Security Policy
Last Updated: February 8, 2026
At Handshake Bets, Inc. ("Handshake"), security is our top priority. This Security Policy outlines the measures we implement to protect user data and platform integrity for Handshake Clubs. Our security practices comply with industry standards and best practices for technology platforms.
1. Our Security Commitment
Handshake is committed to:
- Protecting user personal information and activity data
- Maintaining platform availability and reliability
- Preventing unauthorized access and fraud
- Complying with security best practices
- Continuously improving our security posture
2. Infrastructure Security
Backend-as-a-Service (BaaS) Platform
Handshake Clubs operates on Base44, a SOC 2 Type II certified Backend-as-a-Service platform that provides:
- Enterprise-grade infrastructure security
- Automated security patching and updates
- 24/7 security monitoring and threat detection
- Redundant backups and disaster recovery
- Multi-factor authentication (MFA) for infrastructure access
What This Means:
Our infrastructure security is managed by certified professionals using industry-leading practices. We leverage enterprise-grade security without the overhead of managing our own data centers.
3. Data Protection
Encryption
- In Transit: All data transmitted between users and our servers is encrypted using TLS 1.3
- At Rest: All stored data is encrypted using AES-256 encryption
- Database: Production databases use encrypted storage with access controls
Data Security
- User passwords are hashed using industry-standard algorithms
- Sensitive data is never logged or exposed in error messages
- Access to user data is restricted on a need-to-know basis
Data Minimization
We collect only the minimum data necessary to provide our services. Data is automatically purged according to our Data Retention Policy.
4. Authentication & Access Control
User Authentication
- OAuth 2.0 authentication via Base44
- Secure session management with automatic timeout
- Password hashing using industry-standard algorithms
- Account lockout after multiple failed login attempts
Administrative Access
- Role-Based Access Control (RBAC) for internal systems
- Multi-factor authentication (MFA) required for admin accounts
- All administrative actions are logged and audited
- Principle of least privilege enforced
Infrastructure Access:
Our BaaS provider (Base44) handles infrastructure security and MFA for system-level access. We do not have direct access to production servers or databases outside of managed APIs.
5. Application Security
Secure Development Practices
- Code reviews for all changes
- Dependency scanning for known vulnerabilities
- Input validation and sanitization
- Protection against OWASP Top 10 vulnerabilities
- Regular security testing
API Security
- API keys stored in secure environment variables
- Rate limiting to prevent abuse
- Request authentication and authorization
- CORS policies enforced
6. Security Monitoring & Incident Response
Continuous Monitoring
- Real-time monitoring of platform activity
- Automated alerts for suspicious behavior
- Activity monitoring for fraud detection
- Uptime and performance monitoring
Incident Response Plan
In the event of a security incident, we follow a documented response plan:
- Detection: Immediate identification of security events
- Containment: Isolate affected systems to prevent spread
- Investigation: Determine scope and cause of incident
- Remediation: Fix vulnerabilities and restore services
- Notification: Inform affected users within 72 hours (if required by law)
- Post-Mortem: Document lessons learned and improve processes
Breach Notification:
We will notify affected users via email if a data breach occurs that may impact their personal information, as required by applicable data protection laws.
7. Third-Party Service Providers
We carefully vet all third-party vendors and require them to meet our security standards:
Base44 (BaaS Platform)
SOC 2 Type II certified, handles infrastructure and database security
All third-party integrations are reviewed annually to ensure continued compliance with our security requirements.
8. User Security Responsibilities
Users play a critical role in maintaining security. Please:
- Use strong, unique passwords
- Never share your account credentials
- Log out after each session on shared devices
- Report suspicious activity immediately
- Keep your email account secure (password reset vector)
- Verify you're on the official Handshake domain before entering credentials
9. Compliance
Handshake adheres to the following security standards and regulations:
- GDPR (General Data Protection Regulation) for EU users
- CCPA (California Consumer Privacy Act) for California users
- SOC 2 compliance via our infrastructure provider
We conduct regular internal security reviews and leverage our BaaS provider's annual SOC 2 audits to verify compliance.
10. Vulnerability Disclosure
If you discover a security vulnerability in Handshake Clubs, please report it responsibly:
Report To:
Email support@handshakebets.app with "SECURITY VULNERABILITY" in the subject line.
Please include detailed steps to reproduce the issue. We commit to responding within 48 hours.
We appreciate responsible disclosure and will acknowledge security researchers who help us improve platform security.
11. Policy Updates
This Security Policy is reviewed and updated annually, or more frequently as needed to address emerging threats and regulatory changes. Material changes will be communicated to users via email or platform notification.
Contact Us
Questions about our security practices? Contact: