How your information is protected, in plain English — and how to report a problem.

What we do

Encryption in transit (HTTPS) and at rest by our hosting provider. Every business's data is separated at the database level, so one customer can never read another's. Access is role-based and least-privilege; secret keys stay on the server. Rate limits and abuse checks protect sign-in and the free review. Administrative access is permission-controlled and logged. Backups are maintained by our hosting provider. We have a written incident-response process and will notify affected customers as the law requires.

What we do not claim

Handled does not currently hold SOC 2, ISO 27001, HIPAA or any other certification, and does not claim to.

Reporting a security issue

Please email [to be confirmed: privacy email] with “Security” in the subject. We welcome good-faith reports, will not take action against researchers who follow this policy, and ask you not to access other people's data or disrupt the service.