Trust centre

Security you can verify, not just trust

See where documents are stored, how they are protected, who can reach them, and how every action is recorded.

  • Exportable audit log
  • Delivery receipts
  • Canadian or US residency
Data residencyCanada or the United States
PHIPA controlsOntario health privacy
HIPAA controlsFor covered entities
PIPEDACanadian privacy law

The path a document takes

Five stages, and a record at each one

  1. 01

    Sent from your app

    Sent by a member, from an inbox they have been assigned.

  2. 02

    Encrypted in transit

    Protected while it travels, with the keys held apart from the document.

  3. 03

    Stored in your region

    Canada or the United States, as recorded in your service agreement.

  4. 04

    Written to the audit log

    Every view, download, send and delete is recorded, and exportable.

  5. 05

    Receipt issued

    A timeline with timestamps, and what the receiving device acknowledged.

Controls

Each claim, and the control behind it

A manager at a two-monitor desk in an open-plan office, reading a received fax in the FaxDirect app

What we can send you

  • Completed security questionnaires
  • Architecture diagrams
  • The current subprocessor register
  • A data-processing agreement
Request security documents
Stored in the region you choose

When your account is provisioned you select a residency region — Canada or the United States. Documents, metadata and backups for that account are stored and processed within it. The region is recorded in your service agreement, not just in a settings panel, and it does not change without a written amendment.

Encrypted on the way and in storage

Documents are encrypted while they travel and while they are stored, and the keys are held apart from the documents themselves. No support tool can open one of your faxes without writing an access record first. If your reviewers need the specifics for an assessment, ask us and we will provide them under NDA.

Access is scoped and recorded

Members see only the numbers and inboxes assigned to them. Administrators can restrict export and deletion. Every view, download, send and delete is written to an audit log you can export at any time.

Retention is yours to set

Choose how long documents are kept, whether deletion is permitted, and whether an immutable copy is retained for regulatory purposes. Deletion requests are honoured across primary storage and backups within a published window.

Delivery is evidenced, not asserted

Every transmission produces a timeline with timestamps for each stage and a receipt confirming what the receiving device acknowledged. Failed transmissions record the reported cause rather than a generic error.

Programme

How the security programme runs

Vulnerability management

Dependencies and infrastructure are patched on a published cadence, with severity-based deadlines for anything urgent.

Independent testing

Third-party penetration testing on a recurring schedule. Summary reports are available under NDA.

Employee access

Support staff cannot read a document without an access record being written and retained.

Subprocessors

A current register of every subprocessor, what it does, and where it operates.

Incident response

A defined severity ladder, notification commitments, and public write-ups after resolution.

Responsible disclosure

A published route for reporting a vulnerability, with a commitment not to pursue good-faith researchers.

Bring your security review. We will answer it.

  • Free standard number porting
  • Unlimited sent and received pages
  • Cancel from account settings, any time