Home Features Pricing Compare Security API Integrations Guides Log in Start free trial
Security & Compliance

Security you can verify.

HIPAA-grade infrastructure. BAA with you on every paid plan.
Full encryption at rest and in transit. Audit logs you can export.

Compliance
HIPAA-aligned
BAA
Online · Instant
Encryption
AES-256 / TLS 1.3
Hosting
US · Miami, FL
Audit Logs
Full · Exportable
Retention
While active
HIPAA

HIPAA on every paid plan.

No tiered "HIPAA add-ons" or enterprise-only compliance. Same protections at every level.

LuzardoFax is built from the ground up to meet HIPAA Security Rule requirements for Protected Health Information (PHI). Every paid plan — from Solo to Business — includes the same encryption, the same BAA terms, and the same audit infrastructure.

  • Instant online BAA — signed during account onboarding with timestamp and IP capture. No printable PDFs to fax back, no manual paperwork.
  • Subprocessor BAAs — Our BAA with Vultr (hosting) was executed on July 9, 2026 and is blockchain-anchored for independent verification. Telnyx (fax transport) states in its Terms of Service that it acts as a conduit for the transmissions it carries, and we configure the service so that no fax content is stored on their side. We are in contact with Telnyx regarding a written agreement covering this position, and we keep a dated evidence record of their certifications and contractual terms. Email notifications are zero-PHI by design, so no email subprocessor handles PHI.
  • HIPAA Privacy Rule — access controls, audit trails, breach notification procedures, and data minimization built in.
  • HIPAA Security Rule — administrative, physical, and technical safeguards. Risk assessments performed before every major change.
Plain English

HIPAA is not a certification — there's no certificate to frame on the wall. HIPAA is a set of rules we follow as a Business Associate. We sign a BAA with you, we follow the rules, and our subprocessors do the same. That's how compliance actually works.

Verifiable proof

Independent proof of your signed BAA.

Your compliance evidence shouldn't depend on trusting your vendor's word.

Every signed BAA receives a cryptographic timestamp anchored to the Bitcoin blockchain, creating independently verifiable proof that the signed agreement existed at that point in time. The verification doesn't depend solely on LuzardoFax.

  • What gets anchored — a SHA-256 hash of your executed BAA. The document itself is never published; only its fingerprint.
  • How to verify — from Settings → Compliance you can download the signed BAA, the timestamp proof (.ots), and the evidence file, then verify at opentimestamps.org.
  • Why it matters — in an audit, you can demonstrate your agreement existed at a specific point in time using a public, independent record.
  • Also applied upstream — our own BAA with Vultr (hosting) is anchored the same way.
Plain English

This isn't a crypto feature and it has nothing to do with coins or wallets. It's a well-established way to prove a document existed on a certain date without anyone having to take our word for it — including us.

Data handling

Settings stored server-side.

Your account preferences belong to your account, not to one browser.

Your preferences are stored securely server-side and synchronized across your devices, rather than relying only on data stored in your browser.

  • Consistent across devices — notification settings, language and interface preferences follow your login.
  • Session tokens only — the browser holds session data and lightweight cache, not your account configuration.
  • Revocable — sessions can be revoked server-side, which also applies when a user is deactivated.
In-app assistant

Guidance that never touches your faxes.

The assistant helps you use the app. Fax content is excluded by architecture, not by policy.

Inside your account, “Ask me” answers questions about how to use LuzardoFax. It is built so that protected health information cannot reach it in the first place.

  • What it can use — a limited whitelist of non-PHI account details: your plan, fax number, pages used in the current cycle, and days left in your billing cycle. That is the complete list.
  • What it cannot access — fax documents, recipients, contacts, or any patient data. Fax content is architecturally excluded: the code that builds the assistant’s context never reads those tables.
  • What we store — usage metadata only (account, timestamp, token counts). The text of your messages is not persisted.
  • Scope — the assistant explains how the product works. It will not discuss the contents of your faxes, and it points you to your own inbox for anything about your specific documents.
Plain English

We could have let the assistant read your faxes to give richer answers. We deliberately did not. Sending PHI to a third-party model we do not have a BAA with would be exactly the kind of shortcut this product exists to avoid.

Encryption

Faxes encrypted at every step.

From the moment a fax is sent or received to the moment you archive it years later.

  • In transit — TLS 1.3 for all web traffic. TLS-encrypted SIP for fax transmission to Telnyx.
  • At rest — AES-256-GCM encryption on all fax PDFs, contact data, and audit logs in our database.
  • Backups — Encrypted at rest with separate keys from production data. Stored in isolated environments.
  • Email notifications — TLS-encrypted in transit via SendGrid. Zero-PHI by design: notifications never include the fax document or sender details, only a secure link.
  • Passwords — bcrypt hashing with strong cost factors. We can't see your password — even we can't read it.
Infrastructure

Built on audited cloud infrastructure.

We don't run our own data centers. We build on top of audited providers and add our application layer.

LuzardoFax production infrastructure runs on Vultr in their Miami, FL region. Vultr maintains SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, and HIPAA-aligned controls, with independently audited compliance reports available.

Important context: SOC 2 certifications belong to the provider, not us. Vultr's certifications validate that their infrastructure meets those standards — they don't automatically certify our application. Our responsibility is to configure their infrastructure correctly, sign the BAA with Vultr, and apply our own controls on top.

  • Region — Production in Miami, FL; encrypted offsite backups in a second US region (US-only data residency)
  • Network — DDoS mitigation, firewall isolation, private networking between services
  • Backups — Daily encrypted backups with 30-day retention
  • Monitoring — 24/7 infrastructure monitoring with automatic alerts
Access Controls

Only you. Only your team.

Strong authentication, role-based access, and granular audit trails.

  • Two-factor authentication — Optional for every user on every plan. On Business and Enterprise, an account admin can require it for the whole team.
  • Role-based access — On Business plans, admins control who has which permissions: send, receive, manage users, view audit logs.
  • Session management — JWT tokens with reasonable expiry. Sessions revoked instantly on logout.
  • Password requirements — Minimum length, complexity, and breached-password checks at signup.
  • Account isolation — Multi-tenant architecture with strict account-level data separation enforced at every database query.
Audit Logs

Full visibility into every action.

The compliance trail your auditor expects — accessible whenever you need it.

Every action that touches PHI or account configuration is logged with timestamp, user, IP address, and user agent. Account admins can view and export logs anytime from the dashboard.

  • Fax send / receive / view / download / delete events
  • Login attempts (successful and failed)
  • Settings changes (security, notifications, billing)
  • User add / remove / permission changes
  • BAA signing event with IP and timestamp
  • Exports in CSV format · API access on every plan

Access logs are kept for the life of your account, so you always have a complete audit trail of who accessed what and when. Separately, the compliance documentation the HIPAA Security Rule requires us to maintain is retained for six (6) years under 45 CFR § 164.316(b)(2)(i).

Subprocessors

Full transparency on third parties.

We publish the complete list of who touches your data and why.

Below is the live status of every subprocessor that can touch Protected Health Information. We publish it as-is rather than claiming blanket coverage. Where applicable, they also maintain their own SOC 2 / ISO certifications.

Provider Purpose BAA Region
Vultr Cloud infrastructure hosting Executed — July 9, 2026 US (Miami, FL)
Telnyx Fax transport (PSTN ↔ digital) No signed BAA — conduit position US
SendGrid Transactional email delivery (zero-PHI by design) Not required (no PHI handled) US
Cloudflare CDN & DDoS protection (no PHI in cache) Not required (PHI never cached) Global edge

If we add or replace a subprocessor, we'll notify all customers 30 days in advance. Need the full list with effective BAA dates? Contact us — we'll send you a current copy.

Breach Response

If something goes wrong.

Documented procedures, fast notifications, full disclosure.

We follow the HIPAA Breach Notification Rule. In the event of any incident affecting PHI:

  • Detection — 24/7 monitoring of infrastructure and application logs flags anomalies for review.
  • Containment — Immediate isolation of affected systems and forensic preservation.
  • Notification — Affected customers notified within statutory HIPAA deadlines (60 days max, typically much faster).
  • Disclosure — Full transparency: what happened, what data was affected, what we're doing to prevent it again.
  • Post-incident — Root-cause analysis, corrective actions documented, BAA review updated.

For security concerns or to report a vulnerability, email [email protected].

Data Retention

Your faxes, for as long as you need them.

No time limits, no storage tiers, no extra fees.

Received faxes, transmission records, and account history are stored for as long as your account is active — searchable, downloadable, and available 24/7 on every plan, Solo or Business, at no additional cost. You're always in control: download any fax as a PDF anytime to keep your own records.

  • While active — Received faxes are searchable, downloadable, and available 24/7 in your inbox. For sent faxes, we keep the full transmission record and history.
  • Deleted faxes — Recoverable for 30 days, then permanently and securely destroyed.
  • On cancellation — 30 days of read-only access to export anything you need. After the transition period, your fax content is securely destroyed where feasible.
  • Customer-initiated deletion — You can delete specific faxes at any time. Access-log entries are preserved so your audit trail stays complete.
Roadmap

What's next for security.

We don't claim what we haven't built. Here's what's actually planned.

Security is not a one-time effort. As we grow, here's what's planned for the LuzardoFax security program:

  • Hardware key support (FIDO2 / WebAuthn) — for high-security customers who want phishing-resistant 2FA.
  • IP allowlisting — under evaluation for Enterprise. Not available today.
  • Bug bounty program — once we cross certain volume thresholds, we'll launch a responsible disclosure program.
  • Third-party penetration testing — Annual external pen testing once our customer base reaches the volume that justifies it.
Why no SOC 2 promise?

SOC 2 audits cost $15-30k per year and require dedicated compliance staff. We could promise it for 2026 to sound impressive, but that wouldn't be honest. We'll pursue SOC 2 when our revenue justifies it — and we'll announce a real date, not a vague future. Until then, we lean on our hosting partners' audited controls (Vultr SOC 2 Type II, ISO 27001) and our own rigorous practices.

Have specific security questions?

Compliance officers, security teams, IT directors — we welcome the detailed questions. Our team will reply within one business day.