Security
Protection designed into the service.
Last updated August 1, 2026
Cloud and data protection
Handspring runs on Amazon Web Services. Production traffic is encrypted in transit with HTTPS, stored service data is encrypted at rest using AWS-managed controls, and public assets are delivered through a content delivery network.
Identity and access
Administrative access uses managed authentication and role-based workspace permissions. Owners control membership and sensitive workspace actions. Service components use scoped identities, and customer workspaces are logically isolated by organization identifiers.
Operations
We monitor service errors, throttling, failed ingestion, and unusual operating conditions. Alerts and operational runbooks support investigation and recovery. We apply browser security headers and keep production secrets out of source code.
Customer controls
Workspace owners can export their organization’s data or request permanent deletion in the product. Customers should use unique credentials, remove former team members promptly, limit uploaded data to what is needed, and review assistant output before consequential use.
Report a concern
To report a suspected vulnerability or security incident, email contact@handspring.ai with enough detail for us to investigate. Please do not access, alter, or retain other users’ data while testing.
