Government and regulated workflows

Agency procurement readiness for FaxSeal

A practical review page for agencies evaluating FaxSeal as a fax transport, proof, and workflow layer. PHI and EMS workflows require a signed Enterprise BAA.

Readiness matrix

Contract-ready with agency terms

Agency-wide fax operations

Organization workspaces, SSO, shared fax numbers, audit-ready delivery receipts, API tokens, and exportable history are already present. Agency use should be governed by a signed order, support terms, and retention instructions.

Requires signed Enterprise BAA

PHI and EMS incident workflows

Self-service FaxSeal is not authorized for PHI. Patient, EMS, public-health, behavioral-health, or incident workflows may be used only after a countersigned Business Associate Agreement and agency-specific safeguards are in place.

Vendor review package required

Formal IT procurement

A procurement officer should receive security documentation, sub-processor list, DPA, support model, SLA targets, incident notice terms, disaster recovery targets, and the SOC 2 roadmap before production approval.

Transport-first unless contracted otherwise

System of record

FaxSeal is best positioned as the fax transport, receipt, and audit layer. If the agency wants FaxSeal to be the system of record, the contract must define retention, legal hold, export, deletion, and records-disposition responsibilities.

Contract targets

These are contract targets for agency agreements, not a change to the self-service Terms of Service.

Availability target

99.9% monthly

Critical support

4 hour first response

Standard support

1 business day first response

Security notice

72 hours after confirmation

Disaster recovery RPO

24 hours

Disaster recovery RTO

8 hours

Vendor packet contents

Security overview and sub-processor list

Data Processing Agreement

Business Associate Agreement for PHI workflows

Contracted SLA and support escalation terms

Incident response and breach-notice commitments

Retention, export, and deletion instructions

Disaster recovery targets and backup description

Accessibility, privacy, and acceptable-use documentation

SOC 2 roadmap and current control evidence

Implemented controls

TLS 1.2+ in transit and encrypted cloud object storage

Dedicated organization workspaces with role-based membership

SAML/OIDC SSO for enterprise organizations

Scoped API tokens with hashed token storage

Carrier status tracking with certified delivery receipts

SHA-256 document hash on delivery proof

Webhook signature verification and replay protections

Rate limiting and scanner-path blocking on public endpoints

Configurable contract layer for agency retention and PHI terms

Next procurement step

Send the agency use case, data classification, expected volume, retention needs, and whether PHI or EMS incident data will be transmitted.

Contact [email protected]Maine agency workflow guide