Trust

HNDOVR™ Security

What we actually run today — not a certificate badge.

  • AES-256 credential encryption

    Access logins stored in a HNDOVR™ are encrypted at rest with AES-256-GCM. Card numbers never sit in our database — Stripe takes payments.

  • TLS encrypted connections

    Production traffic is HTTPS, with HSTS. Sessions with Clerk and Checkout with Stripe stay on TLS.

  • MFA available

    Turn on multi-factor authentication in Clerk for your team. We recommend it on every production login.

  • Organisation isolation

    Installer, manufacturer and admin apps require sign-in. Records are scoped to your organisation. Memberships are owner, admin or member.

  • Handover activity logs

    Each HNDOVR™ keeps a timeline of sends, issues and services. Sign-in and payments also log in Clerk and Stripe. That is not a SIEM.

  • Hosted database backups

    Postgres and uploads persist on our Coolify host. We restore from host backups when needed. We do not quote an untested daily RPO.

  • UK GDPR controls

    UK company, UK GDPR policy and DSAR process. Processors may be outside the UK under IDTA/SCCs. Not a claim that every byte lives in a UK datacentre.

Legal

How we protect data

HNDOVR™ is a multi-tenant SaaS platform. We operate an ISMS aligned with ISO/IEC 27001:2022 and a PIMS aligned with ISO/IEC 27701:2025, and we use that as the basis for a CSA STAR Level 1 self-assessment. None of these is a certification.

Last updated: 19 August 2026