Fax privacy and security

What is protected, what is not, and what you can do about it.

A fax is not end-to-end encrypted, and no service can make it so: the T.30 protocol provides no encryption, and the last leg to the fax machine travels the telephone network in the clear. What MondialFax encrypts is the path between your browser and its servers, where the document is deleted once the fax has gone. In practice the real risk is almost never someone tapping the line: it is the page coming out on a shared machine, and the mistyped number.

Where a fax is really exposed

Ordered by how often it actually happens, not by how dramatic it sounds. The first three have nothing to do with cryptography.

  1. 1

    The page coming out on a shared machine

    This is the number one risk, by a wide margin. The document arrives printed on a device sitting in a corridor, a mail room or a reception desk, and stays there until somebody collects it. Nobody needs to tap a line to read it.

  2. 2

    The mistyped number

    One digit off and your document goes to a stranger, with no way to recall it and often without your knowing: a fax delivered to a wrong but valid number is a successful transmission as far as the machine is concerned.

  3. 3

    The device's memory

    Office multifunction machines keep sent and received pages in internal memory, sometimes on a disk, and print a transmission log. A device resold or scrapped without being wiped takes those pages with it.

  4. 4

    The fax received by email

    A fax-to-email gateway turns your document into an attachment. Its confidentiality then becomes that of the mailbox hosting it: backups, synced devices, provider access, retention period. That is not worse, it is different — and it deserves to be a decision rather than a surprise.

What MondialFax does, and what it does not

Stated precisely, because a service promising more than it can deliver makes you take risks without knowing it.

The path to our servers is encrypted
Your document travels from your browser to our servers over an encrypted connection. The next leg, from our servers to the receiving fax machine, uses the telephone network: nobody encrypts that leg, neither we nor a competitor.
The document is deleted after sending
Once the transmission is complete, the file is deleted from our servers. It is neither archived, indexed nor analysed, and it serves no purpose other than being sent.
There is no account, so there is no history
MondialFax asks for no registration. There is therefore no personal area holding your past sends, and nothing to compromise that would bring them together.
No advertising is inserted
The document transmitted is exactly the one you uploaded. The service is free, but it does not pay for itself by adding anything to your pages.

Five precautions that make a difference

  1. Read the number back before sending

    This is the single most effective measure on this page. Check the country code, then the number digit by digit, especially when copying it from a letter or a website.

  2. Tell the recipient it is coming

    A call or a message before you send, and the page is collected on arrival instead of waiting on the device. It is the direct counter-measure to the number one risk.

  3. Add a cover sheet

    It states who the transmission is for and lets whoever finds it know they should not read on. A confidentiality notice has no binding force, but it does get read.

  4. Send less

    Redact what the recipient does not need: a full social security number, bank details, a date of birth irrelevant to this file. What is not transmitted cannot leak.

  5. Keep the acknowledgment

    It records which number answered, when, and how many pages went through. That is what lets you notice quickly that something went to the wrong place, rather than finding out weeks later.

What a fax will never guarantee

A fax does not protect the document after it arrives. Once the page is out it lives its own life: put down, photocopied, filed or forgotten on a tray, and no technical property of the protocol changes that. If your requirement is about what happens after arrival, the channel is not the lever — the recipient's own procedure is.

Nor does a fax prove who read the page. It proves that a device attached to a given number received a number of pages at a given time, which is already more than email provides, but it is not an identification of a person. For documents whose confidentiality is genuinely critical, an end-to-end encrypted and authenticated channel remains better — when the recipient accepts one.

Frequently asked questions

Is a fax encrypted?
The T.30 protocol provides no encryption: over the telephone line the transmission travels in the clear. Online services encrypt the path between you and their servers — that is what MondialFax does — but the last leg to the fax machine is still the telephone network. A service promising you end-to-end encryption on a fax is promising something that does not exist.
Is a fax safer than an email?
Differently, not absolutely. A fax travels in the clear over the phone network, but leaves no copy stored at a provider and is not exposed to a mailbox breach. An email can be encrypted, but it crosses and rests with several intermediaries. Both have weaknesses; they are simply not in the same place.
What happens to my document after sending?
It is deleted from our servers once the transmission is complete: no archiving, no indexing, no analysis. What remains is the page at the recipient's end, over which we obviously have no control.
Can I send a medical or legal document by fax?
Such documents go by fax every day, and it is often the recipient who requires it. The precautions to take are the ones on this page — check the number, warn them, send less. If your organisation is subject to specific obligations on health data or court filings, which channel is permitted is settled with your compliance contact, not with a website.

The most useful pages to carry on with your fax.