Trust · Security · Privacy

Built for important documents

Documentd and Keepd are designed around security, privacy and long-term availability. Our information-security controls are independently assessed, and recipients keep their own private copies of the documents delivered to them.

Independently certified and assessed

ISO 27001 certification Cyber Essentials Plus certification

StayPrivate operates an information security management system independently certified to ISO 27001 and holds Cyber Essentials Plus certification.

Security

Layered technical and organisational controls protect documents and information throughout their lifecycle.

Privacy

Documentd and Keepd are not built around advertising, profiling or exploiting personal information.

Recipient ownership

Recipients receive their own copy in Keepd, under their control and independent of the organisation that sent it.

Resilience

Our infrastructure and operational processes are designed to protect important information and keep it available.

Security by design

Important documents require more than a secure login. Documentd and Keepd use layered technical and operational controls to protect information throughout its lifecycle.

Encryption

Documents and sensitive information are encrypted in transit and at rest using modern industry-standard encryption.

Access control

Access to systems and information is restricted according to operational need and limited to authorised personnel.

Secure infrastructure

Documentd and Keepd operate on professionally managed cloud infrastructure designed for security, resilience and scalability.

Environment separation

Production systems are separated from development environments, with access and configuration governed through our information-security processes.

Monitoring and maintenance

Systems and dependencies are monitored and maintained, with security vulnerabilities assessed and addressed according to risk.

Authentication

Recipients access their Keepd through authenticated accounts rather than permanently accessible public document links.

Independent assurance

Security controls independently assessed

ISO 27001

StayPrivate operates an information security management system certified to ISO 27001.

ISO 27001 provides a structured framework for identifying information-security risks, implementing appropriate controls and continually reviewing and improving those controls.

Cyber Essentials Plus

StayPrivate also holds Cyber Essentials Plus certification.

Cyber Essentials Plus adds independent technical verification to the Cyber Essentials framework, providing external assurance that important technical protections are operating effectively.

Additional security testing

We carry out additional internal security testing as part of the ongoing development and operation of Documentd and Keepd. This includes targeted testing when systems, features or potential vulnerabilities warrant further investigation.

G-Cloud supplier

StayPrivate services are available through the UK Government's G-Cloud framework, supporting procurement by public-sector organisations.

G-Cloud supplier
Recipient ownership

The recipient's copy belongs with the recipient

Documentd differs fundamentally from a conventional customer portal. A business uses Documentd to deliver an important document. The recipient receives their copy through Keepd, their personal place for the things they want to keep.

That copy is not simply a temporary window back into the sender's system. The recipient can continue to keep and access it independently of the organisation that originally delivered it.

The sender remains responsible for its own records and systems. Keepd gives the recipient somewhere for their own copy.

Keepd

Private to the individual

A Keepd account belongs to its user. Documents delivered by different organisations can sit alongside documents, files, emails, notes and other things that the individual chooses to keep for themselves.

Businesses using Documentd do not gain access to the rest of a recipient's Keepd. One organisation cannot see documents delivered by another organisation simply because both use Documentd.

Privacy

Built to provide the service, not to exploit the data

Documentd is not built around advertising, profiling or exploiting personal information. Information entrusted to Documentd and Keepd is used to provide and operate the services for which it was supplied.

We aim to collect and retain only the information needed to deliver those services, operate them securely and meet our legal obligations.

Resilience

Designed for long-term availability

Important documents are often needed long after they were first delivered. Documentd and Keepd are therefore designed around durability as well as immediate delivery.

Our systems incorporate backup, recovery and operational-resilience measures intended to protect against loss and maintain availability. We regularly review risks affecting the confidentiality, integrity and availability of information through our information security management system.

Data protection

Privacy built into how we operate

StayPrivate operates Documentd and Keepd with data protection and privacy built into their design.

Where Documentd is used by an organisation to process personal information on its behalf, appropriate contractual and data-processing arrangements can be put in place.

Access to personal information
Retention and deletion
Security incidents
Supplier and sub-processor management
Risk assessment
Business continuity
Information-security training
Ongoing review of information-security controls
Enterprise assurance

Supporting your due diligence

Organisations in regulated and security-sensitive industries may need to conduct their own due diligence before using Documentd.

We can provide additional assurance information as part of an appropriate enterprise evaluation.

Information-security governance
ISO 27001 certification
Cyber Essentials Plus certification
Technical architecture
Encryption and access controls
Data protection
Sub-processors
Business continuity and disaster recovery
Vulnerability management
Incident management
Data retention and deletion
Integration and API security
A simple trust model

The business sends. Documentd delivers. The individual keeps.

Security protects the journey. Privacy protects the individual. Keepd gives the recipient a place for their own copy that does not depend on continuing to use the organisation that originally sent it.

Talk to us about Documentd

If you are considering Documentd for large-scale or regulated document delivery, talk to us about security, privacy, compliance or technical integration.