Trust
HNDOVR™ Security
What we actually run today — not a certificate badge.
AES-256 credential encryption
Access logins stored in a HNDOVR™ are encrypted at rest with AES-256-GCM. Card numbers never sit in our database — Stripe takes payments.
TLS encrypted connections
Production traffic is HTTPS, with HSTS. Sessions with Clerk and Checkout with Stripe stay on TLS.
MFA available
Turn on multi-factor authentication in Clerk for your team. We recommend it on every production login.
Organisation isolation
Installer, manufacturer and admin apps require sign-in. Records are scoped to your organisation. Memberships are owner, admin or member.
Handover activity logs
Each HNDOVR™ keeps a timeline of sends, issues and services. Sign-in and payments also log in Clerk and Stripe. That is not a SIEM.
Hosted database backups
Postgres and uploads persist on our Coolify host. We restore from host backups when needed. We do not quote an untested daily RPO.
UK GDPR controls
UK company, UK GDPR policy and DSAR process. Processors may be outside the UK under IDTA/SCCs. Not a claim that every byte lives in a UK datacentre.
Legal
How we protect data
HNDOVR™ is a multi-tenant SaaS platform. We operate an ISMS aligned with ISO/IEC 27001:2022 and a PIMS aligned with ISO/IEC 27701:2025, and we use that as the basis for a CSA STAR Level 1 self-assessment. None of these is a certification.
Last updated: 19 August 2026
Report a vulnerability
Email security@hndovr.app (also info@hndovr.app). Please include steps to reproduce and avoid accessing other customers’ data. We aim to acknowledge within two business days.
Machine-readable contact: /.well-known/security.txt
Shared responsibility
HNDOVR™ secures the application, tenant isolation in our database, and the configuration of our processors. You secure your own logins (including enabling MFA in Clerk where available), who you invite, and who you send portal links to. Our hosting provider secures the underlying datacentre, hypervisor and physical access.
Application controls
- Installer, manufacturer and admin apps sit behind Clerk authentication. Organisation data is scoped by organisation ID in application queries.
- Customer portals use unguessable tokens. Recipients do not need an account. Treat the link as confidential.
- Customer access credentials stored in a HNDOVR™ are encrypted with AES-256-GCM. Production must set a dedicated
CREDENTIALS_ENCRYPTION_KEY. - Card payments are processed by Stripe Checkout / Stripe Connect. HNDOVR™ does not store card numbers.
- Stripe webhooks are verified with the signing secret before fulfilling bookings or spare parts orders.
- Ask HNDOVR™ / AI Helper answers from manuals and FAQs in your library — it does not send those questions to a third-party generative model.
- File uploads are stored on the application volume (S3-compatible object storage is optional). Paths are constrained to the upload root to prevent directory traversal.
- Responses include standard browser security headers (HTTPS HSTS, nosniff, referrer policy, framing controls except the public booking embed).
Subprocessors
- Clerk — identity and session management.
- Stripe — payments and Connect payouts, where a business enables them.
- Resend — transactional email, where configured.
- Our cloud host / Coolify — compute, TLS termination, PostgreSQL.
- Meta, LinkedIn or Google — only if you connect a social account in Marketing.
ISO/IEC 27001
We maintain an internal ISMS (scope, policy, risk register, statement of applicability, and operating procedures) aligned with ISO/IEC 27001:2022. ISO itself does not certify organisations. We are not ISO 27001 certified and we do not use the ISO logo. The truthful statement until an independent certification body issues a certificate is: security controls aligned with ISO/IEC 27001.
Certification, if we pursue it, requires a UKAS-accredited (or equivalent) certification body, evidence that the ISMS has been operated (reviews, access records, restore tests, incident handling), and a stage 1 / stage 2 audit. That is separate from CSA STAR Level 1.
ISO/IEC 27701
We maintain an internal privacy information management system aligned with ISO/IEC 27701:2025 (standalone PIMS; the 2019 edition was only an extension of 27001). We are not ISO 27701 certified. Do not read this page as a certificate. The truthful statement is: privacy management aligned with ISO/IEC 27701. Detail for people whose data we process is in the Privacy Policy.
HNDOVR™ is typically the controller of installer account data and the processor of homeowner data inside a customer’s HNDOVR™. That split is what enterprise security questionnaires usually want.
CSA STAR Level 1
STAR Level 1 is a complimentary CSA self-assessment. We complete the STAR Level 1 Security Questionnaire (CAIQ v4.1), mapped to CCM v4.1, and submit it to the STAR Registry. It is transparency, not an audit. We will not mark a control “yes” unless we operate it. The listing must be refreshed at least annually.
Submit via cloudsecurityalliance.org/star/submit using the CAIQ workbook (not the combined CCM+CAIQ reference spreadsheet). Optional Valid-AI-ted scoring is paid unless you are a CSA corporate member.
What this page does not claim
- ISO 27001, ISO 27701, or SOC 2 certification (STAR Level 2 typically sits on top of those audits).
- A penetration test or independent audit of these statements.
- Full-disk “AES-256 encrypted storage” of every file, a SIEM, daily encrypted backups with a published RPO, or data residency only in the UK.
- UK GDPR accountability is described in the Privacy Policy.