Security

Built for records that matter.

Board papers, registers and personal information need more care than most business data. Here is what Handholder does to protect them, in plain English.

01

Signing in

Single sign-on
Connect your identity provider over SAML, for example Microsoft Entra, so people sign in with their work account.
Automatic provisioning
With SCIM, accounts are created when someone joins and removed when they leave, straight from your directory.
Sign in with Microsoft
Teams on Microsoft 365 can sign in with the account they already use.
Two-step login
Require a code from an authenticator app in addition to a password.
Session policy
Each organisation sets its own maximum session length and idle timeout.

02

Your data

Isolated at the database level
Every organisation’s records are separated by row-level security in the database itself, not only in application code.
Hosted in Sydney
App servers and the database run in Sydney, Australia.
Encrypted
Data is encrypted in transit and at rest. Sensitive fields are encrypted again individually before they are stored.
Daily backups
Your database and uploaded files are backed up every day.

03

Accountability

Audit log
A permanent record of who changed what, and when, plus who opened each board paper. Entries can’t be edited or deleted through the app.
Privacy export and erasure
Respond to access and erasure requests with a built-in export and erasure process.
Retention and legal hold
Set how long records are kept, and place a legal hold to stop deletion while a matter is live.
No trackers, no data sales
No advertising or analytics trackers in the app. We don’t sell your data or use it for advertising.

Security questionnaire or DPA needed for your procurement team?

Contact us at admin@handholder.com.au and we will work through it with you.

Try it with your own security settings.

Turn on single sign-on, two-step login and session limits during your 14-day demo.