If you work in a regulated field - accounting, financial advice, lending, legal or healthcare - and need to assess Fax.Plus as a vendor, this page answers the questions compliance teams ask most often and points you to the documentation behind each answer.
Need our reports? Our SOC 2 Type 2 report, ISO/IEC 27001 certificate, penetration test report and CSA STAR documentation are available through the Alohi Trust Center. See How to request compliance documentation for due diligence.
Certifications and compliance
Which certifications does Fax.Plus hold?
SOC 2 Type 2 and ISO/IEC 27001. Fax.Plus also complies with HIPAA, PHIPA, FERPA, DORA, PCI-DSS, GDPR and CCPA. Details for each are on our compliance page.
Is Fax.Plus GLBA compliant? Do you have a certification letter?
There is no certification or certification letter for the Gramm-Leach-Bliley Act (GLBA). GLBA obligations apply to financial institutions rather than to their vendors. Alohi acts as a service provider that supports our customers’ GLBA programs. Financial institutions can use our SOC 2 Type 2 report and ISO 27001 certification as evidence when assessing us as a service provider under the GLBA Safeguards Rule. Both are independently audited and address the administrative, technical and physical safeguards the rule requires. Reports are available under NDA via our Trust Center.
Can I use Fax.Plus for health information (HIPAA)?
Yes, on eligible plans with a signed Business Associate Agreement (BAA). See Can I use Fax.Plus for HIPAA-protected faxes?
Data protection
Is my data encrypted?
Yes. Faxes are encrypted in transit with TLS and at rest with AES-256. See How do we ensure sending information via Fax.Plus is secure?
Where is my data stored?
Alohi is based in Switzerland and protects all user data under the Swiss Federal Act on Data Protection. Data residency options let you choose where your data is stored and processed - see Data residency.
How long are faxes kept? Can we delete them?
- By default, faxes are kept in encrypted storage with no time limit.
- On the Enterprise plan, you can set a retention period from 1 day to 5 years, after which faxes are deleted automatically, or turn storage off entirely.
- On any plan, you can delete individual faxes yourself.
Access control
Is two-factor authentication (2FA) available?
Yes, for every user on every plan. We recommend requiring it for your whole team.
Can several employees have their own logins?
Yes, on the Business and Enterprise plans. One plan covers the whole team: an admin adds and removes users, assigns fax numbers and sets page quotas per user. Premium is a single-user plan.
Do you support single sign-on (SSO)?
Yes - see How can I activate Single Sign-On (SSO)?
Records and proof of delivery
Can we see who sent each fax?
Each fax record shows the sender, the recipient number, the date and time, and the delivery status.
Do we get a delivery confirmation we can keep?
Yes. Every sent fax has a confirmation report showing its delivery status, pages and transmission details, which you can download or print for your records.
Recommended setup for regulated teams
- Require 2FA (or SSO) for every user.
- Set a retention period that matches your recordkeeping policy (Enterprise), and keep confirmation reports for faxes you need to document.
- Use cover sheets, which can be enforced across the team.
- Have a named admin manage users, so access is removed as soon as someone leaves.
Questions not covered here?
For security questionnaires or vendor assessment forms, contact support@alohi.com. To report a security concern, email security@alohi.com.