Security
High-level overview for customers and users. It is not a guarantee, audit report, or substitute for your own security review.
Our focus
hnndl is an authentication and single sign-on service. Protecting account credentials, sessions, and sign-in flows is central to how we build and operate the product.
Practices we emphasize
- Encrypted connections (HTTPS) for Service traffic
- Passwords stored using modern one-way hashing (not reversible encryption)
- Optional two-factor authentication (app or email codes)
- Session-based sign-in with controls aimed at reducing session abuse
- Email verification as part of account lifecycle
- Least-privilege separation between public site content and the API
Your responsibilities
Use a unique, strong password; enable two-factor authentication when available; keep recovery email access secure; and only approve sign-in or authorization prompts you expect. Relying Party operators should follow their own secure integration practices and protect any secrets used with hnndl.
Reporting a vulnerability
If you believe you have found a security issue in hnndl, please report it responsibly. Do not access data that is not yours or disrupt the Service. Contact security@hnndl.com with a clear description, steps to reproduce, and impact. We will review good-faith reports and aim to respond in a timely manner.
Related policies
See our Privacy Policy for how we handle personal data, and our Terms of Service for acceptable use.