Snapshot 29707
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Handshake Trust Portal At Handshake, we're committed to delivering industry-leading privacy and security infrastructure with transparency. We ensure the information we receive is handled with care, and complies with all applicable standards, laws and regulations globally. Handshake’s commitment to protecting data privacy goes beyond basic compliance; we continuously evaluate and refine our processes and policies to lead the industry in responsible data stewardship, continuous employer screening, and full student control. Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation. Skip to main content Handshake Trust Portal At Handshake, we're committed to delivering industry-leading privacy and security infrastructure with transparency. We ensure the information we receive is handled with care, and complies with all applicable standards, laws and regulations globally. Handshake’s commitment to protecting data privacy goes beyond basic compliance; we continuously evaluate and refine our processes and policies to lead the industry in responsible data stewardship, continuous employer screening, and full student control. ⌘K OverviewDocumentationControlsService ProvidersUpdatesAI Features Loading content... Certifications Trusted by Disney TikTok McDonald's Target Box EY Johnson & Johnson IBM CDW Teach For America Contact supportReport a vulnerability Trust center by Wolfia: AI trust center & security questionnaire automation Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers Documentation Featured SOC 2 Type II Report PCI DSS Attestation of Compliance and Self-Assessment Questionnaire D Cloud Platform Architecture Diagram Web Application Penetration Testing Report Service Providers Amazon Web Services · United States Cloud Service Provider United States Anthropic · United States AI workflows United States Arize AI · United States Model observability for AI recommendations United States Bugsnag · United States Platform bug logging, detection and reporting United States Cloudflare · United States Security, performance and reliability services, video processing and distribution United States Controls Audit and compliance Independent certifications and continuous compliance demonstrate alignment with global security and privacy standards. SOC 2 Type II Attestation TX-RAMP certification UK Cyber Essentials GDPR compliance PCI SAQ-D compliance CCPA compliance EU-U.S. Data Privacy Framework Privacy and data protection Comprehensive policies and practices ensure personal data is handled in full compliance with GDPR and applicable regulations. Privacy Policy Lawful basis for processing Data Controller and Processor roles Student data control Data Protection Impact Assessments Data Protection Officer Data retention and deletion Purpose limitation and data minimisation Transparency of data processing Data security Encryption, backup and malware protection keep data confidential and resilient throughout its lifecycle. Encryption in transit Encryption at rest File upload security Malware protection Backup and data replication Log management Financial data security Frequently asked security questions Is Handshake secure? Handshake operates this public trust center. It publishes 10 independent compliance certifications, security documentation available on request, and a published list of its subprocessors. Is Handshake SOC 2 compliant? Yes. Handshake maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center. Who are Handshake's subprocessors? Handshake discloses its subprocessors in this trust center, including Amazon, Anthropic, and Arize AI. See the subprocessors section for the complete list. Where is Handshake data hosted? Handshake discloses its infrastructure and hosting subprocessors in this trust center, including Cloudflare. See the subprocessors section for details. How do I request Handshake's security documentation? You can request access to Handshake's security documentation directly through this trust center. Submit an access request and the Handshake team reviews and grants access. Contact supportReport a vulnerability Trust center by Wolfia: AI trust center & security questionnaire automation Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers Controls Audit and compliance Independent certifications and continuous compliance demonstrate alignment with global security and privacy standards. SOC 2 Type II Attestation Handshake is SSAE 18 SOC 2 Type II certified. The annual audit report can be shared upon request. TX-RAMP certification Handshake holds TX-RAMP certification, meeting the security requirements set by the State of Texas. UK Cyber Essentials Handshake is UK Cyber Essentials certified, demonstrating adherence to UK government-backed security standards. GDPR compliance Handshake adheres to all applicable data protection regulations including the General Data Protection Regulation (GDPR) for its European platform. PCI SAQ-D compliance Handshake maintains PCI compliance as a merchant, running quarterly scans and using a fully PCI compliant infrastructure stack. An AOC is available upon request. CCPA compliance Handshake is compliant with the requirements of the California Consumer Privacy Act (CCPA). EU-U.S. Data Privacy Framework Stryder Corp. dba Handshake is certified with the Department of Commerce as adhering to the EU-U.S. Data Privacy Framework, ensuring personal data transferred to the U.S. is handled with equivalent EU-level protections. Privacy and data protection Comprehensive policies and practices ensure personal data is handled in full compliance with GDPR and applicable regulations. Privacy Policy Handshake maintains a comprehensive Privacy Policy describing practices regarding the collection, use and storage of personal data processed by the platform. Lawful basis for processing Handshake only processes personal data where a valid legal basis exists under applicable data protection law, primarily performance of a contract, compliance with legal obligations, or legitimate interests. Data Controller and Processor roles When universities transfer personal data, the university acts as Controller and Handshake serves as Processor. Once a student claims their account, Handshake and the university act as Joint Controllers. Student data control Students retain full control over their personal data in accordance with GDPR. They can adjust profile visibility, privacy settings, and request erasure of their data at any time. Data Protection Impact Assessments Handshake conducts Data Protection Impact Assessments (DPIAs) for processing activities that may present a high risk to individuals' rights and freedoms, in line with GDPR regulatory guidance. Data Protection Officer Handshake has appointed Datenschutz Nord GmbH as DPO for Germany and a Group Data Protection Officer for the EMEA region, ensuring dedicated oversight of data protection obligations. Data retention and deletion Personal data is stored for as long as users utilise the platform. After account deletion, data is removed unless continued retention is required to fulfil legitimate interests or legal obligations. Users have the right to request deletion at any time. Purpose limitation and data minimisation Handshake processes personal data solely to deliver services to platform users. Data will never be sold to third parties or used for marketing without appropriate consent under GDPR or the ePrivacy Directive. Transparency of data processing Users are informed of Handshake's data processing practices through the Privacy Policy and Terms of Service upon registration, with transparency information shared in key sections of the platform. Data security Encryption, backup and malware protection keep data confidential and resilient throughout its lifecycle. Encryption in transit All data transmitted is encrypted using TLS 1.2 or higher, securing data exchanges among all platform users including students, employers, career services and Handshake staff. Encryption at rest All data at rest containing non-public information is encrypted using the industry-standard AES-256 encryption algorithm within the Google Cloud Platform infrastructure. File upload security Handshake applies antivirus checks on all file uploads, with access to uploaded files restricted to authorised users only. Malware protection Comprehensive anti-malware measures including Endpoint Protection through CrowdStrike Falcon and antivirus software safeguard all endpoints. Backup and data replication Platform data is replicated across multiple locations within the Western Europe region. Production databases are backed up daily, with backups retained for seven days and encrypted at the whole disk level. Log management Application server logs capture all user actions that prompt HTTPS requests, as well as administrative account activities. Access to these logs is strictly limited to specific members of the technical team. Financial data security Handshake does not manage, process, store or transmit sensitive financial information. Payment processing is handled through third-party integrations (Stripe, CashNet, TouchNet) with quarterly PCI scans. Access control Role-based permissions, SSO and least-privilege principles restrict data access to authorized users only. Role-based access control Handshake enforces strict access controls with predefined roles and specific permissions for different user groups (career services, students, employers), adhering to the principle of least-privilege. Single Sign-On (SSO) Handshake supports contemporary SSO solutions including SAML, SAML 2.0, Shibboleth, LDAP, CAS and TFA, facilitating secure platform access from any trusted identity provider. User access provisioning and deprovisioning Career services and employer interfaces allow for user role configuration as needed. Access to administrative interfaces is secured using TLS 1.2 and higher. Handshake administrators manage user registration and de-registration. Production infrastructure access Access to production infrastructure follows least and just-in-time privilege principles. Changes require explicit approval, are time-bound, and all access is audited and monitored. Device trust ensures access occurs solely from Handshake-managed devices. Quarterly access reviews User access reviews are conducted quarterly to verify the accuracy and validity of permissions, with the infrastructure team leader overseeing access and the security team auditing. Cloud security Google Cloud Platform hosting with certified data centers, network segmentation and continuous monitoring protect the infrastructure. Google Cloud Platform hosting The European platform is hosted on Google Cloud, leveraging GCP's certified facilities for data storage, system backups, server management and cloud management tools. GCP certifications Google Cloud Platform holds ISO 9001:2015, ISO 27001, ISO/IEC 27017, ISO/IEC 27018, ISO 22301:2019, ISO 50001:2018, ISO/IEC 27110, ISO/IEC 27701, SOC1/SOC2/SOC3, EU Cloud Code of Conduct and GDPR certifications. Network security architecture Multiple security zones place sensitive systems like database servers in highly trusted zones. Traffic between and within zones is regulated by firewalls ensuring only required ports and protocols are permitted. Network segregation Infrastructure on GCP uses Virtual Private Clouds (VPC), Application Load Balancers, Firewall Rules and Network Policies to isolate from external traffic and block unauthorised access. Network monitoring Network monitoring on GCP infrastructure is managed through global infrastructure monitoring. All logs are sent to a centralised logging service for monitoring, analysis and alerting. Physical security (shared responsibility) GCP maintains physical security controls at its data centers including multi-layered authentication, fire detection and suppression, redundant power supply, and climate controls for optimal equipment performance. Application security Secure development lifecycle, vulnerability scanning and penetration testing keep the software layer resilient. Secure development lifecycle Every piece of code undergoes a thorough review and approval process with separation of duties. Code security and dependency checks are performed before every deployment, including checks against OWASP Top 10 security risks. Vulnerability scanning An automated web scanning appliance is deployed on the pre-production platform, sending alerts on vulnerabilities before deployment. Regular scans are conducted every quarter. Static code analysis An automated system meticulously scans the codebase, identifying bugs, vulnerabilities, code smells and areas for improvement, ensuring software meets the highest standards. Penetration testing A leading third-party security firm performs external penetration tests of different scopes at least annually. The full scope of public-facing products are tested and reviewed at least once a year. Agile change management Development follows the Scrum/Agile framework with iterative sprints. Change management is directly integrated within the process, with all changes tracked by version control. Technical code review Every source code change undergoes peer code review, functional review and/or non-regression testing. Security-sensitive changes are flagged and reviewed by the security team. Environment separation Clear boundaries between development, testing, pre-production and live production environments using Virtual Private Clouds. Production data is never used in lower environments. Secure development environment GitHub Enterprise is used for code development, guaranteeing an appropriate level of confidentiality, availability, integrity and traceability. Source code access is heavily restricted. Web framework security controls Contemporary web frameworks (React, Ruby on Rails) with continuous security assessments against OWASP Top 10 reduce exposure to XSS, CSRF, SQL Injection and other common vulnerabilities. Patch management Infrastructure is consistently kept up-to-date through an infrastructure upgrade policy, minimising the need for emergency patching. Data storage and transfers EU-based data storage and certified transfer frameworks ensure data remains protected across jurisdictions. European data storage The European platform operates on Google Cloud with data storage located in Germany. Personal data collected via services is stored and processed within the EU or UK whenever feasible. International data transfers Handshake is certified under the EU-U.S. Data Privacy Framework. When data must be managed outside the UK and EU, all necessary measures ensure that data subjects continue to receive protection mirroring EU standards. Sub-processor management Third-party service providers are thoroughly vetted by the Privacy and Security team. All vendors are bound by confidentiality agreements and Data Processing Agreements (DPAs). A list of sub-processors is publicly available. Vendor risk management A well-defined vendor risk management program reviews the security posture of third-party services as part of procurement, limiting data transfer scope and ensuring comparable confidentiality and DPA requirements. Corporate governance Formal security policies aligned with SSAE18, NIST and ISO27001 guide organizational security strategy. Information Systems Security Policy (ISSP) Handshake has crafted an ISSP in collaboration with security management specialists, aligned with industry leading frameworks such as SSAE18, NIST and ISO27001. Management commitment to security General Management recognises the Information System as the backbone of operations and is committed to protecting data confidentiality, integrity and availability. Resources and means are dedicated to ensuring Handshake remains a trusted platform. Third-party relationships All third parties used for the platform and applications have been vetted and approved by the security team. All third parties are subject to security and privacy controls at least as strict as those imposed by customers, with mandatory confidentiality agreements. Employee security Screening, training, confidentiality agreements and least-privilege access keep the human layer secure. Hiring process controls Skills and education are verified for all hires. Handshake verifies education, previous employment and performs reference checks. Criminal background checks are conducted where permitted by law. Confidentiality agreements All employment contracts contain a Confidentiality and Non-Disclosure Agreement clause. Every employee signs a confidentiality agreement. Security awareness and training All new employees participate in initial information security and privacy awareness training during onboarding and annually thereafter. Training covers security best practices, workstation security, sensitive information management, attack vectors and GDPR. Technical security training Technical team members meet monthly to discuss security best practices, share resources and identify actions. Secure code trainings cover the OWASP Top 10 and other common attack vectors. Device monitoring and management Employee devices are monitored and managed through a mobile device management solution, ensuring consistent security posture across all corporate endpoints. Internal application access management Access to internal applications is granted on a need-to-know basis and revoked upon departure. All access requests require separation of duties and approvals. Sensitive application access is regularly audited with mandatory MFA. Okta SSO and passwordless authentication Employees use Okta for Single Sign-On with MFA. Handshake has adopted passwordless authentication and enforces device trust to ensure critical assets are accessible only on corporate devices. Password security Information Security Policy requires adherence to NIST 800-53b password standards. A password management solution enables complex password generation, limits reuse and allows secure sharing. Business continuity Robust backup, disaster recovery and high-availability architecture maintain service availability during disruptions. Business Continuity Plan A robust Business Continuity Plan (BCP) is in place, reviewed annually. All data centres are online with no cold standby. Core applications are deployed in N+1 configuration with automated failover. RTO < 24 hours, RPO < 6 hours. Information security continuity Critical infrastructure components (web servers, application servers, data-stores) are clustered with redundancy ensuring availability during system failures. Platform data is replicated across several geographical locations. Disaster recovery Infrastructure-as-code enables faster recovery in the event of a major disaster. Databases are restored automatically from snapshots to a point in time between zero and five minutes from the disaster. Configurations are used daily and continuously tested. Service availability Handshake is committed to 99.9% uptime backed by SLA guarantees. A dedicated engineering team with automated monitoring and on-call rotation ensures platform reliability around the clock. Content moderation and trust safety Proactive employer validation, flagging and content moderation protect the integrity of platform interactions. Employer validation The Trust and Safety team uses information from Sift and Google's WebRisk API to manually review and validate new employer accounts, requesting additional documentation including public platform evidence and partner institution endorsements. Employer flagging University partners and student users can report suspicious activity or abuse related to companies, users or job postings directly to the Trust and Safety team. Violations of Terms of Service may result in suspension with notification to all impacted parties. Content moderation and spam filtering Platform content is moderated by a dedicated Trust and Safety team, ensuring the integrity and safety of all platform interactions. Physical and asset security Encrypted workstations, premises access controls and network segmentation protect corporate assets. Workstation security All workstations are encrypted at the disk level and are protected using an industry-leading malware protection solution and endpoint management. Premises security Handshake premises are protected by individual identification badges and CCTV video surveillance. Office doors are locked before 7am, after 10pm and during weekends. Network security The internal network is protected by an industry-standard firewall with all incoming traffic forbidden by default. Network areas isolate different roles with printers and personal devices segregated from employee workstations. Documentation Featured SOC 2 Type II Report PCI DSS Attestation of Compliance and Self-Assessment Questionnaire D Cloud Platform Architecture Diagram Web Application Penetration Testing Report Certifications SOC 2 Type II Report Handshake Student Web VPAT PCI DSS Attestation of Compliance and Self-Assessment Questionnaire D PCI Shared Responsibility Summary Security Cloud Platform Architecture Diagram Web Application Penetration Testing Report Compliance NYC LL 144 EU-US DPF UK Extension to EU-US DPF Swiss-US DPF Policies Access Control Policy Acceptable Use Policy Human Resources Security Policy Network Security Policy Third-Party Risk Management Policy Software Development Lifecycle Policy Change Management Policy Incident Response Policy Endpoint Security Policy Vulnerability Management Policy Responsible Disclosure Policy Logging and Monitoring Policy Backup and Restoration Policy Vulnerability Management Guidelines Security Exceptions Policy Code of Conduct and Ethics Data Retention, Destruction, and Disposal Policy Physical Security Policy Information Security Policy Encryption Policy Business Continuity and Disaster Recovery Policy Data Classification Policy Risk Management Policy Asset Management Policy Privacy & Legal Privacy and Security Overview Global Service Providers Questionnaires HECVAT Solution Provider Response Standardized Information Gathering Questionnaire Third Party Risk Questionnaire Consensus Assessments Initiative Questionnaire The table below lists the Service Providers that Handshake engages to support the delivery of its products and services to Handshake Users. Handshake offers a range of products, and not all of the Service Providers listed below are involved in every product or data processing activity. This list is updated regularly to reflect any changes to Handshake's data processing practices. You can subscribe to the trust portal updates to be notified of changes to Handshake’s service providers. If you have any questions related to this list, please contact [email protected]. Amazon Web Services · United States Cloud Service Provider United States Anthropic · United States AI workflows United States Arize AI · United States Model observability for AI recommendations United States Bugsnag · United States Platform bug logging, detection and reporting United States Cloudflare · United States Security, performance and reliability services, video processing and distribution United States Cronofy · United States Synchronization of calendars between Career Services staff and Handshake United States Daily.co · United States In-app video technology United States Elastic.co · United States Search functionality across the Handshake platform United States Google Cloud Platform / Gemini · United States Cloud service provider; AI Workflows United States Iterable · United States Sending personalized emails United States LaunchNotes · United States Product Change Log and email updates to subscribers United States Looker · United States In-app analytics and reports to Educational Partners United States Mailgun · United States Sending emails via the platform United States Mapbox · United States Location-based searches United States Marketo · United States Marketing automation tool United States Merge · United States Employer ATS Integrations United States Omni · United States In-app analytics and reports to Educational Partners United States OpenAI · United States AI Workflows United States Temporal · United States Workflow orchestration engine United States Twilio · United States In-app video technology United States Zendesk · United States Help desk solution for support United States Loading content... Updates Overview