Security & trust

Security & trust center.

How we run Handshake.AI as a vendor: compliance roadmap, sub-processors, DPA on request, vulnerability disclosure, SLA, and pen-test policy. For evidence requests, security questionnaires, or anything not listed below, email info@handshake.ai.

Compliance roadmap

We're building toward the audit and assurance posture regulated buyers need. The list below shows what we're working on and where each item stands today.

WhatStatus
SOC2 Type I

In progress, controls drafted, audit firm engaged

SOC2 Type II

Observation period begins after the Type I report

ISO 27001

Planned

FedRAMP Moderate

Planned, sponsor engagement to follow

Sub-processors

Vendors that may process customer data on our behalf. The list below shows the categories we operate in; the current named vendor list is available on request and we notify customers under contract before adding a new sub-processor.

  • Cloud hosting / computeNamed list available on request
  • Managed databaseNamed list available on request
  • Object storage / backupsNamed list available on request
  • Observability / loggingNamed list available on request
  • Transactional emailNamed list available on request
  • Error monitoringNamed list available on request

Request the current named list: info@handshake.ai.

Data Processing Agreement (DPA)

A standard DPA is available on request and is signed before any production rollout that processes personal data. Email info@handshake.ai with your entity name and we'll send the current draft.

Vulnerability disclosure

Report security issues, including suspected vulnerabilities in the protocol, the SDKs, or our hosted services, to security@handshake.ai. We acknowledge within two business days, target initial triage within five, and will credit reporters in release notes by default unless you ask us not to. Please don't test against production tenants you don't own.

SLA summary

Hosted Registry availability target is 99.9% monthly for paid tiers, with credits issued against the affected month's fees. Receipt verification is offline by design and continues to function during Registry incidents, only DID document lookups and freshness checks against the Registry are affected. Full SLA terms are part of the master agreement and are shared alongside the DPA on request.

Pen-test policy

We engage a third-party firm for an annual penetration test against the hosted Registry and Console; the most recent executive summary is shared under NDA on request. Customers on Enterprise tiers may run their own coordinated penetration tests against a non-production tenant, contact security@handshake.ai to arrange scope and timing.

Signed: Handshake.AI · Last updated May 2026.

Looking for an active production rollout? Apply to be a design partner