Security, compliance and data handling

What we claim, and what we do not.

You are considering giving a supplier privileged access to your infrastructure. That decision deserves specifics rather than reassurance, including the places where our answer is "no".

Our compliance position

STP is not certified. STP gets clients certified.

STP designs, implements and audits infrastructure so our clients can achieve and keep these certifications. Our own internal practice is aligned with ISO/IEC 27001. STP does not hold a certificate of its own, and we will never imply otherwise.

We deliver compliance enablement as a service for ISO/IEC 27001, SOC 2, SOC 3, HIPAA: gap assessment, technical control implementation, evidence automation, and sitting with your auditor during the walkthrough.

What we will not do is display a badge we have not earned. Plenty of providers in this market describe themselves as "ISO 27001 compliant", which is a phrase with no defined meaning. Certification is a binary that an accredited body either granted or did not. If we ever hold a certificate, this page will name the certifying body, the certificate number and the scope, and you will be able to verify it independently.

Services

Internal practice

How we operate as a supplier

  • No single-person dependency

    Procedures are documented and coordinated so that no client environment depends on one individual at STP. If an engineer leaves, your estate does not become unknowable. This has been a stated company principle since 2018.

  • Client environment data held to ISO 27001 practice

    Documentation about your infrastructure (diagrams, credentials inventory, cable schedules) is stored and access-controlled in line with ISO/IEC 27001 practice. Access is on a need-to-know basis and is reviewed.

  • Penetration testing capability in-house

    STP employs penetration testers directly. That capability is used on client engagements and it also means our own recommendations are written by people who break systems, not only by people who build them.

  • Secondary review on project work

    Projects are checked by a senior technical reviewer who did not perform the work, before handover. The purpose is to catch the errors that the person who made them cannot see.

  • Change and access records

    Work is tracked in systems that retain a record of what was changed, when, and by whom, which is what makes an audit trail possible for clients who need one.

This website

We built this site the way we would build yours.

A security practice that does not apply to its own website is a marketing claim. Here is how this page is served, so you can check it against the response headers yourself.

ControlImplementation
Static deliveryThis site is pre-rendered static HTML served from Cloudflare's edge. There is no application server, no database and no CMS behind it, which removes most of the attack surface a marketing site normally carries.
Content Security PolicyA strict CSP with no unsafe-inline and no unsafe-eval for scripts. Every inline script is pinned by its SHA-256 hash, derived from the built output at deploy time, rather than permitted by a blanket exception.
No third-party scriptsNo tag managers, no advertising pixels, no chat widgets, no third-party fonts. Nothing on this page is loaded from a domain we do not control.
Transport securityHTTPS enforced with HSTS including subdomains and preload. HTTP requests are upgraded rather than redirected.
Privacy by defaultNo advertising cookies and no cross-site tracking. We do not need a consent banner because we are not doing the things that require one.
Form handlingEnquiries are validated server-side and delivered by email. Submissions are not stored in a database, because data that is never retained cannot be breached.

Responsible disclosure

Found something? Please tell us.

If you have found a security issue affecting stp.am or STP-managed infrastructure, we want to hear about it and we will not be difficult about it.

  • Email website@stp.am
  • Machine-readable contact at /.well-known/security.txt
  • We acknowledge reports and tell you what we did about them
  • Please give us a reasonable window to fix an issue before disclosing it publicly

Questions we get asked in procurement

Is STP ISO 27001, SOC 2 or HIPAA certified?
No. STP holds no certification of its own against ISO/IEC 27001, SOC 2, SOC 3 or HIPAA. STP implements, audits and documents infrastructure so that its clients can achieve and maintain those certifications, and its internal practice is aligned with ISO 27001. We state this explicitly because misrepresenting certification is precisely the kind of risk our clients engage us to eliminate.
How do you handle credentials for our systems?
Credentials are held in access-controlled secret management with access granted on a need-to-know basis, and are revoked when an engagement or an engineer's involvement ends. Where your own secret management system exists, we prefer to use it rather than duplicate custody.
What happens to our documentation if we stop working with STP?
It is yours. Documentation produced during an engagement is handed over in full, and it is written so that a different supplier can use it. We also remove our access to your systems on exit, and will confirm that in writing.
How do I report a security vulnerability?
Email website@stp.am, or use the contact form. Our security.txt file at /.well-known/security.txt carries the current contact details. We will acknowledge your report and keep you informed of what we do about it.

Need a supplier security questionnaire completed?

Send it over. We answer them properly, including the awkward questions.

Get in touch