How Handled is designed to keep your documents safe. Handled is in active development; this describes how it's built and our commitments at launch.
Handled holds the paperwork you'd least like exposed. Legal, financial, personal. So security isn't a feature; it's the point. Our approach is defense-in-depth: a certified platform underneath, and least-privilege design on top.
Built on Base44
Handled runs on Base44, a fully managed application platform. That means Handled is built on SOC 2 Type II-audited and ISO 27001-certified infrastructure, with:
Encryption in transit and at rest, using industry-standard encryption.
Continuous monitoring, automatic patching, and managed backups.
Secure, threat-detected APIs and platform-level vulnerability scanning.
These certifications are Base44's, describing the infrastructure Handled is built on.
Your data stays yours
Built to keep your documents in your own cloud: Google Drive or Dropbox, inside a single "Handled" folder we add to but never reach beyond. This is coming soon. Until it's live, your documents are stored securely on Handled's own encrypted servers.
Once your own-cloud connection is live, we'll keep only metadata, a secure hash (SHA-256), and timestamps on our side. Never your files.
Your documents are processed only to organize them: never sold, and never used to train AI models.
No bank linking and no stored email passwords. You forward or scan only what you choose.
Access & accounts
Row-level security: your records are reachable by your account alone.
Sign in by email magic-link; we ask you to re-confirm before sensitive actions (like exporting a Records pack or granting emergency access).
Data minimization: we collect only what's needed.
One-tap export and delete, whenever you want them.
What we don't claim
Handled surfaces your own documents. It does not give medical, legal, or financial advice.
We keep tamper-evident, time-stamped records. We don't claim they are "court-admissible."
Handled has no health features at launch, is not a HIPAA-covered entity or “Business Associate,” and doesn't claim “HIPAA compliance.” If we ever add features for health-related information, they will be strictly opt-in with separate, explicit consent.
Reporting a vulnerability
Security researchers are welcome. If you believe you've found a vulnerability, please report it through our contact form and choose "Security report." See also our security.txt. We commit to an independent security review before launch and to responsible-disclosure handling.
Accessibility
We're building Handled to meet WCAG 2.2 AA: readable contrast, clear structure, keyboard support, and respect for reduced-motion. If something isn't working for you, tell us via the contact form.
Security is a shared responsibility and no system is perfectly secure, but Handled is designed so the most sensitive information is protected by default. This page describes our security approach and commitments; it is general information, not legal advice.