generated: '2026-08-22' method: searched source: https://www.handle.com/security-and-trust/ note: >- Handle publishes no machine-readable contract, so nothing here is derived from a specification. Every entry below is read from a page Handle publishes, or recorded as not-found after probing. standards: - id: soc2-type1 conforms: true evidence: >- "Handle is officially Service Organizational Control (SOC) 2 Type 1 ... compliant" — https://www.handle.com/security-and-trust/ (HTTP 200) - id: soc2-type2 conforms: true evidence: >- "Handle is officially Service Organizational Control (SOC) 2 ... Type 2 compliant"; the page badges "SOC 2 Type 2 Compliant" — https://www.handle.com/security-and-trust/ (HTTP 200) - id: pci-dss conforms: unknown evidence: >- Handle makes no PCI DSS claim of its own. Its partners page states the Handle platform "will integrate with CardPointe(R) Gateway and other PCI-compliant tools from Fiserv via the company's ISV payments engine" — https://www.handle.com/partners/ (HTTP 200). That is a statement about Fiserv's tools, not about a Handle attestation, and is NOT recorded as Handle conformance. - id: oauth2 conforms: unknown evidence: >- No OpenAPI and no public auth documentation. /.well-known/oauth-authorization-server and /.well-known/openid-configuration return 404 on www.handle.com and api.handle.com. - id: openid-connect conforms: unknown evidence: /.well-known/openid-configuration returns 404 on every probed Handle host. - id: rfc9457-problem-details conforms: unknown evidence: >- api.handle.com returns errors as application/json {"message": "..."} rather than application/problem+json, observed on the unauthenticated /api and /api/docs 404 responses. That is a single observed envelope, not a published error contract. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.handle.com and api.handle.com. - id: rfc8594-sunset-header conforms: unknown evidence: No published deprecation policy; no authenticated surface available to observe headers. domain_standards: - market: Construction finance / lien rights and waiver exchange standard: null conforms: false evidence: >- No domain standard is declared anywhere on Handle's public surface. Handle's compliance domain is US state-by-state mechanics-lien statute, which is law rather than an interoperability standard, and Handle publishes no contract in which a standard could be declared. No SCIM URN, OData $metadata, OpenRTB, ActivityPub, OAI-PMH, ISO 20022, X12 or EDIFACT signature was found. REWARD-ONLY dimension: recorded as absent, not as a failure. - market: B2B payments standard: iso-20022 conforms: false evidence: >- No ISO 20022 message type or namespace appears on any Handle public surface. Handle's payment rails are described as running through Fiserv's CardPointe gateway (card) rather than as ISO 20022 messaging. compliance_programs: - name: SOC 2 Type 1 published: true url: https://www.handle.com/security-and-trust/ - name: SOC 2 Type 2 published: true url: https://www.handle.com/security-and-trust/ report_access: gated via https://trust.handle.com/ ("Request Report")