FaxTerra

How We Protect Your Documents

Your documents are encrypted on the way to us and for as long as we hold them.

Encryption

Your documents travel to us over an encrypted connection and are stored encrypted with AES-256 on Amazon S3, in the US East region. The site is served over HTTPS only, with strict browser security policies on every response.

Payments

Stripe processes every payment. It is a PCI Level 1 payment processor, and your card details go straight to it, so we never see or store them.

Signing in

Creating an account never requires a password. You sign in with a link emailed to you, with Google, or with Apple, and you can set a password later if you prefer one. A password you set is stored only as a one-way hash, so nobody can read it back, including us.

Who can see your account

Nobody on our side reaches your account without signing in through an identity provider that requires a second factor. When someone here opens one of your documents, or loads your account's detail view, we write it to an access log we keep for six years.

Retention and deletion

Documents you send are deleted after 30 days on Free and Starter. Business and Pro start at 1 year and can choose a longer window, or keep them until you delete them yourself. Faxes you receive are kept for 90 days on Free and Starter and 1 year on Business and Pro, and any plan can choose a longer window. Deletion runs every day, and we check afterwards that it happened.

Screening for junk faxes

Outbound faxes may be screened automatically for the junk-fax blasts our terms prohibit. The screening runs inside Amazon Web Services, under the same agreement that covers our storage, and the pages are not retained there or used to train anything.

The HIPAA add-on

If you transmit protected health information, the HIPAA add-on gives you a signed Business Associate Agreement, a unique AES-256 key for each document on top of encrypted storage, an access log kept for six years, and notifications (email and mobile push) that carry no patient detail. Our storage, database, hosting and error-monitoring vendors each sign their own agreement. The add-on also gives you Business-level retention on whatever plan you are on. HIPAA has no certifying body, so compliance is the controls plus the signed agreement, never a certificate. Read how it works.

Weekly security checks

Every week we check the software we build on against published vulnerability advisories, and re-read the full set of security settings the live site serves. The content security policy is also checked by an automated test before every release. Your documents never leave production, and our test environments run on made-up data rather than a copy of the live system.

We name every company that handles your data in the privacy policy.

Security documentation

If you are running a vendor security review, email support@faxterra.com and we will send our security documentation.

Vulnerability disclosure

Report a security problem to security@faxterra.com. Our security.txt has the same contact in machine-readable form.

Send your first fax

No fax machine needed.

Send a fax free