Security you can verify.
HIPAA-grade infrastructure. BAA with you on every paid plan.
Full encryption at rest and in transit. Audit logs you can export.
HIPAA on every paid plan.
No tiered "HIPAA add-ons" or enterprise-only compliance. Same protections at every level.
LuzardoFax is built from the ground up to meet HIPAA Security Rule requirements for Protected Health Information (PHI). Every paid plan — from Solo to Business — includes the same encryption, the same BAA terms, and the same audit infrastructure.
- Instant online BAA — signed during account onboarding with timestamp and IP capture. No printable PDFs to fax back, no manual paperwork.
- Subprocessor BAAs — Our BAA with Vultr (hosting) was executed on July 9, 2026 and is blockchain-anchored for independent verification. Telnyx (fax transport) states in its Terms of Service that it acts as a conduit for the transmissions it carries. On outbound faxes the document never leaves our servers: Telnyx receives a temporary tokenized URL back to us, valid for 30 minutes and revoked once the fax is sent. On inbound faxes the carrier necessarily receives the transmission and converts it before we retrieve it. As soon as our server has stored its own encrypted copy, we delete the carrier-side copy through their API and record the result in the audit log — so the window in which a copy exists outside our infrastructure is minutes, not the carrier’s retention period. If that deletion ever fails, it is logged and your fax is never at risk: our copy is already saved. We are in contact with Telnyx regarding a written agreement covering this position, and we keep a dated evidence record of their certifications and contractual terms. Email notifications are zero-PHI by design: they carry the page count, size and time, never the document, the sender or the recipient. The contact form is free text you write yourself, so we mask recognizable identifiers there before the message leaves our servers.
- HIPAA Privacy Rule — access controls, audit trails, breach notification procedures, and data minimization built in.
- HIPAA Security Rule — administrative, physical, and technical safeguards. Risk assessments performed before every major change.
HIPAA is not a certification — there's no certificate to frame on the wall. HIPAA is a set of rules we follow as a Business Associate. We sign a BAA with you, we follow the rules, and each subprocessor is handled according to its actual role: a signed BAA where one is required, the carrier conduit analysis for fax transport. The table below shows where each one stands today. That's how compliance actually works.
Independent proof of your signed BAA.
Your compliance evidence shouldn't depend on trusting your vendor's word.
Every signed BAA receives a cryptographic timestamp anchored to the Bitcoin blockchain, creating independently verifiable proof that the signed agreement existed at that point in time. The verification doesn't depend solely on LuzardoFax.
- What gets anchored — a SHA-256 hash of your executed BAA. The document itself is never published; only its fingerprint.
- How to verify — from Settings → Compliance you can download the signed BAA, the timestamp proof (.ots), and the evidence file, then verify at opentimestamps.org.
- Why it matters — in an audit, you can demonstrate your agreement existed at a specific point in time using a public, independent record.
- Also applied upstream — our own BAA with Vultr (hosting) is anchored the same way.
This isn't a crypto feature and it has nothing to do with coins or wallets. It's a well-established way to prove a document existed on a certain date without anyone having to take our word for it — including us.
Settings stored server-side.
Your account preferences belong to your account, not to one browser.
Your preferences are stored securely server-side and synchronized across your devices, rather than relying only on data stored in your browser.
- Consistent across devices — notification settings, language and interface preferences follow your login.
- Session tokens only — the browser holds session data and lightweight cache, not your account configuration.
- Revocable — sessions can be revoked server-side, which also applies when a user is deactivated.
Guidance that never touches your faxes.
The assistant helps you use the app. Fax content is excluded by architecture, not by policy.
Inside your account, “Ask me” answers questions about how to use LuzardoFax. It is built so that protected health information cannot reach it in the first place.
- What it can use — a limited whitelist of non-PHI account details: your plan, fax number, pages used in the current cycle, and days left in your billing cycle. That is the complete list.
- What it cannot access — fax documents, recipients, contacts, or any patient data. Fax content is architecturally excluded: the code that builds the assistant’s context never reads those tables.
- What you type is filtered too — the context we build carries no PHI, but you write the messages. Before a message leaves our servers we mask recognizable identifiers: phone and fax numbers, emails, dates, SSNs, record and policy numbers, and names introduced as a patient. The filter recognizes formats, not intent, so the chat still asks you not to enter patient details.
- What we store — usage metadata only (account, timestamp, token counts). The text of your messages is not persisted.
- Scope — the assistant explains how the product works. It will not discuss the contents of your faxes, and it points you to your own inbox for anything about your specific documents.
We could have let the assistant read your faxes to give richer answers. We deliberately did not. Sending PHI to a third-party model we do not have a BAA with would be exactly the kind of shortcut this product exists to avoid.
Faxes encrypted at every step.
From the moment a fax is sent or received to the moment you archive it years later.
- In transit — TLS 1.3 for all web traffic. TLS-encrypted SIP for fax transmission to Telnyx.
- At rest — the volume holding every fax PDF, the database and the logs is encrypted with LUKS2 (AES-256-XTS). Nothing lands on disk unencrypted, and the key never lives on the same volume it unlocks.
- Backups — Encrypted at rest with separate keys from production data. Stored in isolated environments.
- Email notifications — TLS-encrypted in transit via SendGrid. Zero-PHI by design: notifications never include the fax document, the sender or the recipient. The button opens your inbox at the same generic URL for everyone — there is no per-fax link and no token in the email, so you sign in to see anything.
- Passwords — bcrypt hashing with strong cost factors. We can't see your password — even we can't read it.
Built on audited cloud infrastructure.
We don't run our own data centers. We build on top of audited providers and add our application layer.
LuzardoFax production infrastructure runs on Vultr in their Miami, FL region. Vultr maintains SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, and HIPAA-aligned controls, with independently audited compliance reports available.
Important context: SOC 2 certifications belong to the provider, not us. Vultr's certifications validate that their infrastructure meets those standards — they don't automatically certify our application. Our responsibility is to configure their infrastructure correctly, sign the BAA with Vultr, and apply our own controls on top.
- Region — Production in Miami, FL; encrypted offsite backups in a second US region (US-only data residency)
- Network — DDoS mitigation, firewall isolation, private networking between services
- Backups — Daily encrypted backups with 90-day retention
- Monitoring — 24/7 infrastructure monitoring with automatic alerts
Only you. Only your team.
Strong authentication, role-based access, and granular audit trails.
- Two-factor authentication — Optional for every user on every plan. On Business and Enterprise, an account admin can require it for the whole team.
- Role-based access — On Business plans, admins control who has which permissions: send, receive, manage users, view audit logs.
- Session management — JWT tokens with reasonable expiry. Sessions revoked instantly on logout.
- Password requirements — Minimum length, complexity, and breached-password checks at signup.
- Account isolation — Multi-tenant architecture with strict account-level data separation enforced at every database query.
Full visibility into every action.
The compliance trail your auditor expects — accessible whenever you need it.
Every action a person takes on PHI is logged with timestamp, user, IP address and user agent: opening or downloading a fax, sending, receiving, deleting, restoring, purging, exporting, and every change to contacts, users, 2FA or account settings. Automated background processing (format conversion, carrier transmission, scheduled retention) is not logged per action; it is governed by the retention rules described below. Account admins can view and export logs anytime from the dashboard.
- Fax send / receive / view / download / delete events
- Login attempts (successful and failed)
- Settings changes (security, notifications, billing)
- User add / remove / permission changes
- BAA signing event with IP and timestamp
- Exports in CSV format · API access on every plan
Access logs are kept for the life of your account, so you always have a complete audit trail of who accessed what and when. Separately, the compliance documentation the HIPAA Security Rule requires us to maintain is retained for six (6) years under 45 CFR § 164.316(b)(2)(i).
Full transparency on third parties.
We publish the complete list of who touches your data and why.
Below is the live status of every subprocessor that can touch Protected Health Information. We publish it as-is rather than claiming blanket coverage. Where applicable, they also maintain their own SOC 2 / ISO certifications.
| Provider | Purpose | BAA | Region |
|---|---|---|---|
| Vultr | Cloud infrastructure hosting | Executed — July 9, 2026 | US (Miami, FL) |
| Telnyx | Fax transport (PSTN ↔ digital) | No signed BAA — conduit position | US |
| SendGrid | Transactional email delivery (zero-PHI by design) | Not required (no PHI handled) | US |
| Cloudflare | CDN & DDoS protection (no PHI in cache) | Not required (PHI never cached) | Global edge |
If we add or replace a subprocessor, we'll notify all customers 30 days in advance. Need the full list with effective BAA dates? Contact us — we'll send you a current copy.
If something goes wrong.
Documented procedures, fast notifications, full disclosure.
We follow the HIPAA Breach Notification Rule. In the event of any incident affecting PHI:
- Detection — 24/7 monitoring of infrastructure and application logs flags anomalies for review.
- Containment — Immediate isolation of affected systems and forensic preservation.
- Notification — Affected customers notified within statutory HIPAA deadlines (60 days max, typically much faster).
- Disclosure — Full transparency: what happened, what data was affected, what we're doing to prevent it again.
- Post-incident — Root-cause analysis, corrective actions documented, BAA review updated.
For security concerns or to report a vulnerability, email [email protected].
Your faxes, for as long as you need them.
No time limits, no storage tiers, no extra fees.
Received faxes, transmission records, and account history are stored for as long as your account is active — searchable, downloadable, and available 24/7 on every plan, Solo or Business, at no additional cost. You're always in control: download any fax as a PDF anytime to keep your own records.
- While active — Received faxes are searchable, downloadable, and available 24/7 in your inbox. For sent faxes, we keep the full transmission record and history.
- Deleted faxes — Recoverable for 30 days, then removed from our active systems (encrypted backups expire on their own cycle).
- On cancellation — 30 days of read-only access to export anything you need. After the transition period, your fax content is deleted from our active systems. Encrypted backups taken before that date expire on their own 90-day cycle, so a copy can remain in backup for up to 90 days longer. Backups are never restored except to recover from a failure, and the copy is destroyed when the backup expires.
- Customer-initiated deletion — You can delete specific faxes at any time. Access-log entries are preserved so your audit trail stays complete.
What's next for security.
We don't claim what we haven't built. Here's what's actually planned.
Security is not a one-time effort. As we grow, here's what's planned for the LuzardoFax security program:
- Hardware key support (FIDO2 / WebAuthn) — for high-security customers who want phishing-resistant 2FA.
- IP allowlisting — under evaluation for Enterprise. Not available today.
- Bug bounty program — once we cross certain volume thresholds, we'll launch a responsible disclosure program.
- Third-party penetration testing — Annual external pen testing once our customer base reaches the volume that justifies it.
SOC 2 audits cost $15-30k per year and require dedicated compliance staff. We could promise it for 2026 to sound impressive, but that wouldn't be honest. We'll pursue SOC 2 when our revenue justifies it — and we'll announce a real date, not a vague future. Until then, we lean on our hosting partners' audited controls (Vultr SOC 2 Type II, ISO 27001) and our own rigorous practices.
Have specific security questions?
Compliance officers, security teams, IT directors — we welcome the detailed questions. Our team will reply within one business day.