Built to pass your vendor review.
Recipient data in a breach matter is sensitive by definition. NotifyCertain handles it under the same audited program Electronic Output Solutions has run for regulated clients since 2001 — so your risk reviewer can approve us from this page.
SOC 2
Examined controlsOperations run under SOC 2 examined controls spanning security, availability, and confidentiality. A current report is available under NDA to firms evaluating us for panel placement.
HIPAA
Business associateWhere recipient data includes protected health information, we execute a Business Associate Agreement before intake. The BAA is incorporated into the applicable matter and governs handling, breach obligations, and return or destruction of data.
Data intake
EncryptedRecipient files are received only through channels that protect them end to end:
- Encrypted portal upload, or SFTP for firms that require it
- Encryption in transit and at rest
- No recipient data accepted by email
Access & logging
Least privilegeAccess to matter data is role-based and scoped to the individuals working the matter. Activity is logged, and our logging practice is designed so recipient identifiers do not appear in plain text outside the controlled production environment.
Retention & destruction
Per matterEach matter carries a defined retention and destruction schedule. After the return-mail window closes, recipient data is destroyed or returned per the BAA and engagement terms — except the records we must retain to evidence the mailing itself.
Subcontractors
None on dataComposition, printing, insertion, and mailing are performed in-house across our own California and Texas facilities. No third party touches recipient data, which removes an entire category of vendor-risk questions from your review.
Continuity
Dual facilityTwo production facilities provide built-in disaster recovery, so a single-site disruption does not put a deadline-driven mailing at risk.
Insurance & onboarding
Ready to signWe carry cyber liability and errors-and-omissions coverage and provide certificates on request. W-9, certificate of insurance, and completed vendor security questionnaires are returned within one business day.
Security overview for your file
A one-document summary of controls, agreements, and data handling — formatted for a vendor risk review. We'll send it along with a current certificate of insurance.