1. What SafeHanded is for
SafeHanded is for requesting, receiving and sending credentials and other sensitive information in the course of legitimate IT support, administration and business operations. Use it only for that purpose and only in line with the law.
2. You must not
- Deceive people. Send requests that impersonate another organisation, trick a person into handing over a credential they are not entitled to share, or support phishing, fraud or social engineering.
- Request credentials you have no right to. Ask for or collect credentials, codes or personal data without a lawful basis and the authority of the organisation that owns the account.
- Send unlawful or harmful content. Use a handover or share to transmit malware, material that infringes someone else's rights, or content that is unlawful, harassing or abusive.
- Send unwanted messages. Use requests, campaigns, email or SMS to send bulk or unsolicited messages to people who have no relationship with your organisation.
- Attack the service. Probe, scan or test SafeHanded's security outside our disclosure policy; bypass rate limits, plan limits or access controls; or interfere with other customers' use.
- Overload it. Use automation that places an unreasonable load on the service, or run denial-of-service or volumetric testing. "Unlimited" requests or shares on a plan means there is no monthly count; the published service limits (such as file storage, API rate and the number of API keys and webhooks) still apply, and are listed on our pricing page.
- Misuse the link checker. Use the public link checker to enumerate links or harvest information about other organisations.
- Resell without agreement. Resell or sublicense SafeHanded, except that a managed service provider may use it to serve its own clients under our Customer Terms.
- Copy or reverse engineer it. Copy, decompile or reverse engineer the service except to the extent the law allows despite this restriction.
- Use it for special-category data. Put health, biometric, criminal-offence or other special-category data into ticket references, names, messages or other fields we can read. The encrypted payload is not readable by us, but the surrounding metadata is.
3. Your responsibility
You are responsible for the use of SafeHanded by your technicians, administrators, integrations and API keys, and, if you are a managed service provider, for use carried out on behalf of your clients.
4. What we do about breaches
Because we cannot read encrypted payloads, we act on the metadata we hold, reports we receive and the behaviour of accounts. If we reasonably believe this policy has been breached, we may remove access to a request or share, suspend an account, API key or organisation, and report unlawful activity to the relevant authorities. Where it is safe to do so, we will tell you first and give you a chance to put it right.
5. Reporting abuse
If you received a SafeHanded link you did not expect, use Report this link on the page: it cancels the link and alerts the organisation that sent it. If you believe the organisation itself is misusing SafeHanded, email support@safehanded.com. To report a security vulnerability, see our disclosure policy.
Harman AJ Ltd · Company number 17412886Reports: support@safehanded.com