security,
written down.
This page describes the measures that are in place in faxB2B today. It is deliberately specific, and it also says what we do not offer yet.
In place
- Encryption in transitThe service only runs over HTTPS with HSTS; sign-in and session cookies are marked Secure and HttpOnly.
- Encryption at restStored documents are encrypted with AES-256-GCM, with a separate key derived for each organization.
- Isolation between organizationsEvery organization’s data is separated with row-level security in the database, so one team cannot read another’s records.
- Virus scanningEvery upload is scanned before processing. If the scanner is unavailable the file is held back, never passed through unchecked.
- Safe document processingFiles are checked by content type, converted to plain black-and-white pages in an isolated process, and every version is fingerprinted with SHA-256.
- Two-factor sign-inSign-in uses one-time email codes. Team workspaces also require an authenticator app, with single-use recovery codes.
- Session controlEvery signed-in device is listed and can be signed out; sensitive actions ask for a fresh two-factor check.
- Audit trailSign-ins, role changes and sensitive actions are recorded with who did what and when.
- Abuse protectionSign-in attempts and verification codes are rate-limited; carrier and payment notifications must carry a valid signature.
- Strict browser policyA strict Content Security Policy allows only our own scripts and styles; pages cannot be framed by other sites.
Not offered yet
- We do not sign Business Associate Agreements and do not claim HIPAA compliance. Please do not use faxB2B for protected health information yet.
- No third-party security certification (such as SOC 2 or ISO 27001) has been completed.
- Retention periods and data export are still being defined; this page will be updated when they are.
Report a vulnerability
Found a security issue? Please write to us before disclosing it publicly, and don't access other people's data while testing.
