Every mailing list you upload is a list of real people. Names, addresses, sometimes account numbers or appointment dates. So before you hand that list to any direct mail provider, it's fair to ask whether it's safe.
Yes, Stannp.com is secure for uploading and sending data. The platform is independently certified to ISO 27001:2022, and encrypts your data with 256-bit AES at rest and TLS 1.2/1.3 in transit. It runs on Microsoft Azure's HIPAA-compliant cloud, and it's scanned continuously and tested regularly by independent security firms.
October is Cybersecurity Awareness Month, which makes it a good moment to look at this properly. According to the FBI's 2025 Internet Crime Report (pdf), its Internet Crime Complaint Center received more than 1 million complaints in 2025, with reported losses of nearly $21 billion. Your mail provider is part of your security, whether you've checked them or not.
Below, we answer the questions you should ask any direct mail provider about security, and how Stannp.com answers each one.
Direct mail runs on personal data. A mailing list is names and addresses at the very least, and transactional mail like statements, invoices and appointment reminders often carries far more. If you handle health information under HIPAA, or consumer data covered by state privacy laws like the CCPA, the suppliers you choose are part of how you meet those obligations.
The risks keep growing. The FBI's 2025 Internet Crime Report found reported losses rose 26% on 2024. Business email compromise, where criminals impersonate a colleague, executive or supplier, accounted for more than $3 billion of those losses on its own.
So the questions below aren't box checking. They're the checks that keep your customers' data, and your reputation, where they should be.
This is the first question to ask, because a certificate means someone outside the business has checked. Stannp.com holds three independently audited ISO certifications, PCI DSS compliance and USPS CASS certification, all listed on our accreditations and certifications page.
|
Certification |
What it covers |
|---|---|
|
ISO 27001:2022 |
Information security management, audited every year |
|
ISO 9001:2015 |
Quality management, audited every year |
|
ISO 14001:2015 |
Environmental management, audited every year |
|
PCI DSS 4.0.1 |
Payment card data security, validated every year with quarterly scans |
|
USPS CASS |
Address validation that meets USPS standards for accuracy |
If you work in a regulated industry, ask about compliance features by name. For healthcare, that starts with a Business Associate Agreement (BAA). Stannp.com operates as a HIPAA Business Associate and signs BAAs with all covered entity customers, and its access controls, encryption and audit logging are all HIPAA-compliant. CASS-certified address validation then checks addresses against USPS standards before your mail goes out. Our HIPAA page has the full details. If a provider can't show you current certificates, ask why not.
Your data is encrypted from the moment you upload it. Stannp.com uses 256-bit AES encryption for data at rest and TLS 1.2/1.3 for data in transit, and consistently achieves A+ ratings from Qualys SSL Labs.
In plain terms, that covers two moments:
The keys that unlock that encryption are managed through Azure Key Vault, with strict access controls and regular key rotation. Full detail is in the platform and infrastructure security section of our trust center.
When you ask another provider this question, listen for specifics. "Your data is safe with us" tells you nothing. An encryption standard and a protocol version tell you something.
Stannp.com stores data on secure cloud infrastructure hosted on Microsoft Azure, with HIPAA-compliant security controls, encryption at rest and in transit, and complete audit logging. Each customer's data stays isolated from every other customer's through a multi-tenancy architecture.
Stannp.com processes personal data on behalf of its clients in compliance with US privacy laws including CCPA, CPRA and HIPAA. You keep full control of your data, including the ability to manage and delete it at any time through the platform, subject to any legal retention requirements.
It's worth asking any provider two follow-up questions here. Who controls your data once it's uploaded? And can you delete it yourself, or do you have to ask? Our policies, including the Data Processing Agreement, are in the trust center.
Only the people who need to. Stannp.com uses role-based access control with least privilege principles, which means staff can only reach the systems their role requires. Multi-factor authentication is mandatory on all systems that access protected health information (PHI) or sensitive customer data, and every user has a unique account with no shared credentials.
Every access is logged, monitored and regularly audited. Audit logs are protected against unauthorized changes with tamper-evident controls, and a security information and event management (SIEM) system watches activity 24/7 with real-time alerts. You can also see user action logs inside your own account.
Your data is kept apart from everyone else's, too. The platform's multi-tenancy architecture keeps each customer's data completely segregated from other customers.
On your side, you control who in your team gets in. Paid plans from Growth upwards include multiple user logins, so each person can have their own account rather than sharing one. That makes it easy to remove access the day someone leaves. See detailed pricing for what each plan includes.
All the time. Stannp.com runs continuous automated vulnerability scanning across its infrastructure, monthly assessments with automated alerting, and regular penetration testing by independent, specialist security firms. Testing covers the OWASP Top 10 (the most common web application risks) as a minimum.
Finding problems is only half of it. The other half is how fast they're fixed. Stannp.com works to clear timeframes:
|
Severity |
Resolved within |
|---|---|
|
Critical |
7 days |
|
High |
14 days |
|
Medium |
30 days |
A good provider should be able to tell you how they test, who tests them and how quickly they fix what's found. If they can't give you numbers, that's an answer in itself.
Stannp.com is built to recover quickly. Business critical data is backed up automatically every 15 minutes, with daily full backups and weekly secondary backups stored in geographically separated server regions. Backups are encrypted with 256-bit AES and kept for 30 days, with 12 months of total retention, and disaster recovery procedures are documented.
The platform also runs 24/7 infrastructure monitoring with real-time alerts, and a 99%+ uptime SLA supported by redundant systems. You can check live platform status any time on the service status monitor.
If you have a security question or need to report a concern, the compliance team is on hand through the trust center.
It's reasonable to expect your suppliers to have a plan for when something goes wrong, and to have a plan of your own for when a supplier has a bad day.
The API carries the same protection as the rest of the platform. It uses token-based authentication, HTTPS/TLS encryption rated A+, and intelligent rate limiting. All API activity is logged and monitored through the SIEM system, and monthly vulnerability scans test specifically for the OWASP Top 10.
This matters most if you send mail automatically. Many businesses connect their CRM or billing system to the direct mail API so a letter or postcard goes out when something happens, like an invoice being raised or a patient's appointment coming up. Transactional mail sent through virtual printing often carries the most sensitive data of all, from account numbers to balances owed. If you're weighing up both kinds of mail, our guide to marketing mail or transactional mail explains the difference.
Using the API needs a live API key, which comes with a paid plan. Treat that key like a password: it's what proves a request really comes from you.
A secure platform does a lot, but some of the protection sits with you. Phishing and spoofing was the most reported crime type in the FBI's 2025 Internet Crime Report, with 191,561 complaints. A stolen password gets around good encryption very easily.
Five habits that make a real difference:
Give everyone their own login. Shared accounts make it impossible to see who did what, or to cut off one person's access.
Turn on two-factor authentication. It stops a stolen password from being enough on its own, and you can turn it on for your Stannp.com account.
Keep API keys out of shared places. Never paste them into emails, chat threads or code that other people can see. If one leaks, replace it straight away.
Only upload what you need. If a campaign only needs a name and address, leave the rest of the spreadsheet behind.
Tidy up old data. Delete lists and campaigns you no longer need. Data that isn't there can't be lost.
None of these take long, and they turn a secure platform into a secure process.
Everything in this guide is published in full, with certificates and policy documents, in the Stannp.com trust center. If your procurement or compliance team needs it, it's all there.
Ready to see the platform for yourself? Create your free account, with no minimum order, or log in and get your next campaign out the door knowing your data is in safe hands.
Yes. Stannp.com operates as a HIPAA Business Associate, with HIPAA-compliant access controls, encryption and audit logging on Microsoft Azure's HIPAA-compliant cloud. It processes personal data in compliance with US privacy laws including HIPAA, CCPA and CPRA.
Yes. Stannp.com signs BAAs with all covered entity customers. Covered entities sign the BAA before submitting any protected health information, and the agreement can be downloaded from the HIPAA section of the trust center.
Yes. Stannp.com is independently certified to ISO 27001:2022 for information security management, with annual audits. The certification is listed in the trust center.
Yes. Stannp.com holds USPS Coding Accuracy Support System (CASS) certification, which confirms its address validation meets USPS standards for accuracy and standardization.
It is when the platform encrypts your data, controls access tightly and is independently certified. Check for encryption at rest and in transit, ISO 27001 certification, and HIPAA-compliant controls if you handle health information, before you upload anything.
Yes. You keep full control of your data and can manage and delete it at any time through the platform, subject to any legal retention requirements.
Yes. Stannp.com is compliant with PCI DSS version 4.0.1, the security standard for handling payment card data, with annual validation and quarterly vulnerability scanning.
Contact the compliance team through the form in the Stannp.com trust center. It handles security questions, compliance discussions and reports of security issues.
Good security shouldn't be something you have to take on trust. Create your free account and see how Stannp.com handles your data from the very first upload.