Trust · Security · Privacy

Built for important information

StayPrivate has spent more than a decade building systems for important communication and information. Security, privacy and resilience are built into the way we design and operate our products and Bespoke solutions.

Independently certified and assessed

ISO 27001 Information security management
Cyber Essentials Plus Independently verified technical controls
G-Cloud UK Government supplier

StayPrivate operates an information security management system independently certified to ISO 27001 and holds Cyber Essentials Plus certification.

Security

Layered technical and organisational controls protect information throughout its lifecycle.

Privacy

Our services are built to provide the service required, not around advertising, profiling or exploiting personal information.

Customer ownership

Where customer ownership forms part of the solution, Keepd gives individuals their own private place for the information they receive.

Resilience

Our infrastructure and operational processes are designed to protect important information and keep it available.

Security by design

Protection throughout the information lifecycle

Important information requires more than a secure login. We use layered technical and operational controls across our systems and processes.

Encryption

Documents and sensitive information are encrypted in transit and at rest using modern industry-standard encryption.

Access control

Access to systems and information is restricted according to operational need and limited to authorised personnel.

Secure infrastructure

Our products operate on professionally managed cloud infrastructure designed for security, resilience and scalability.

Environment separation

Production systems are separated from development environments, with access and configuration governed through our information-security processes.

Monitoring and maintenance

Systems and dependencies are monitored and maintained, with security vulnerabilities assessed and addressed according to risk.

Operational controls

Information-security governance, risk assessment, incident management and ongoing review form part of how our services are operated.

Independent assurance

Security controls independently assessed

ISO 27001

StayPrivate operates an information security management system certified to ISO 27001.

ISO 27001 provides a structured framework for identifying information-security risks, implementing appropriate controls and continually reviewing and improving those controls.

Cyber Essentials Plus

StayPrivate also holds Cyber Essentials Plus certification.

Cyber Essentials Plus adds independent technical verification to the Cyber Essentials framework, providing external assurance that important technical protections are operating effectively.

Additional security testing

We carry out additional internal security testing as part of the ongoing development and operation of our products. This includes targeted testing when systems, features or potential vulnerabilities warrant further investigation.

G-Cloud supplier

StayPrivate services are available through the UK Government's G-Cloud framework, supporting procurement by public-sector organisations.

Privacy

Built to provide the service, not to exploit the data

StayPrivate's products are not built around advertising, profiling or exploiting personal information. Information entrusted to our services is used to provide and operate the services for which it was supplied.

We aim to collect and retain only the information needed to provide those services, operate them securely and meet our legal obligations.

Read our Privacy Policy

Customer ownership

When information should belong with the individual

StayPrivate designs for both sides of important communication. Sometimes secure delivery or access is enough. In other cases, customer ownership is part of the solution.

Documentd is built around that model. A business delivers an important document and the recipient receives their own copy in Keepd, their private place for the things they want to keep.

Businesses using Documentd do not gain access to the rest of a recipient's Keepd. Documents from different organisations can remain private to the individual.

Bespoke solutions also use Keepd where customer ownership is part of the solution.

Resilience

Designed for important information over time

Important information may be needed long after it was first sent or received, so our systems are designed around durability as well as immediate communication.

Our systems incorporate backup, recovery and operational-resilience measures intended to protect against loss and maintain availability.

Risks affecting the confidentiality, integrity and availability of information are regularly reviewed through our information security management system.

Data protection

Privacy built into how we operate

Appropriate contractual and data-processing arrangements can be put in place where StayPrivate processes personal information on behalf of an organisation.

Our information-security and data-protection processes cover areas including:

Access to personal information

Retention and deletion

Security incidents

Supplier and sub-processor management

Risk assessment

Business continuity

Information-security training

Ongoing review of information-security controls

Enterprise assurance

Supporting your due diligence

Organisations in regulated and security-sensitive industries may need to conduct their own due diligence before using a StayPrivate product or solution.

We can provide additional assurance information as part of an appropriate enterprise evaluation.

Information-security governance

ISO 27001 certification

Cyber Essentials Plus certification

Technical architecture

Encryption and access controls

Data protection

Sub-processors

Business continuity and disaster recovery

Vulnerability management

Incident management

Data retention and deletion

Integration and API security

Security and due diligence

Talk to us about your requirements

If you are evaluating StayPrivate for a regulated or security-sensitive use case, talk to us about security, privacy, compliance, resilience or technical integration.

Contact us