Security
Layered technical and organisational controls protect information throughout its lifecycle.
Trust · Security · Privacy
StayPrivate has spent more than a decade building systems for important communication and information. Security, privacy and resilience are built into the way we design and operate our products and Bespoke solutions.
Independently certified and assessed
StayPrivate operates an information security management system independently certified to ISO 27001 and holds Cyber Essentials Plus certification.
Layered technical and organisational controls protect information throughout its lifecycle.
Our services are built to provide the service required, not around advertising, profiling or exploiting personal information.
Where customer ownership forms part of the solution, Keepd gives individuals their own private place for the information they receive.
Our infrastructure and operational processes are designed to protect important information and keep it available.
Security by design
Important information requires more than a secure login. We use layered technical and operational controls across our systems and processes.
Documents and sensitive information are encrypted in transit and at rest using modern industry-standard encryption.
Access to systems and information is restricted according to operational need and limited to authorised personnel.
Our products operate on professionally managed cloud infrastructure designed for security, resilience and scalability.
Production systems are separated from development environments, with access and configuration governed through our information-security processes.
Systems and dependencies are monitored and maintained, with security vulnerabilities assessed and addressed according to risk.
Information-security governance, risk assessment, incident management and ongoing review form part of how our services are operated.
Independent assurance
StayPrivate operates an information security management system certified to ISO 27001.
ISO 27001 provides a structured framework for identifying information-security risks, implementing appropriate controls and continually reviewing and improving those controls.
StayPrivate also holds Cyber Essentials Plus certification.
Cyber Essentials Plus adds independent technical verification to the Cyber Essentials framework, providing external assurance that important technical protections are operating effectively.
We carry out additional internal security testing as part of the ongoing development and operation of our products. This includes targeted testing when systems, features or potential vulnerabilities warrant further investigation.
StayPrivate services are available through the UK Government's G-Cloud framework, supporting procurement by public-sector organisations.
Privacy
StayPrivate's products are not built around advertising, profiling or exploiting personal information. Information entrusted to our services is used to provide and operate the services for which it was supplied.
We aim to collect and retain only the information needed to provide those services, operate them securely and meet our legal obligations.
Read our Privacy Policy →Customer ownership
StayPrivate designs for both sides of important communication. Sometimes secure delivery or access is enough. In other cases, customer ownership is part of the solution.
Documentd is built around that model. A business delivers an important document and the recipient receives their own copy in Keepd, their private place for the things they want to keep.
Businesses using Documentd do not gain access to the rest of a recipient's Keepd. Documents from different organisations can remain private to the individual.
Bespoke solutions also use Keepd where customer ownership is part of the solution.
Resilience
Important information may be needed long after it was first sent or received, so our systems are designed around durability as well as immediate communication.
Our systems incorporate backup, recovery and operational-resilience measures intended to protect against loss and maintain availability.
Risks affecting the confidentiality, integrity and availability of information are regularly reviewed through our information security management system.
Data protection
Appropriate contractual and data-processing arrangements can be put in place where StayPrivate processes personal information on behalf of an organisation.
Our information-security and data-protection processes cover areas including:
Access to personal information
Retention and deletion
Security incidents
Supplier and sub-processor management
Risk assessment
Business continuity
Information-security training
Ongoing review of information-security controls
Enterprise assurance
Organisations in regulated and security-sensitive industries may need to conduct their own due diligence before using a StayPrivate product or solution.
We can provide additional assurance information as part of an appropriate enterprise evaluation.
Information-security governance
ISO 27001 certification
Cyber Essentials Plus certification
Technical architecture
Encryption and access controls
Data protection
Sub-processors
Business continuity and disaster recovery
Vulnerability management
Incident management
Data retention and deletion
Integration and API security
Security and due diligence
If you are evaluating StayPrivate for a regulated or security-sensitive use case, talk to us about security, privacy, compliance, resilience or technical integration.