generated: '2026-08-13' method: searched probe: true source: https://www.stannp.com/us/trust grade: minimal summary: >- Stannp publishes a named intake channel for reporting a security issue — the Compliance Team form on its trust center — and nothing more. There is no security.txt, no dedicated /security or /responsible-disclosure page, no bug bounty, no safe-harbour statement, no PGP key and no published response SLA for security reports. Recorded as a real but minimal disclosure posture, with the gaps named rather than implied. policy: [] policy_url: null contact: - kind: web-form url: https://www.stannp.com/us/trust owner_role: Compliance Team stated_purpose: >- "...or need to report a security issue, complete the form and we'll respond promptly." - kind: email address: support.us@stannp.com note: >- General support address published in the site footer. Not designated for security reports; recorded because it is the only published email channel. bug_bounty: program: none platforms_checked: - HackerOne - Bugcrowd - Intigriti result: no program found security_txt: served: false probed: - url: https://www.stannp.com/.well-known/security.txt status: 200 served: false reason: >- Soft-200 catch-all — body is `{}`, and a nonsense control path (/.well-known/this-does-not-exist-xyz) returns the identical 200 + `{}`. Not a served RFC 9116 document. - url: https://api-eu1.stannp.com/.well-known/security.txt status: 404 - url: https://api-us1.stannp.com/.well-known/security.txt status: 404 - url: https://app-us1.stannp.com/.well-known/security.txt status: 200 served: false reason: Soft-200 SPA catch-all — body is an HTML shell. see_also: well-known/stannp-well-known.yml disclosure_pages_probed: - url: https://www.stannp.com/us/security status: 404 - url: https://www.stannp.com/us/direct-mail-api/changelog status: 404 note: probed while looking for a security advisories feed security_practices_published: source: https://www.stannp.com/us/developer-tools claims: - weekly penetration testing - two-factor authentication - SFTP for all off-platform data exchange - SecurityScorecard A rating - GDPR and ISO 9001/27001 compliance - Royal Mail Mail Made Easy certification evidence: - source: https://www.stannp.com/us/trust kind: trust-center security contact status: 200 - source: https://www.stannp.com/us/developer-tools kind: published security practices status: 200 gaps: - No /.well-known/security.txt (RFC 9116). - No standalone vulnerability disclosure or responsible disclosure policy page. - No safe-harbour / non-prosecution statement for good-faith researchers. - No PGP/OpenPGP key or encrypted intake. - No published acknowledgement or remediation timeline for security reports. - No CVE/advisory feed.