Handled

Where your data is, and who can see it.

Handled is an internal preview. Customer security review and deployment verification are incomplete.

Where it lives

Our current database and attachment storage are in the EU. Transactional email uses SendGrid’s standard global service, which may process data outside the EU. We do not promise EU-only processing. Backup and provider-contract reviews remain incomplete.

Who can see it

Between companies

Each company's data is separated by the database itself, not by our code remembering to ask for the right rows. Every request runs as a restricted user that the database will not let read outside one company, and the service checks this is actually working every time it starts — if it is not, it refuses to run rather than serve anyone.

We say this specifically because "isolated" is easy to claim and easy to get wrong. During development we found that this protection was doing nothing, because the service was connecting with too much privilege. We fixed it, and then made the service prove it at every start so the same mistake cannot come back quietly.

Inside your company: Public or Private

Public work is visible across your company. Private work is visible only to its author and current subject owners. Replies and attachments follow the same rule. Administrators have no automatic reader exception.

Before a private request has a subject, only its author can read it. Ownership changes update access. Disconnected devices receive access changes when they reconnect. This is access control, not end-to-end encryption.

Signing in

A link sent to your email address. The link works once and expires in fifteen minutes. We store a one-way fingerprint of the email link. This protects the link itself; session storage and other access risks still require security review.

Google and Microsoft sign-in require configured credentials and release verification. There is no application-level second factor or company single sign-on yet.

The routing

Connected routing can use a configured language model. It can receive the current request, responsibility information and relevant explicit correction examples from public work. Private items are excluded from company-wide correction learning. A private request can still be processed by the configured routing provider. The local preview uses a built-in matcher.

The provider must not train on customer data. Its processing locations must be disclosed before customer use. Every decision is logged with its explanation, so we can always answer "why did this come to me?".

Not done yet. These provider terms are not signed. Until they are, no customer data goes anywhere near them. This is a condition of anyone using Handled for real work, not an intention.

Your data is yours

What is not built yet

We would rather list this than have you find it.

If something goes wrong

We contain it, work out what was affected from our audit records, notify the authorities within 72 hours where we are required to, tell you without delay, and then write publicly about what happened. In that order.