Handshake Trust Portal

At Handshake, we're committed to delivering industry-leading privacy and security infrastructure with transparency. We ensure the information we receive is handled with care, and complies with all applicable standards, laws and regulations globally. Handshake’s commitment to protecting data privacy goes beyond basic compliance; we continuously evaluate and refine our processes and policies to lead the industry in responsible data stewardship, continuous employer screening, and full student control.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Handshake Trust Portal
Header background

Handshake Trust Portal

At Handshake, we're committed to delivering industry-leading privacy and security infrastructure with transparency. We ensure the information we receive is handled with care, and complies with all applicable standards, laws and regulations globally.

Handshake’s commitment to protecting data privacy goes beyond basic compliance; we continuously evaluate and refine our processes and policies to lead the industry in responsible data stewardship, continuous employer screening, and full student control.

Audit and compliance

Independent certifications and continuous compliance demonstrate alignment with global security and privacy standards.

SOC 2 Type II Attestation

Handshake is SSAE 18 SOC 2 Type II certified. The annual audit report can be shared upon request.

TX-RAMP certification

Handshake holds TX-RAMP certification, meeting the security requirements set by the State of Texas.

UK Cyber Essentials

Handshake is UK Cyber Essentials certified, demonstrating adherence to UK government-backed security standards.

GDPR compliance

Handshake adheres to all applicable data protection regulations including the General Data Protection Regulation (GDPR) for its European platform.

PCI SAQ-D compliance

Handshake maintains PCI compliance as a merchant, running quarterly scans and using a fully PCI compliant infrastructure stack. An AOC is available upon request.

CCPA compliance

Handshake is compliant with the requirements of the California Consumer Privacy Act (CCPA).

EU-U.S. Data Privacy Framework

Stryder Corp. dba Handshake is certified with the Department of Commerce as adhering to the EU-U.S. Data Privacy Framework, ensuring personal data transferred to the U.S. is handled with equivalent EU-level protections.

Privacy and data protection

Comprehensive policies and practices ensure personal data is handled in full compliance with GDPR and applicable regulations.

Privacy Policy

Handshake maintains a comprehensive Privacy Policy describing practices regarding the collection, use and storage of personal data processed by the platform.

Lawful basis for processing

Handshake only processes personal data where a valid legal basis exists under applicable data protection law, primarily performance of a contract, compliance with legal obligations, or legitimate interests.

Data Controller and Processor roles

When universities transfer personal data, the university acts as Controller and Handshake serves as Processor. Once a student claims their account, Handshake and the university act as Joint Controllers.

Student data control

Students retain full control over their personal data in accordance with GDPR. They can adjust profile visibility, privacy settings, and request erasure of their data at any time.

Data Protection Impact Assessments

Handshake conducts Data Protection Impact Assessments (DPIAs) for processing activities that may present a high risk to individuals' rights and freedoms, in line with GDPR regulatory guidance.

Data Protection Officer

Handshake has appointed Datenschutz Nord GmbH as DPO for Germany and a Group Data Protection Officer for the EMEA region, ensuring dedicated oversight of data protection obligations.

Data retention and deletion

Personal data is stored for as long as users utilise the platform. After account deletion, data is removed unless continued retention is required to fulfil legitimate interests or legal obligations. Users have the right to request deletion at any time.

Purpose limitation and data minimisation

Handshake processes personal data solely to deliver services to platform users. Data will never be sold to third parties or used for marketing without appropriate consent under GDPR or the ePrivacy Directive.

Transparency of data processing

Users are informed of Handshake's data processing practices through the Privacy Policy and Terms of Service upon registration, with transparency information shared in key sections of the platform.

Data security

Encryption, backup and malware protection keep data confidential and resilient throughout its lifecycle.

Encryption in transit

All data transmitted is encrypted using TLS 1.2 or higher, securing data exchanges among all platform users including students, employers, career services and Handshake staff.

Encryption at rest

All data at rest containing non-public information is encrypted using the industry-standard AES-256 encryption algorithm within the Google Cloud Platform infrastructure.

File upload security

Handshake applies antivirus checks on all file uploads, with access to uploaded files restricted to authorised users only.

Malware protection

Comprehensive anti-malware measures including Endpoint Protection through CrowdStrike Falcon and antivirus software safeguard all endpoints.

Backup and data replication

Platform data is replicated across multiple locations within the Western Europe region. Production databases are backed up daily, with backups retained for seven days and encrypted at the whole disk level.

Log management

Application server logs capture all user actions that prompt HTTPS requests, as well as administrative account activities. Access to these logs is strictly limited to specific members of the technical team.

Financial data security

Handshake does not manage, process, store or transmit sensitive financial information. Payment processing is handled through third-party integrations (Stripe, CashNet, TouchNet) with quarterly PCI scans.

Access control

Role-based permissions, SSO and least-privilege principles restrict data access to authorized users only.

Role-based access control

Handshake enforces strict access controls with predefined roles and specific permissions for different user groups (career services, students, employers), adhering to the principle of least-privilege.

Single Sign-On (SSO)

Handshake supports contemporary SSO solutions including SAML, SAML 2.0, Shibboleth, LDAP, CAS and TFA, facilitating secure platform access from any trusted identity provider.

User access provisioning and deprovisioning

Career services and employer interfaces allow for user role configuration as needed. Access to administrative interfaces is secured using TLS 1.2 and higher. Handshake administrators manage user registration and de-registration.

Production infrastructure access

Access to production infrastructure follows least and just-in-time privilege principles. Changes require explicit approval, are time-bound, and all access is audited and monitored. Device trust ensures access occurs solely from Handshake-managed devices.

Quarterly access reviews

User access reviews are conducted quarterly to verify the accuracy and validity of permissions, with the infrastructure team leader overseeing access and the security team auditing.

Cloud security

Google Cloud Platform hosting with certified data centers, network segmentation and continuous monitoring protect the infrastructure.

Google Cloud Platform hosting

The European platform is hosted on Google Cloud, leveraging GCP's certified facilities for data storage, system backups, server management and cloud management tools.

GCP certifications

Google Cloud Platform holds ISO 9001:2015, ISO 27001, ISO/IEC 27017, ISO/IEC 27018, ISO 22301:2019, ISO 50001:2018, ISO/IEC 27110, ISO/IEC 27701, SOC1/SOC2/SOC3, EU Cloud Code of Conduct and GDPR certifications.

Network security architecture

Multiple security zones place sensitive systems like database servers in highly trusted zones. Traffic between and within zones is regulated by firewalls ensuring only required ports and protocols are permitted.

Network segregation

Infrastructure on GCP uses Virtual Private Clouds (VPC), Application Load Balancers, Firewall Rules and Network Policies to isolate from external traffic and block unauthorised access.

Network monitoring

Network monitoring on GCP infrastructure is managed through global infrastructure monitoring. All logs are sent to a centralised logging service for monitoring, analysis and alerting.

Physical security (shared responsibility)

GCP maintains physical security controls at its data centers including multi-layered authentication, fire detection and suppression, redundant power supply, and climate controls for optimal equipment performance.

Application security

Secure development lifecycle, vulnerability scanning and penetration testing keep the software layer resilient.

Secure development lifecycle

Every piece of code undergoes a thorough review and approval process with separation of duties. Code security and dependency checks are performed before every deployment, including checks against OWASP Top 10 security risks.

Vulnerability scanning

An automated web scanning appliance is deployed on the pre-production platform, sending alerts on vulnerabilities before deployment. Regular scans are conducted every quarter.

Static code analysis

An automated system meticulously scans the codebase, identifying bugs, vulnerabilities, code smells and areas for improvement, ensuring software meets the highest standards.

Penetration testing

A leading third-party security firm performs external penetration tests of different scopes at least annually. The full scope of public-facing products are tested and reviewed at least once a year.

Agile change management

Development follows the Scrum/Agile framework with iterative sprints. Change management is directly integrated within the process, with all changes tracked by version control.

Technical code review

Every source code change undergoes peer code review, functional review and/or non-regression testing. Security-sensitive changes are flagged and reviewed by the security team.

Environment separation

Clear boundaries between development, testing, pre-production and live production environments using Virtual Private Clouds. Production data is never used in lower environments.

Secure development environment

GitHub Enterprise is used for code development, guaranteeing an appropriate level of confidentiality, availability, integrity and traceability. Source code access is heavily restricted.

Web framework security controls

Contemporary web frameworks (React, Ruby on Rails) with continuous security assessments against OWASP Top 10 reduce exposure to XSS, CSRF, SQL Injection and other common vulnerabilities.

Patch management

Infrastructure is consistently kept up-to-date through an infrastructure upgrade policy, minimising the need for emergency patching.

Data storage and transfers

EU-based data storage and certified transfer frameworks ensure data remains protected across jurisdictions.

European data storage

The European platform operates on Google Cloud with data storage located in Germany. Personal data collected via services is stored and processed within the EU or UK whenever feasible.

International data transfers

Handshake is certified under the EU-U.S. Data Privacy Framework. When data must be managed outside the UK and EU, all necessary measures ensure that data subjects continue to receive protection mirroring EU standards.

Sub-processor management

Third-party service providers are thoroughly vetted by the Privacy and Security team. All vendors are bound by confidentiality agreements and Data Processing Agreements (DPAs). A list of sub-processors is publicly available.

Vendor risk management

A well-defined vendor risk management program reviews the security posture of third-party services as part of procurement, limiting data transfer scope and ensuring comparable confidentiality and DPA requirements.

Corporate governance

Formal security policies aligned with SSAE18, NIST and ISO27001 guide organizational security strategy.

Information Systems Security Policy (ISSP)

Handshake has crafted an ISSP in collaboration with security management specialists, aligned with industry leading frameworks such as SSAE18, NIST and ISO27001.

Management commitment to security

General Management recognises the Information System as the backbone of operations and is committed to protecting data confidentiality, integrity and availability. Resources and means are dedicated to ensuring Handshake remains a trusted platform.

Third-party relationships

All third parties used for the platform and applications have been vetted and approved by the security team. All third parties are subject to security and privacy controls at least as strict as those imposed by customers, with mandatory confidentiality agreements.

Employee security

Screening, training, confidentiality agreements and least-privilege access keep the human layer secure.

Hiring process controls

Skills and education are verified for all hires. Handshake verifies education, previous employment and performs reference checks. Criminal background checks are conducted where permitted by law.

Confidentiality agreements

All employment contracts contain a Confidentiality and Non-Disclosure Agreement clause. Every employee signs a confidentiality agreement.

Security awareness and training

All new employees participate in initial information security and privacy awareness training during onboarding and annually thereafter. Training covers security best practices, workstation security, sensitive information management, attack vectors and GDPR.

Technical security training

Technical team members meet monthly to discuss security best practices, share resources and identify actions. Secure code trainings cover the OWASP Top 10 and other common attack vectors.

Device monitoring and management

Employee devices are monitored and managed through a mobile device management solution, ensuring consistent security posture across all corporate endpoints.

Internal application access management

Access to internal applications is granted on a need-to-know basis and revoked upon departure. All access requests require separation of duties and approvals. Sensitive application access is regularly audited with mandatory MFA.

Okta SSO and passwordless authentication

Employees use Okta for Single Sign-On with MFA. Handshake has adopted passwordless authentication and enforces device trust to ensure critical assets are accessible only on corporate devices.

Password security

Information Security Policy requires adherence to NIST 800-53b password standards. A password management solution enables complex password generation, limits reuse and allows secure sharing.

Business continuity

Robust backup, disaster recovery and high-availability architecture maintain service availability during disruptions.

Business Continuity Plan

A robust Business Continuity Plan (BCP) is in place, reviewed annually. All data centres are online with no cold standby. Core applications are deployed in N+1 configuration with automated failover. RTO < 24 hours, RPO < 6 hours.

Information security continuity

Critical infrastructure components (web servers, application servers, data-stores) are clustered with redundancy ensuring availability during system failures. Platform data is replicated across several geographical locations.

Disaster recovery

Infrastructure-as-code enables faster recovery in the event of a major disaster. Databases are restored automatically from snapshots to a point in time between zero and five minutes from the disaster. Configurations are used daily and continuously tested.

Service availability

Handshake is committed to 99.9% uptime backed by SLA guarantees. A dedicated engineering team with automated monitoring and on-call rotation ensures platform reliability around the clock.

Content moderation and trust safety

Proactive employer validation, flagging and content moderation protect the integrity of platform interactions.

Employer validation

The Trust and Safety team uses information from Sift and Google's WebRisk API to manually review and validate new employer accounts, requesting additional documentation including public platform evidence and partner institution endorsements.

Employer flagging

University partners and student users can report suspicious activity or abuse related to companies, users or job postings directly to the Trust and Safety team. Violations of Terms of Service may result in suspension with notification to all impacted parties.

Content moderation and spam filtering

Platform content is moderated by a dedicated Trust and Safety team, ensuring the integrity and safety of all platform interactions.

Physical and asset security

Encrypted workstations, premises access controls and network segmentation protect corporate assets.

Workstation security

All workstations are encrypted at the disk level and are protected using an industry-leading malware protection solution and endpoint management.

Premises security

Handshake premises are protected by individual identification badges and CCTV video surveillance. Office doors are locked before 7am, after 10pm and during weekends.

Network security

The internal network is protected by an industry-standard firewall with all incoming traffic forbidden by default. Network areas isolate different roles with printers and personal devices segregated from employee workstations.