Compliance

You can review and sign a Business Associate Agreement (BAA) or Data Processing Agreement (DPA) in the mintfax dashboard. Both are available at every price tier, along with the data controls described below.

Encryption

Fax content is encrypted in storage using AES-256. mintfax manages and automatically rotates the encryption keys, with a separate content key for each environment. Database storage also uses the cloud provider’s encryption.

API requests and outbound webhooks use TLS 1.2 or higher. Webhook endpoints must use HTTPS.

These controls do not provide end-to-end encryption of a fax. The telephone network and the recipient’s fax system are outside mintfax’s control.

Content retention and deletion

Fax content is kept for 30 days by default. You can choose a period between 7 and 365 days for each environment, or delete an individual fax’s content through the API.

With zero-footprint mode enabled, mintfax deletes protected health information (PHI) as soon as the fax is delivered or fails. This includes the document, cover-page body, sender name, recipient name, and recipient company.

The destination number and operational records, such as status, error codes, timestamps, and attempt history, remain. Deleting content does not delete the fax record. Billing records are kept permanently.

See data retention for the policy and the developer guide for configuration.

Audit logs

The audit log records access to fax content, including access through the API, dashboard, and mintfax support tools. Staff access entries include a staff identifier and a reason.

Audit entries include linked hashes so you can check whether records have been altered. You can export them as JSON through GET /v1/account/audit or download CSV from the dashboard. Records are kept for six years.

Agreements and subprocessors

An authorized signer can review and accept the BAA or DPA in the dashboard, then download the signed PDF. mintfax records the signer, acceptance time, and agreement version. The two agreements are separate; you can sign whichever your organization needs.

Changes to primary subprocessors are announced at least 14 days in advance by email to account admins, a dashboard notice, and an Atom feed. The list also identifies standby providers that may be activated on short notice. Adding a standby provider requires the same advance notice.

Service limits

Data is stored in one US region. Region selection and customer-managed encryption keys are not available.

mintfax does not hold SOC 2, ISO 27001, HITRUST, FedRAMP, or PCI DSS Level 1 certification.

mintfax’s commitments cover its API infrastructure, content storage, operational databases, and application logs. They exclude upstream carriers, recipient fax systems, your webhook endpoints, and payment processors.

Keep your records

You can download your signed agreements and export the audit log for your own records. For implementation details, read the HIPAA guide and data retention guide.

START HERE

Try sending a fax in the sandbox.

Test the API with simulated deliveries before sending real faxes. The sandbox is free and does not require a credit card.

SANDBOXFree
SPECOpenAPI 3.1
CREDIT CARDNot required
WEBHOOKSSigned
ERRORSDocumented