HTTPS and private configuration
Production traffic is forced over HTTPS. Database bootstrap credentials and the local encryption key stay outside public pages, and integration secrets stored in the database are encrypted with the server-side key.
The service is built with practical safeguards around the parts that can cost money, expose documents or trigger duplicate delivery.
Production traffic is forced over HTTPS. Database bootstrap credentials and the local encryption key stay outside public pages, and integration secrets stored in the database are encrypted with the server-side key.
Media links used by the fax provider are signed and short-lived. Provider webhooks are verified before order state is trusted, and duplicate webhook events are handled idempotently.
Checkout is rate-limited, exact duplicate submissions can be blocked, order size and amount have hard limits, and international checkout can remain locked until pricing and allowed destinations are verified.
If a provider timeout makes it unclear whether a fax was accepted, FaxAtlas stops blind retries and sends the order to review instead of risking duplicate transmissions.
File signatures and dimensions are validated. Password-protected PDFs are blocked before payment, and uploaded documents are scheduled for deletion after the configured retention period.
Use the support form and include your FaxAtlas order number if you have one.