Built from day one for healthcare, education, and legal interpreting, where the data is sensitive and the auditors are real.
Hosted on SOC 2-certified cloud infrastructure with managed compute and managed databases. Physical security, network isolation, and 24/7 monitoring are handled at the platform level.
Every byte of data stored is encrypted with AES-256. Database volumes, backups, and object storage all use provider-managed encryption keys.
All data in transit is encrypted with TLS 1.2 or higher. API calls, browser sessions, and internal service communication are all encrypted.
Continuous encrypted backups with point-in-time recovery. If something goes wrong, we can restore to any moment in the retention window.
Managed database high availability with automatic failover. Designed for uptime, not compliance checkboxes.
Granular RBAC with distinct roles for agency admins, schedulers, interpreters, customers, and deaf consumers. Each role sees exactly what it should and nothing more.
Every database query is scoped to the user's role and organization at the Postgres level. This isn't application-layer filtering. It's enforced by the database engine itself.
Separate database users for migrations and application queries. The application user cannot alter schema, and migration credentials are never available at runtime.
Secure session handling with configurable expiration. Multi-factor authentication support so organizations can enforce strong identity verification.
Every data access and modification is recorded in append-only audit logs. Records can't be edited or deleted. Immutable by design.
Every audit event captures who did what, to which record, and exactly when. Full traceability from user action to database row.
Audit trails meet HIPAA requirements for PHI access logging. Every view, export, or modification of protected health information is captured and retained.
Infrastructure and application monitoring with automated alerting. We know about issues before users do.
Encryption, audit logs, access controls, and breach notification procedures designed for HIPAA compliance. Business Associate Agreement available on request.
Cloud-hosted on SOC 2-certified providers with centralized logging, monitoring, and access controls aligned to the Trust Services Criteria.
Institutional isolation ensures student data stays within its organization. Strict access controls and educational-context data handling for K-12 and university interpreting.
DPA available for organizations that need contractual data protection commitments. We are transparent about how data is processed and where it lives.
Handshapes does not process your data through AI models. AI features work through MCP (Model Context Protocol) connections that your team controls, using your own AI provider.
MCP connections respect the same RBAC and RLS boundaries as every other part of the platform. AI assistants can only access what the connected user is authorized to see.
Organizations control whether MCP connections are enabled. Nothing is turned on by default. Agencies decide what automation they want and when.
Organization data is logically isolated in a multi-tenant architecture with strict boundaries. Row-level security ensures one organization can never access another's data.
Your data is yours. Full data export is available so you are never locked in. We believe in earning your business, not trapping it.
We maintain a public list of sub-processors at /subprocessors. You know exactly who handles your data and why.
Happy to discuss our security practices, provide documentation for your compliance team, or walk through our architecture.
[email protected]