generated: '2026-08-13' method: searched source: https://www.stannp.com/us/accreditations also: - https://www.stannp.com/us/trust - https://www.stannp.com/us/developer-tools - https://www.stannp.com/us/detailed-pricing - openapi/stannp-*-openapi.yml summary: >- Stannp's published conformance posture is strong on POSTAL and DATA-PROTECTION accreditation (Royal Mail PAF, Royal Mail Mail Made Easy, USPS CASS, ICO registration, HIPAA business associate, GDPR, ISO 9001/27001) and weak on API and web-standards conformance (no OAuth, no OIDC, no RFC 9457, no RFC 8594, no RFC 9116, no OpenAPI published by the provider). That split is the honest shape of a print-and-post company with a REST API attached. standards: - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in any spec and no OAuth documentation. Auth is a static account API key (HTTP Basic username, or `api_key` query parameter). - id: openid-connect conforms: false evidence: /.well-known/openid-configuration serves no document on any host. - id: http-basic-authentication conforms: true evidence: >- securitySchemes.basicAuth type http scheme basic across every spec; documented at https://www.stannp.com/us/direct-mail-api/guide. - id: tls-required conforms: true evidence: >- Stannp documents that HTTPS is mandatory and that plain-HTTP requests fail and may suspend the API key. TLSv1.3 observed on www, api-eu1 and api-us1 (security/stannp-domain-security.yml). - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary `{"success": false, "error": "..."}` envelope with content-type application/json, not application/problem+json. See errors/stannp-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy and no Sunset/Deprecation header documented. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt is not served. www.stannp.com answers 200 with `{}` for every /.well-known/ path including a nonsense control path — a catch-all, not a document. See well-known/stannp-well-known.yml. - id: idempotency-key conforms: partial evidence: >- Idempotency IS supported, via an `idempotency_key` request PARAMETER rather than the IETF `Idempotency-Key` HEADER, and a replay returns HTTP 409 with the original body rather than the original status. Real capability, non-standard shape. See conventions/stannp-conventions.yml. - id: rate-limit-headers conforms: partial evidence: >- Returns the de-facto X-RateLimit-Limit / X-RateLimit-Remaining / X-RateLimit-Reset headers on every response, not the RFC 9331 / draft `RateLimit-*` form. No exhaustion status code or Retry-After documented. - id: webhook-hmac-signing conforms: true evidence: >- X-Stannp-Signature carries an HMAC-SHA256 digest of the raw body against a subscriber secret, with documented constant-time comparison guidance. See asyncapi/stannp-webhooks.yml. - id: asyncapi conforms: false evidence: No AsyncAPI document published; webhooks are documented in prose only. - id: openapi conforms: false evidence: >- Stannp publishes no OpenAPI or Swagger document. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on api-eu1, api-us1 and www — all 404 or HTML. Stannp DOES publish a machine-readable markdown reference at https://www.stannp.com/stannp-api-llm.md (saved at llms/stannp-api-llm.md), which is an LLM-oriented substitute, not an OpenAPI. The specs in openapi/ are API Evangelist's own. - id: iso-3166-1-alpha-2 conforms: true evidence: >- Country is an ISO 3166-1 alpha-2 code throughout (recipient.country, letters/post `country`, sms `country`). - id: iso-8601-timestamps conforms: partial evidence: >- Mixed. Some fields are ISO 8601 with offset ("2024-01-15T10:30:00+00:00", recipient/campaign created), others are space-separated "YYYY-MM-DD HH:MM:SS" (mailpiece timestamp, recipient created/updated in list responses). A consumer must handle both. - id: json-api conforms: false evidence: Proprietary success/data envelope; not JSON:API. - id: graphql conforms: false evidence: No /graphql surface documented or reachable. - id: mcp conforms: false evidence: >- No MCP server, hosted or local. See mcp/stannp-mcp.yml (candidate only). - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. compliance: published: true page: https://www.stannp.com/us/accreditations trust_center: https://www.stannp.com/us/trust contact: Compliance Team form on the trust center certifications_and_accreditations: - name: HIPAA role: Business Associate detail: >- Stannp states it is HIPAA compliant as a business associate processing Protected Health Information, with physical, network and process safeguards, breach notification protocols, workforce training and subprocessor due diligence. Listed as "HIPAA certified" on the plan comparison table. source: https://www.stannp.com/us/accreditations - name: ISO 27001 status: claimed compliant detail: Stated as "GDPR & ISO 9001/27001 compliant" on the developer tools page. source: https://www.stannp.com/us/developer-tools - name: ISO 9001 status: claimed compliant source: https://www.stannp.com/us/developer-tools - name: GDPR status: claimed compliant source: https://www.stannp.com/us/developer-tools - name: ICO registration registration_number: ZA134992 role: Data Processor detail: >- Registered with the UK Information Commissioner's Office as a Data Processor; customer data remains the customer's and is processed only on their instruction. source: https://www.stannp.com/us/accreditations - name: USPS CASS certification detail: >- Coding Accuracy Support System certified by the United States Postal Service for US address formatting and handling. source: https://www.stannp.com/us/accreditations - name: Royal Mail PAF accreditation detail: >- Accredited Postal Address File partner; PAF covers 1.8m UK postcodes and 30m+ addresses and backs the free data-cleaning/address-verification service. source: https://www.stannp.com/us/accreditations - name: Royal Mail Mail Made Easy partner source: https://www.stannp.com/us/accreditations - name: SecurityScorecard A rating status: claimed source: https://www.stannp.com/us/developer-tools security_practices_claimed: - weekly penetration testing - two-factor / multi-factor authentication - SFTP for all off-platform data exchange - encrypted transmission and secure cloud infrastructure - 24/7 system monitoring - access controls, data segregation, secure backup procedures - audit log of every user action not_found: - name: SOC 2 note: Not claimed anywhere on the trust center or accreditations page. - name: PCI DSS note: Not claimed. - name: FedRAMP note: Not claimed. environmental: - Forest Carbon scheme (via Premier Paper and Antalis) - Carbon Capture scheme - carbon-neutral mailing listed as a plan feature