Handshake Bets is our demo environment — free test chips, real mechanics.

Live Platform

Security Policy

Last Updated: December 2, 2025

At Handshake Bets, Inc. ("Handshake"), security is our top priority. This Security Policy outlines the measures we implement to protect user data, financial information, and platform integrity. Our security practices comply with industry standards and regulatory requirements for financial technology platforms.

1. Our Security Commitment

Handshake is committed to:

  • Protecting user financial data and personally identifiable information
  • Maintaining platform availability and reliability
  • Preventing unauthorized access and fraud
  • Complying with financial services security standards
  • Continuously improving our security posture

2. Infrastructure Security

Backend-as-a-Service (BaaS) Platform

Handshake operates on Base44, a SOC 2 Type II certified Backend-as-a-Service platform that provides:

  • Enterprise-grade infrastructure security
  • Automated security patching and updates
  • 24/7 security monitoring and threat detection
  • Redundant backups and disaster recovery
  • Multi-factor authentication (MFA) for infrastructure access

What This Means:

Our infrastructure security is managed by certified professionals using industry-leading practices. We do not have direct access to the underlying servers where consumer financial data is processed, ensuring an additional layer of security.

3. Data Protection

Encryption

  • In Transit: All data transmitted between users and our servers is encrypted using TLS 1.3
  • At Rest: All stored data is encrypted using AES-256 encryption
  • Database: Production databases use encrypted storage with access controls

Payment Security

  • Bank account connections handled by Plaid (PCI-compliant payment processor)
  • We never store raw bank credentials or full account numbers
  • All financial transactions are tokenized and encrypted

Data Minimization

We collect only the minimum data necessary to provide our services. Sensitive data is automatically purged according to our Data Retention Policy.

4. Authentication & Access Control

User Authentication

  • OAuth 2.0 authentication via Base44
  • Secure session management with automatic timeout
  • Password hashing using industry-standard algorithms
  • Account lockout after multiple failed login attempts

Administrative Access

  • Role-Based Access Control (RBAC) for internal systems
  • Multi-factor authentication (MFA) required for admin accounts
  • All administrative actions are logged and audited
  • Principle of least privilege enforced

Infrastructure Access:

Our BaaS provider (Base44) handles infrastructure security and MFA for system-level access. We do not have direct access to production servers or databases outside of managed APIs.

5. Application Security

Secure Development Practices

  • Code reviews for all changes
  • Dependency scanning for known vulnerabilities
  • Input validation and sanitization
  • Protection against OWASP Top 10 vulnerabilities
  • Regular security testing and penetration testing

API Security

  • API keys stored in secure environment variables
  • Rate limiting to prevent abuse
  • Request authentication and authorization
  • CORS policies enforced

6. Security Monitoring & Incident Response

Continuous Monitoring

  • Real-time monitoring of platform activity
  • Automated alerts for suspicious behavior
  • Transaction monitoring for fraud detection
  • Uptime and performance monitoring

Incident Response Plan

In the event of a security incident, we follow a documented response plan:

  1. Detection: Immediate identification of security events
  2. Containment: Isolate affected systems to prevent spread
  3. Investigation: Determine scope and cause of incident
  4. Remediation: Fix vulnerabilities and restore services
  5. Notification: Inform affected users within 72 hours (if required by law)
  6. Post-Mortem: Document lessons learned and improve processes

Breach Notification:

We will notify affected users via email if a data breach occurs that may impact their personal or financial information, as required by applicable data protection laws.

7. Third-Party Service Providers

We carefully vet all third-party vendors and require them to meet our security standards:

Base44 (BaaS Platform)

SOC 2 Type II certified, handles infrastructure and database security

Plaid (Payment Processing)

PCI-compliant, bank-level security for financial connections

All third-party integrations are reviewed annually to ensure continued compliance with our security requirements.

8. User Security Responsibilities

Users play a critical role in maintaining security. Please:

  • Use strong, unique passwords
  • Never share your account credentials
  • Log out after each session on shared devices
  • Report suspicious activity immediately
  • Keep your email account secure (password reset vector)
  • Verify you're on the official Handshake domain before entering credentials

9. Compliance & Audits

Handshake adheres to the following security standards and regulations:

  • GDPR (General Data Protection Regulation) for EU users
  • CCPA (California Consumer Privacy Act) for California users
  • Bank Secrecy Act / Anti-Money Laundering (BSA/AML) requirements
  • Payment Card Industry Data Security Standard (PCI DSS) via Plaid

We conduct regular internal security audits and leverage our BaaS provider's annual SOC 2 audits to verify compliance.

10. Vulnerability Disclosure

If you discover a security vulnerability in Handshake, please report it responsibly:

Report To:

Email support@handshakebets.app with "SECURITY VULNERABILITY" in the subject line.

Please include detailed steps to reproduce the issue. We commit to responding within 48 hours.

We appreciate responsible disclosure and will acknowledge security researchers who help us improve platform security.

11. Policy Updates

This Security Policy is reviewed and updated annually, or more frequently as needed to address emerging threats and regulatory changes. Material changes will be communicated to users via email or platform notification.

Contact Us

Questions about our security practices? Contact:

Handshake Bets, Inc.

8 The Green Suite B

Dover, Delaware 19901

Email: support@handshakebets.app