Supafax is built on a simple principle: read only what's needed, store nothing, never send or delete anything. Here's how it works under the hood, and the controls we're have in place.
Three guarantees, built in at the architecture level - not bolted on.
Nothing stored. Emails are processed with our AI then discarded. We never keep copies of anything on our servers.
You approve every send. Supafax drafts and organizes - but it can never send or delete emails.
Encrypted end-to-end. AES-256 at rest, TLS 1.3 in transit, Google-verified OAuth. Revoke access anytime from your Google account.
We're actively pursuing the certifications enterprise security teams look for. Every framework listed below is underway with an independent auditor - progress and scope available on request.

Annual independent audit of security, availability, and confidentiality controls.

Globally recognized information security management standard.

EU data subject rights, DPAs, and sub-processor transparency.

Administrative, technical, and physical safeguards for PHI in healthcare inboxes.