Security Policy
Last Updated: December 2, 2025
At Handshake Bets, Inc. ("Handshake"), security is our top priority. This Security Policy outlines the measures we implement to protect user data, financial information, and platform integrity. Our security practices comply with industry standards and regulatory requirements for financial technology platforms.
1. Our Security Commitment
Handshake is committed to:
- Protecting user financial data and personally identifiable information
- Maintaining platform availability and reliability
- Preventing unauthorized access and fraud
- Complying with financial services security standards
- Continuously improving our security posture
2. Infrastructure Security
Backend-as-a-Service (BaaS) Platform
Handshake operates on Base44, a SOC 2 Type II certified Backend-as-a-Service platform that provides:
- Enterprise-grade infrastructure security
- Automated security patching and updates
- 24/7 security monitoring and threat detection
- Redundant backups and disaster recovery
- Multi-factor authentication (MFA) for infrastructure access
What This Means:
Our infrastructure security is managed by certified professionals using industry-leading practices. We do not have direct access to the underlying servers where consumer financial data is processed, ensuring an additional layer of security.
3. Data Protection
Encryption
- In Transit: All data transmitted between users and our servers is encrypted using TLS 1.3
- At Rest: All stored data is encrypted using AES-256 encryption
- Database: Production databases use encrypted storage with access controls
Payment Security
- Bank account connections handled by Plaid (PCI-compliant payment processor)
- We never store raw bank credentials or full account numbers
- All financial transactions are tokenized and encrypted
Data Minimization
We collect only the minimum data necessary to provide our services. Sensitive data is automatically purged according to our Data Retention Policy.
4. Authentication & Access Control
User Authentication
- OAuth 2.0 authentication via Base44
- Secure session management with automatic timeout
- Password hashing using industry-standard algorithms
- Account lockout after multiple failed login attempts
Administrative Access
- Role-Based Access Control (RBAC) for internal systems
- Multi-factor authentication (MFA) required for admin accounts
- All administrative actions are logged and audited
- Principle of least privilege enforced
Infrastructure Access:
Our BaaS provider (Base44) handles infrastructure security and MFA for system-level access. We do not have direct access to production servers or databases outside of managed APIs.
5. Application Security
Secure Development Practices
- Code reviews for all changes
- Dependency scanning for known vulnerabilities
- Input validation and sanitization
- Protection against OWASP Top 10 vulnerabilities
- Regular security testing and penetration testing
API Security
- API keys stored in secure environment variables
- Rate limiting to prevent abuse
- Request authentication and authorization
- CORS policies enforced
6. Security Monitoring & Incident Response
Continuous Monitoring
- Real-time monitoring of platform activity
- Automated alerts for suspicious behavior
- Transaction monitoring for fraud detection
- Uptime and performance monitoring
Incident Response Plan
In the event of a security incident, we follow a documented response plan:
- Detection: Immediate identification of security events
- Containment: Isolate affected systems to prevent spread
- Investigation: Determine scope and cause of incident
- Remediation: Fix vulnerabilities and restore services
- Notification: Inform affected users within 72 hours (if required by law)
- Post-Mortem: Document lessons learned and improve processes
Breach Notification:
We will notify affected users via email if a data breach occurs that may impact their personal or financial information, as required by applicable data protection laws.
7. Third-Party Service Providers
We carefully vet all third-party vendors and require them to meet our security standards:
Base44 (BaaS Platform)
SOC 2 Type II certified, handles infrastructure and database security
Plaid (Payment Processing)
PCI-compliant, bank-level security for financial connections
All third-party integrations are reviewed annually to ensure continued compliance with our security requirements.
8. User Security Responsibilities
Users play a critical role in maintaining security. Please:
- Use strong, unique passwords
- Never share your account credentials
- Log out after each session on shared devices
- Report suspicious activity immediately
- Keep your email account secure (password reset vector)
- Verify you're on the official Handshake domain before entering credentials
9. Compliance & Audits
Handshake adheres to the following security standards and regulations:
- GDPR (General Data Protection Regulation) for EU users
- CCPA (California Consumer Privacy Act) for California users
- Bank Secrecy Act / Anti-Money Laundering (BSA/AML) requirements
- Payment Card Industry Data Security Standard (PCI DSS) via Plaid
We conduct regular internal security audits and leverage our BaaS provider's annual SOC 2 audits to verify compliance.
10. Vulnerability Disclosure
If you discover a security vulnerability in Handshake, please report it responsibly:
Report To:
Email support@handshakebets.app with "SECURITY VULNERABILITY" in the subject line.
Please include detailed steps to reproduce the issue. We commit to responding within 48 hours.
We appreciate responsible disclosure and will acknowledge security researchers who help us improve platform security.
11. Policy Updates
This Security Policy is reviewed and updated annually, or more frequently as needed to address emerging threats and regulatory changes. Material changes will be communicated to users via email or platform notification.
Contact Us
Questions about our security practices? Contact: