NEW!

Security Statement

How PayPerFax protects your document in transit and at rest, who can access it, and the one segment of a fax transmission that cannot be encrypted.

This document explains how PayPerFax protects a fax document from upload through transmission: who can access it, how it is encrypted at each step, and where encryption ends. It is the authoritative source for these claims across the site.

The document’s journey

A fax handled by PayPerFax passes through several stages under our control before a final leg that is not.

Uploads to our servers travel over TLS.

Uploaded documents, previews, and transmitted fax images are encrypted at rest on our systems with AES-256. Encryption is applied server-side by our storage provider using provider-managed keys, is enabled by default, and cannot be turned off.

Traffic between our systems and the services that process data on our behalf is encrypted in transit.

The final leg, from our transmission provider to the receiving fax machine, travels over the public switched telephone network. This leg is not encrypted. The public phone network does not encrypt calls, and the ITU-T Group 3 and Group 4 fax protocols do not add encryption on top of it. No fax provider can change this. It is the same for a fax sent from any physical fax machine or through any other fax service.

Internal access

Uploaded documents are accessible only to the highest administrative tier at PayPerFax, and only for the operational purposes set out in the Data Retention Policy. No other role has read access to document contents. For the third-party services that process data on our behalf, see the Privacy Policy.

Terminology

We say TLS rather than SSL. SSL is the obsolete name for the same idea and still appears in some older material on the site.

Where our material calls the portal “end-to-end”, the meaning is that the browsing and upload session is served over HTTPS throughout. It does not mean end-to-end encryption of the fax itself, which is not achievable on the public telephone network.

Security contact

Report a suspected vulnerability or security concern through the contact form. Include enough detail for us to reproduce the issue: what you did, what you expected to happen, and what you observed.

Last reviewed/updated: July 30, 2026