STANDARD

Security

What we actually do.

Described plainly, and limited to what is true today.

Your money

We never see your card.

Payments are handled entirely by Stripe. Card details are entered on Stripe's own page and stored by Stripe. They are never sent to us, and we could not retrieve them if we wanted to.

Changing your card, downloading invoices and cancelling all happen in Stripe's own billing portal for the same reason.

Your account

No password is required.

No password is required. Most customers sign in with a link we email them. If you would rather have a password you can set one, and we store only a salted cryptographic hash of it.

Each link works once and expires after thirty minutes.

Your website

Fewer moving parts, fewer ways in.

Your website pages are served as plain files. There is no content management system or plugin installation for you to maintain. Contact forms, bookings and your account use our hosted services.

Every site is served over HTTPS with a certificate that renews automatically. Our website analytics run on our own service, without third-party tracking or advertising code.

Your visitors

Useful counts, without advertising trackers.

Visitor numbers are counted by our own analytics, without analytics cookies or a third-party analytics provider.

Our analytics do not store raw visitor IP addresses. An address is combined with a secret value and turned into an irreversible fingerprint, which helps estimate how many visitors used your website and returned.

Messages sent through your contact form are written down before we try to email them to you, so an email delivery failure does not remove the saved inquiry from your account.

Names and messages submitted through forms are different from anonymous visit counts. Our privacy notice explains their use, including what your account assistant can process.

Reporting a problem

If you find something.

Email hello@handledbystandard.com with what you found and how to reproduce it. We'll confirm we've received it and tell you what we're doing about it.

Please don't test against a customer's live site. If you need a target, use our demonstration site.

Being straight with you

What we don't claim.

We are a small, new company. We do not hold SOC 2, ISO 27001 or any other certification, and we are not going to imply otherwise by decorating this page with badges.

What is written above is what we do. If something on this page ever stops being true, it comes off the page.