All systems operational

Trust is built with
evidence, not promises.

Every security control, compliance commitment, data practice, and uptime metric — documented and verifiable before you go live.

99.97%
Platform uptime
last 90 days
0
P0 incidents
in the last 90 days
7yr
Audit log retention
IRS-compliant recordkeeping
<2h
Median incident resolution
across all P0/P1 events

Security architecture

HandShake is built on infrastructure designed for regulated financial operations — not repurposed from a generic SaaS template.

🔒
Data Encryption
At rest and in transit
  • AES-256 encryption for all stored client data and deal records
  • TLS 1.3 enforced on every connection — no protocol fallback
  • Encryption keys managed separately from application data
  • Database-level encryption with automatic key rotation
✓ AES-256 + TLS 1.3
🛡️
Access Controls
Role-based, not trust-based
  • RBAC across all user types — Officers, Managers, Partners
  • Isolated permission scopes per role — no over-privileged accounts
  • SSO support with SAML 2.0 and OAuth 2.0
  • MFA mandatory on all accounts with deal-access permissions
✓ RBAC + MFA enforced
🔍
Penetration Testing
External verification, annually
  • Annual third-party penetration tests by independent security firm
  • Responsible disclosure / bug bounty program active
  • Critical findings remediated within 72 hours (P0 SLA)
  • !Full pentest report available to Enterprise customers under NDA
Annual external pentest
🏢
Infrastructure
SOC 2 Type II cloud
  • Hosted on SOC 2 Type II certified cloud infrastructure
  • Automatic failover across multiple availability zones
  • Daily encrypted backups with 30-day retention
  • Network-level DDoS mitigation and WAF protection
✓ SOC 2 Type II infra

Uptime and status

Exchange operations can't wait for maintenance windows. We publish reliability data publicly and carry contractual SLA commitments.

All systems operational
Last checked: just now · Updated every 60 seconds
99.97%
Platform uptime (90 days)
● Operational
99.9%
SLA commitment
● SLA backed
<2h
Median incident resolution
● Within SLA
0
P0 incidents (90 days)
● Clean
90-day uptime history — each bar is one day
Operational
Minor incident

Regulatory & legal posture

1031 exchanges are governed by IRS regulations and strict recordkeeping requirements. HandShake is built to support those requirements, not work around them.

📑
IRS Recordkeeping
All exchange records retained for 7 years to meet IRS audit requirements. Structured as court-admissible audit trails.
🏛️
RESPA Alignment
Partner referral and commission tracking structured to support RESPA disclosure requirements for real estate settlement services.
🔏
Data Residency
All customer data stored and processed in the United States. No cross-border data transfers for core exchange records.
📊
Audit Logging
Every user action, record modification, and system event is logged with timestamp, actor, and change diff. Tamper-evident log chain.
🤝
BAA Available
Business Associate Agreements available for organizations with HIPAA or NPI data considerations affecting exchange client profiles.
📜
DPA & Privacy
Data Processing Addendum available. Our Privacy Policy explains what we collect, how we use it, how long we keep it, and how to exercise your rights.

No hidden costs. Ever.

Your subscription price is your total cost. No per-transaction fees, no overage charges, no surprise add-ons.

ItemStarterGrowthEnterprise
Platform subscription
Per seat / month, billed annually
$49
$99
Custom
Deal volume fees
Charged per exchange record
None
None
None
Partner seats
Read-only partner portal access
Included
Unlimited
API access
REST API + webhooks
Included
Included
Data export
CSV, JSON, or API
Free
Free
Free
Setup & onboarding
White-glove migration
Included

All prices in USD. Annual billing. Monthly available at 15% premium. Full detail on the Pricing page →

What happens when something goes wrong

We define, classify, and respond to incidents on a documented timeline — and communicate proactively, not reactively.

Incident severity tiers
  • P0Platform-wide outage or data integrity risk — response in 15 min, target 4h resolution
  • P1Major feature degraded — response in 1h, target 8h resolution
  • P2Minor feature impacted — response in 4h, target 24h resolution
  • P3Cosmetic or low-impact — triaged in next sprint
Communication commitments
  • Status page updated within 15 minutes of a confirmed P0/P1
  • Affected customers notified via email within 30 minutes
  • Post-incident review published within 5 business days for P0 events
  • Root cause and remediation steps documented publicly

Questions about our security
or compliance posture?

Our team is available for security reviews, compliance calls, and vendor due diligence documentation.