We only claim what we've actually done — standards we build to vs. certifications we hold are kept clearly apart.
Trust & honesty

Built compliance-first. Labelled honestly.

Every HandelOS app is built to recognised privacy, accessibility and security standards — and independently audited before it goes live. And every app is labelled for what it actually is: Live, a Build, or a Demo. No badges we haven't earned.

Where we stand

Six standards, labelled for what they really are.

A standard we build to is not a certification we hold — so each card carries its honest status right up front.

🔐

Data privacy — GDPR & India DPDP

A lawful basis for every purpose, consent on every form (recorded, not just ticked), a full privacy policy with named sub-processors, data-subject rights and defined retention. EU-facing apps add a §5 DDG Impressum.

Built to

Accessibility — WCAG 2.1 AA

Colour-contrast, full keyboard navigation, screen-reader labels, visible focus and reduced-motion support. Our latest audited build scores full WCAG 2.1 AA.

Met on audited apps
🛡️

App security — OWASP Top 10

Server-side validation, rate limiting, no secrets in the browser, security headers (CSP, HSTS), generic error pages and least-privilege multi-tenant isolation enforced with row-level security.

Built to
📜

SOC 2 & ISO 27001

We design to the SOC 2 and ISO 27001 control sets, but these are independent certifications that need an external auditor and an observation window. We have not obtained them yet — and we'll say so plainly until we do.

Roadmap — not yet certified
🔒

Privacy-first by default

We use only cookieless, first-party analytics — aggregate page views, nothing more. No cookies, no cross-site tracking, no advertising pixels. Your business data is yours; it is never the product.

Met
💳

Card payments — PCI DSS

Our apps record cash, UPI, bank and cheque accounting and never store card data, so PCI DSS doesn't apply. If card payments are ever added, we use hosted checkout to stay in the smallest possible scope.

Out of scope
Our method

How every app is audited.

The same loop runs before any product reaches a real customer.

  1. Build

    The app is built and must pass a clean production build first — no audit on broken code.

  2. Audit

    An independent, skeptical readiness audit against the standards that apply to that product and its market.

  3. Remediate

    Findings are fixed in priority order — critical, then high, then medium — and the build is re-verified.

  4. Re-audit & sign off

    A second pass confirms the fixes actually moved the scores — no rubber-stamping — before anything ships.

The rule

We only claim what we've actually done.

There's a real difference between a standard we build to and a certification we hold — and we keep the two clearly apart. You'll never see a SOC 2 or ISO badge on a HandelOS product until it's genuinely been certified.

The same rule applies to product status: Live means live, a Build means a real app that isn't public yet, and a Demo is a concept. See it applied on the apps page and in Built by us.

No badges we haven't earned. No status a product hasn't reached.
Ask us anything

Request our compliance summary.

We'll send the honest one-pager: what each app is built to, what's independently audited, and exactly where the certifications stand today.