Security & Compliance

Built to pass your vendor review.

Recipient data in a breach matter is sensitive by definition. NotifyCertain handles it under the same audited program Electronic Output Solutions has run for regulated clients since 2001 — so your risk reviewer can approve us from this page.

SOC 2

Examined controls

Operations run under SOC 2 examined controls spanning security, availability, and confidentiality. A current report is available under NDA to firms evaluating us for panel placement.

HIPAA

Business associate

Where recipient data includes protected health information, we execute a Business Associate Agreement before intake. The BAA is incorporated into the applicable matter and governs handling, breach obligations, and return or destruction of data.

Data intake

Encrypted

Recipient files are received only through channels that protect them end to end:

  • Encrypted portal upload, or SFTP for firms that require it
  • Encryption in transit and at rest
  • No recipient data accepted by email

Access & logging

Least privilege

Access to matter data is role-based and scoped to the individuals working the matter. Activity is logged, and our logging practice is designed so recipient identifiers do not appear in plain text outside the controlled production environment.

Retention & destruction

Per matter

Each matter carries a defined retention and destruction schedule. After the return-mail window closes, recipient data is destroyed or returned per the BAA and engagement terms — except the records we must retain to evidence the mailing itself.

Subcontractors

None on data

Composition, printing, insertion, and mailing are performed in-house across our own California and Texas facilities. No third party touches recipient data, which removes an entire category of vendor-risk questions from your review.

Continuity

Dual facility

Two production facilities provide built-in disaster recovery, so a single-site disruption does not put a deadline-driven mailing at risk.

Insurance & onboarding

Ready to sign

We carry cyber liability and errors-and-omissions coverage and provide certificates on request. W-9, certificate of insurance, and completed vendor security questionnaires are returned within one business day.

Security overview for your file

A one-document summary of controls, agreements, and data handling — formatted for a vendor risk review. We'll send it along with a current certificate of insurance.

Request the overview

Ready to add us before the incident?

Set up a standing MSA and BAA so matter one starts at intake, not paperwork.