We only claim what we've actually done, standards we build to vs. certifications we hold are kept clearly apart.
Trust & honesty

Built compliance-first. Labelled honestly.

We design each product around recognised privacy, accessibility and security practices, and state the evidence level plainly. Every app is also labelled for what it actually is: Live, a Build, or a Demo. No badges we haven't earned.

Where we stand

Six standards, labelled for what they really are.

A standard we build to is not a certification we hold, so each card carries its honest status right up front.

๐Ÿ”

Data privacy, GDPR & India DPDP

A lawful basis for every purpose, consent on every form (recorded, not just ticked), a full privacy policy with named sub-processors, data-subject rights and defined retention. EU-facing apps add a ยง5 DDG Impressum.

Built to
โ™ฟ

Accessibility, WCAG 2.1 AA

Colour contrast, keyboard navigation, screen-reader labels, visible focus and reduced-motion support are part of our current build standard. We publish audit evidence when a product has an independent assessment.

Built to
๐Ÿ›ก๏ธ

App security, OWASP Top 10

Server-side validation, rate limiting, no secrets in the browser, security headers (CSP, HSTS), generic error pages and least-privilege multi-tenant isolation enforced with row-level security.

Built to
๐Ÿ“œ

SOC 2 & ISO 27001

We design to the SOC 2 and ISO 27001 control sets, but these are independent certifications that need an external auditor and an observation window. We have not obtained them yet, and we'll say so plainly until we do.

Roadmap, not yet certified
๐Ÿ”’

Privacy-first by default

Vercel provides aggregate first-party page analytics. Google Analytics and Microsoft Clarity are optional and load only after a visitor chooses to allow analytics. We do not use advertising pixels.

Built to
๐Ÿ’ณ

Card payments, PCI DSS

Our apps record cash, UPI, bank and cheque accounting and never store card data, so PCI DSS doesn't apply. If card payments are ever added, we use hosted checkout to stay in the smallest possible scope.

Out of scope
Our method

How every app is reviewed.

The same review loop is used before any product reaches a real customer.

  1. Build

    The app is built and must pass a clean production build first, no audit on broken code.

  2. Assess

    We assess the applicable privacy, accessibility, security and market requirements, then record the evidence and gaps.

  3. Remediate

    Findings are fixed in priority order, critical, then high, then medium, and the build is re-verified.

  4. Recheck & release

    A second pass confirms the fixes landed. We only describe an external audit or certification when independent evidence exists.

The rule

We only claim what we've actually done.

There's a real difference between a standard we build to and a certification we hold, and we keep the two clearly apart. You'll never see a SOC 2 or ISO badge on a HandelOS product until it's genuinely been certified.

The same rule applies to product status: Live means live, a Build means a real app that isn't public yet, and a Demo is a concept. See it applied on the apps page and in Built by us.

No badges we haven't earned. No status a product hasn't reached.
Ask us anything

Request our compliance summary.

We'll send the honest one-pager: what each app is built to, what's independently audited, and exactly where the certifications stand today.