Third Party Index

Snapshot 29699

Document
Subprocessor list
URL
https://trust.joinhandshake.com/subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
1288662 bytes
SHA-256 (raw)
c4aab1b967c8b4a81167a9131996331ac046b83a8f8ce077fedeeb1816455e29
SHA-256 (normalized text)
d0abd12cf33c1f34e4fee2eddf0931233e95e1bd7f2bb2ff44b04594fa840549

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Handshake Trust Portal
At Handshake, we're committed to delivering industry-leading privacy and security infrastructure with transparency. We ensure the information we receive is handled with care, and complies with all applicable standards, laws and regulations globally. Handshake’s commitment to protecting data privacy goes beyond basic compliance; we continuously evaluate and refine our processes and policies to lead the industry in responsible data stewardship, continuous employer screening, and full student control.
Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.
Skip to main content
Handshake Trust Portal
At Handshake, we're committed to delivering industry-leading privacy and security infrastructure with transparency. We ensure the information we receive is handled with care, and complies with all applicable standards, laws and regulations globally.
Handshake’s commitment to protecting data privacy goes beyond basic compliance; we continuously evaluate and refine our processes and policies to lead the industry in responsible data stewardship, continuous employer screening, and full student control.
⌘K
OverviewDocumentationControlsService ProvidersUpdatesAI Features
Loading content...
Certifications
Trusted by
Disney
TikTok
McDonald's
Target
Box
EY
Johnson & Johnson
IBM
CDW
Teach For America
Contact supportReport a vulnerability
Trust center by Wolfia: AI trust center & security questionnaire automation
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Documentation
Featured
SOC 2 Type II Report
PCI DSS Attestation of Compliance and Self-Assessment Questionnaire D
Cloud Platform Architecture Diagram
Web Application Penetration Testing Report
Service Providers
Amazon Web Services · United States
Cloud Service Provider
United States
Anthropic · United States
AI workflows
United States
Arize AI · United States
Model observability for AI recommendations
United States
Bugsnag · United States
Platform bug logging, detection and reporting
United States
Cloudflare · United States
Security, performance and reliability services, video processing and distribution
United States
Controls
Audit and compliance
Independent certifications and continuous compliance demonstrate alignment with global security and privacy standards.
SOC 2 Type II Attestation
TX-RAMP certification
UK Cyber Essentials
GDPR compliance
PCI SAQ-D compliance
CCPA compliance
EU-U.S. Data Privacy Framework
Privacy and data protection
Comprehensive policies and practices ensure personal data is handled in full compliance with GDPR and applicable regulations.
Privacy Policy
Lawful basis for processing
Data Controller and Processor roles
Student data control
Data Protection Impact Assessments
Data Protection Officer
Data retention and deletion
Purpose limitation and data minimisation
Transparency of data processing
Data security
Encryption, backup and malware protection keep data confidential and resilient throughout its lifecycle.
Encryption in transit
Encryption at rest
File upload security
Malware protection
Backup and data replication
Log management
Financial data security
Frequently asked security questions
Is Handshake secure?
Handshake operates this public trust center. It publishes 10 independent compliance certifications, security documentation available on request, and a published list of its subprocessors.
Is Handshake SOC 2 compliant?
Yes. Handshake maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center.
Who are Handshake's subprocessors?
Handshake discloses its subprocessors in this trust center, including Amazon, Anthropic, and Arize AI. See the subprocessors section for the complete list.
Where is Handshake data hosted?
Handshake discloses its infrastructure and hosting subprocessors in this trust center, including Cloudflare. See the subprocessors section for details.
How do I request Handshake's security documentation?
You can request access to Handshake's security documentation directly through this trust center. Submit an access request and the Handshake team reviews and grants access.
Contact supportReport a vulnerability
Trust center by Wolfia: AI trust center & security questionnaire automation
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Controls
Audit and compliance
Independent certifications and continuous compliance demonstrate alignment with global security and privacy standards.
SOC 2 Type II Attestation
Handshake is SSAE 18 SOC 2 Type II certified. The annual audit report can be shared upon request.
TX-RAMP certification
Handshake holds TX-RAMP certification, meeting the security requirements set by the State of Texas.
UK Cyber Essentials
Handshake is UK Cyber Essentials certified, demonstrating adherence to UK government-backed security standards.
GDPR compliance
Handshake adheres to all applicable data protection regulations including the General Data Protection Regulation (GDPR) for its European platform.
PCI SAQ-D compliance
Handshake maintains PCI compliance as a merchant, running quarterly scans and using a fully PCI compliant infrastructure stack. An AOC is available upon request.
CCPA compliance
Handshake is compliant with the requirements of the California Consumer Privacy Act (CCPA).
EU-U.S. Data Privacy Framework
Stryder Corp. dba Handshake is certified with the Department of Commerce as adhering to the EU-U.S. Data Privacy Framework, ensuring personal data transferred to the U.S. is handled with equivalent EU-level protections.
Privacy and data protection
Comprehensive policies and practices ensure personal data is handled in full compliance with GDPR and applicable regulations.
Privacy Policy
Handshake maintains a comprehensive Privacy Policy describing practices regarding the collection, use and storage of personal data processed by the platform.
Lawful basis for processing
Handshake only processes personal data where a valid legal basis exists under applicable data protection law, primarily performance of a contract, compliance with legal obligations, or legitimate interests.
Data Controller and Processor roles
When universities transfer personal data, the university acts as Controller and Handshake serves as Processor. Once a student claims their account, Handshake and the university act as Joint Controllers.
Student data control
Students retain full control over their personal data in accordance with GDPR. They can adjust profile visibility, privacy settings, and request erasure of their data at any time.
Data Protection Impact Assessments
Handshake conducts Data Protection Impact Assessments (DPIAs) for processing activities that may present a high risk to individuals' rights and freedoms, in line with GDPR regulatory guidance.
Data Protection Officer
Handshake has appointed Datenschutz Nord GmbH as DPO for Germany and a Group Data Protection Officer for the EMEA region, ensuring dedicated oversight of data protection obligations.
Data retention and deletion
Personal data is stored for as long as users utilise the platform. After account deletion, data is removed unless continued retention is required to fulfil legitimate interests or legal obligations. Users have the right to request deletion at any time.
Purpose limitation and data minimisation
Handshake processes personal data solely to deliver services to platform users. Data will never be sold to third parties or used for marketing without appropriate consent under GDPR or the ePrivacy Directive.
Transparency of data processing
Users are informed of Handshake's data processing practices through the Privacy Policy and Terms of Service upon registration, with transparency information shared in key sections of the platform.
Data security
Encryption, backup and malware protection keep data confidential and resilient throughout its lifecycle.
Encryption in transit
All data transmitted is encrypted using TLS 1.2 or higher, securing data exchanges among all platform users including students, employers, career services and Handshake staff.
Encryption at rest
All data at rest containing non-public information is encrypted using the industry-standard AES-256 encryption algorithm within the Google Cloud Platform infrastructure.
File upload security
Handshake applies antivirus checks on all file uploads, with access to uploaded files restricted to authorised users only.
Malware protection
Comprehensive anti-malware measures including Endpoint Protection through CrowdStrike Falcon and antivirus software safeguard all endpoints.
Backup and data replication
Platform data is replicated across multiple locations within the Western Europe region. Production databases are backed up daily, with backups retained for seven days and encrypted at the whole disk level.
Log management
Application server logs capture all user actions that prompt HTTPS requests, as well as administrative account activities. Access to these logs is strictly limited to specific members of the technical team.
Financial data security
Handshake does not manage, process, store or transmit sensitive financial information. Payment processing is handled through third-party integrations (Stripe, CashNet, TouchNet) with quarterly PCI scans.
Access control
Role-based permissions, SSO and least-privilege principles restrict data access to authorized users only.
Role-based access control
Handshake enforces strict access controls with predefined roles and specific permissions for different user groups (career services, students, employers), adhering to the principle of least-privilege.
Single Sign-On (SSO)
Handshake supports contemporary SSO solutions including SAML, SAML 2.0, Shibboleth, LDAP, CAS and TFA, facilitating secure platform access from any trusted identity provider.
User access provisioning and deprovisioning
Career services and employer interfaces allow for user role configuration as needed. Access to administrative interfaces is secured using TLS 1.2 and higher. Handshake administrators manage user registration and de-registration.
Production infrastructure access
Access to production infrastructure follows least and just-in-time privilege principles. Changes require explicit approval, are time-bound, and all access is audited and monitored. Device trust ensures access occurs solely from Handshake-managed devices.
Quarterly access reviews
User access reviews are conducted quarterly to verify the accuracy and validity of permissions, with the infrastructure team leader overseeing access and the security team auditing.
Cloud security
Google Cloud Platform hosting with certified data centers, network segmentation and continuous monitoring protect the infrastructure.
Google Cloud Platform hosting
The European platform is hosted on Google Cloud, leveraging GCP's certified facilities for data storage, system backups, server management and cloud management tools.
GCP certifications
Google Cloud Platform holds ISO 9001:2015, ISO 27001, ISO/IEC 27017, ISO/IEC 27018, ISO 22301:2019, ISO 50001:2018, ISO/IEC 27110, ISO/IEC 27701, SOC1/SOC2/SOC3, EU Cloud Code of Conduct and GDPR certifications.
Network security architecture
Multiple security zones place sensitive systems like database servers in highly trusted zones. Traffic between and within zones is regulated by firewalls ensuring only required ports and protocols are permitted.
Network segregation
Infrastructure on GCP uses Virtual Private Clouds (VPC), Application Load Balancers, Firewall Rules and Network Policies to isolate from external traffic and block unauthorised access.
Network monitoring
Network monitoring on GCP infrastructure is managed through global infrastructure monitoring. All logs are sent to a centralised logging service for monitoring, analysis and alerting.
Physical security (shared responsibility)
GCP maintains physical security controls at its data centers including multi-layered authentication, fire detection and suppression, redundant power supply, and climate controls for optimal equipment performance.
Application security
Secure development lifecycle, vulnerability scanning and penetration testing keep the software layer resilient.
Secure development lifecycle
Every piece of code undergoes a thorough review and approval process with separation of duties. Code security and dependency checks are performed before every deployment, including checks against OWASP Top 10 security risks.
Vulnerability scanning
An automated web scanning appliance is deployed on the pre-production platform, sending alerts on vulnerabilities before deployment. Regular scans are conducted every quarter.
Static code analysis
An automated system meticulously scans the codebase, identifying bugs, vulnerabilities, code smells and areas for improvement, ensuring software meets the highest standards.
Penetration testing
A leading third-party security firm performs external penetration tests of different scopes at least annually. The full scope of public-facing products are tested and reviewed at least once a year.
Agile change management
Development follows the Scrum/Agile framework with iterative sprints. Change management is directly integrated within the process, with all changes tracked by version control.
Technical code review
Every source code change undergoes peer code review, functional review and/or non-regression testing. Security-sensitive changes are flagged and reviewed by the security team.
Environment separation
Clear boundaries between development, testing, pre-production and live production environments using Virtual Private Clouds. Production data is never used in lower environments.
Secure development environment
GitHub Enterprise is used for code development, guaranteeing an appropriate level of confidentiality, availability, integrity and traceability. Source code access is heavily restricted.
Web framework security controls
Contemporary web frameworks (React, Ruby on Rails) with continuous security assessments against OWASP Top 10 reduce exposure to XSS, CSRF, SQL Injection and other common vulnerabilities.
Patch management
Infrastructure is consistently kept up-to-date through an infrastructure upgrade policy, minimising the need for emergency patching.
Data storage and transfers
EU-based data storage and certified transfer frameworks ensure data remains protected across jurisdictions.
European data storage
The European platform operates on Google Cloud with data storage located in Germany. Personal data collected via services is stored and processed within the EU or UK whenever feasible.
International data transfers
Handshake is certified under the EU-U.S. Data Privacy Framework. When data must be managed outside the UK and EU, all necessary measures ensure that data subjects continue to receive protection mirroring EU standards.
Sub-processor management
Third-party service providers are thoroughly vetted by the Privacy and Security team. All vendors are bound by confidentiality agreements and Data Processing Agreements (DPAs). A list of sub-processors is publicly available.
Vendor risk management
A well-defined vendor risk management program reviews the security posture of third-party services as part of procurement, limiting data transfer scope and ensuring comparable confidentiality and DPA requirements.
Corporate governance
Formal security policies aligned with SSAE18, NIST and ISO27001 guide organizational security strategy.
Information Systems Security Policy (ISSP)
Handshake has crafted an ISSP in collaboration with security management specialists, aligned with industry leading frameworks such as SSAE18, NIST and ISO27001.
Management commitment to security
General Management recognises the Information System as the backbone of operations and is committed to protecting data confidentiality, integrity and availability. Resources and means are dedicated to ensuring Handshake remains a trusted platform.
Third-party relationships
All third parties used for the platform and applications have been vetted and approved by the security team. All third parties are subject to security and privacy controls at least as strict as those imposed by customers, with mandatory confidentiality agreements.
Employee security
Screening, training, confidentiality agreements and least-privilege access keep the human layer secure.
Hiring process controls
Skills and education are verified for all hires. Handshake verifies education, previous employment and performs reference checks. Criminal background checks are conducted where permitted by law.
Confidentiality agreements
All employment contracts contain a Confidentiality and Non-Disclosure Agreement clause. Every employee signs a confidentiality agreement.
Security awareness and training
All new employees participate in initial information security and privacy awareness training during onboarding and annually thereafter. Training covers security best practices, workstation security, sensitive information management, attack vectors and GDPR.
Technical security training
Technical team members meet monthly to discuss security best practices, share resources and identify actions. Secure code trainings cover the OWASP Top 10 and other common attack vectors.
Device monitoring and management
Employee devices are monitored and managed through a mobile device management solution, ensuring consistent security posture across all corporate endpoints.
Internal application access management
Access to internal applications is granted on a need-to-know basis and revoked upon departure. All access requests require separation of duties and approvals. Sensitive application access is regularly audited with mandatory MFA.
Okta SSO and passwordless authentication
Employees use Okta for Single Sign-On with MFA. Handshake has adopted passwordless authentication and enforces device trust to ensure critical assets are accessible only on corporate devices.
Password security
Information Security Policy requires adherence to NIST 800-53b password standards. A password management solution enables complex password generation, limits reuse and allows secure sharing.
Business continuity
Robust backup, disaster recovery and high-availability architecture maintain service availability during disruptions.
Business Continuity Plan
A robust Business Continuity Plan (BCP) is in place, reviewed annually. All data centres are online with no cold standby. Core applications are deployed in N+1 configuration with automated failover. RTO < 24 hours, RPO < 6 hours.
Information security continuity
Critical infrastructure components (web servers, application servers, data-stores) are clustered with redundancy ensuring availability during system failures. Platform data is replicated across several geographical locations.
Disaster recovery
Infrastructure-as-code enables faster recovery in the event of a major disaster. Databases are restored automatically from snapshots to a point in time between zero and five minutes from the disaster. Configurations are used daily and continuously tested.
Service availability
Handshake is committed to 99.9% uptime backed by SLA guarantees. A dedicated engineering team with automated monitoring and on-call rotation ensures platform reliability around the clock.
Content moderation and trust safety
Proactive employer validation, flagging and content moderation protect the integrity of platform interactions.
Employer validation
The Trust and Safety team uses information from Sift and Google's WebRisk API to manually review and validate new employer accounts, requesting additional documentation including public platform evidence and partner institution endorsements.
Employer flagging
University partners and student users can report suspicious activity or abuse related to companies, users or job postings directly to the Trust and Safety team. Violations of Terms of Service may result in suspension with notification to all impacted parties.
Content moderation and spam filtering
Platform content is moderated by a dedicated Trust and Safety team, ensuring the integrity and safety of all platform interactions.
Physical and asset security
Encrypted workstations, premises access controls and network segmentation protect corporate assets.
Workstation security
All workstations are encrypted at the disk level and are protected using an industry-leading malware protection solution and endpoint management.
Premises security
Handshake premises are protected by individual identification badges and CCTV video surveillance. Office doors are locked before 7am, after 10pm and during weekends.
Network security
The internal network is protected by an industry-standard firewall with all incoming traffic forbidden by default. Network areas isolate different roles with printers and personal devices segregated from employee workstations.
Documentation
Featured
SOC 2 Type II Report
PCI DSS Attestation of Compliance and Self-Assessment Questionnaire D
Cloud Platform Architecture Diagram
Web Application Penetration Testing Report
Certifications
SOC 2 Type II Report
Handshake Student Web VPAT
PCI DSS Attestation of Compliance and Self-Assessment Questionnaire D
PCI Shared Responsibility Summary
Security
Cloud Platform Architecture Diagram
Web Application Penetration Testing Report
Compliance
NYC LL 144
EU-US DPF
UK Extension to EU-US DPF
Swiss-US DPF
Policies
Access Control Policy
Acceptable Use Policy
Human Resources Security Policy
Network Security Policy
Third-Party Risk Management Policy
Software Development Lifecycle Policy
Change Management Policy
Incident Response Policy
Endpoint Security Policy
Vulnerability Management Policy
Responsible Disclosure Policy
Logging and Monitoring Policy
Backup and Restoration Policy
Vulnerability Management Guidelines
Security Exceptions Policy
Code of Conduct and Ethics
Data Retention, Destruction, and Disposal Policy
Physical Security Policy
Information Security Policy
Encryption Policy
Business Continuity and Disaster Recovery Policy
Data Classification Policy
Risk Management Policy
Asset Management Policy
Privacy & Legal
Privacy and Security Overview
Global Service Providers
Questionnaires
HECVAT Solution Provider Response
Standardized Information Gathering Questionnaire
Third Party Risk Questionnaire
Consensus Assessments Initiative Questionnaire
The table below lists the Service Providers that Handshake engages to support the delivery of its products and services to Handshake Users. Handshake offers a range of products, and not all of the Service Providers listed below are involved in every product or data processing activity. This list is updated regularly to reflect any changes to Handshake's data processing practices. You can subscribe to the trust portal updates to be notified of changes to Handshake’s service providers. If you have any questions related to this list, please contact [email protected].
Amazon Web Services · United States
Cloud Service Provider
United States
Anthropic · United States
AI workflows
United States
Arize AI · United States
Model observability for AI recommendations
United States
Bugsnag · United States
Platform bug logging, detection and reporting
United States
Cloudflare · United States
Security, performance and reliability services, video processing and distribution
United States
Cronofy · United States
Synchronization of calendars between Career Services staff and Handshake
United States
Daily.co · United States
In-app video technology
United States
Elastic.co · United States
Search functionality across the Handshake platform
United States
Google Cloud Platform / Gemini · United States
Cloud service provider; AI Workflows
United States
Iterable · United States
Sending personalized emails
United States
LaunchNotes · United States
Product Change Log and email updates to subscribers
United States
Looker · United States
In-app analytics and reports to Educational Partners
United States
Mailgun · United States
Sending emails via the platform
United States
Mapbox · United States
Location-based searches
United States
Marketo · United States
Marketing automation tool
United States
Merge · United States
Employer ATS Integrations
United States
Omni · United States
In-app analytics and reports to Educational Partners
United States
OpenAI · United States
AI Workflows
United States
Temporal · United States
Workflow orchestration engine
United States
Twilio · United States
In-app video technology
United States
Zendesk · United States
Help desk solution for support
United States
Loading content...
Updates
Service Providers