Security
Built for records that matter.
Board papers, registers and personal information need more care than most business data. Here is what Handholder does to protect them, in plain English.
01
Signing in
- Single sign-on
- Connect your identity provider over SAML, for example Microsoft Entra, so people sign in with their work account.
- Automatic provisioning
- With SCIM, accounts are created when someone joins and removed when they leave, straight from your directory.
- Sign in with Microsoft
- Teams on Microsoft 365 can sign in with the account they already use.
- Two-step login
- Require a code from an authenticator app in addition to a password.
- Session policy
- Each organisation sets its own maximum session length and idle timeout.
02
Your data
- Isolated at the database level
- Every organisation’s records are separated by row-level security in the database itself, not only in application code.
- Hosted in Sydney
- App servers and the database run in Sydney, Australia.
- Encrypted
- Data is encrypted in transit and at rest. Sensitive fields are encrypted again individually before they are stored.
- Daily backups
- Your database and uploaded files are backed up every day.
03
Accountability
- Audit log
- A permanent record of who changed what, and when, plus who opened each board paper. Entries can’t be edited or deleted through the app.
- Privacy export and erasure
- Respond to access and erasure requests with a built-in export and erasure process.
- Retention and legal hold
- Set how long records are kept, and place a legal hold to stop deletion while a matter is live.
- No trackers, no data sales
- No advertising or analytics trackers in the app. We don’t sell your data or use it for advertising.
Security questionnaire or DPA needed for your procurement team?
Contact us at admin@handholder.com.au and we will work through it with you.
Try it with your own security settings.
Turn on single sign-on, two-step login and session limits during your 14-day demo.