Security & Compliance at Click2Mail

Last reviewed: August 4, 2026

Click2Mail handles other people's mail. Legal notices, patient statements, invoices, court correspondence. That means we handle other people's data — names, addresses, account numbers, and sometimes protected health information — and we treat the safeguarding of that data as a core operational function rather than a marketing exercise.

This page describes our certifications, our controls, and the boundaries of what we do and do not support. If you need documentation beyond what's here, see Requesting Documentation.

1. Who we are

Click2Mail and Click2Mail.com are trade names of C2M, LLC, a Delaware limited liability company headquartered at 3103 10th Street N, Suite 201, Arlington, Virginia 22201-2191. We have operated a cloud-based print-to-mail service continuously since 2003.

This overview covers the Click2Mail service and the properties that run on it: Click2Mail.com, Click2EDDM.com, Click2Mail Connect, MailJack+, MailMyPDF, MailJack Automate, and the Click2Mail Dashboard, ZendaNote, and Mail-It Now mobile applications.

C2M, LLC is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.

2. How we handle your data

Click2Mail distinguishes three categories of data, and our obligations differ for each:

Customer Information — your account details, contact information, and payment data. Click2Mail acts as a controller of this data.

Printed Material — the documents you send us to print and mail. Click2Mail acts as a processor. We print what you direct us to print.

List Information — the recipient records you supply. Click2Mail acts as a processor.

Our commitments regarding this data:

  • We do not sell, trade, or rent your Printed Material or List Information to anyone, ever.
  • We do not sell, trade, or rent your Customer Information — including your name and address — for third-party marketing purposes.
  • We do not read or disclose the contents of the postal communications you transmit through our service, except as required to operate the service or as required by law.
  • Documents and lists you submit are used solely to produce the mailing you requested.
  • We do not permit third-party tracking or targeted advertising cookies on our websites or within our service.
  • If we ever want to use your data for a purpose other than the one you gave it to us for, we will ask you to opt in first.

One disclosure we make explicitly: Click2Mail and its production vendors cooperate with the U.S. Postal Service and with law enforcement to demonstrate compliance with postal regulations. This is an unavoidable condition of operating as a mailer, and we would rather you read it here than discover it in a policy footnote.

3. Certifications and attestations

SOC 2

Click2Mail maintains a SOC 2 Type II attestation, independently audited by Johanson Group, AICPA License #5000094 against the AICPA Trust Services Criteria for Security and Confidentiality. The current report covers the period January 1, 2025 through December 31, 2025. Customers and prospective customers may request the report under NDA — see Requesting Documentation.

PCI DSS Attestation of Compliance

Click2Mail validates its compliance with the PCI Data Security Standard annually. Payment card data is handled by our PCI DSS Level 1 certified payment processor; Click2Mail does not store cardholder account numbers. Our current Attestation of Compliance is available on request.

EU-U.S., UK, and Swiss Data Privacy Framework

Click2Mail is certified with the U.S. Department of Commerce under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework. Our certification is publicly viewable at dataprivacyframework.gov .

We comply with the DPF Principles for all onward transfers of personal data from the EU, UK, and Switzerland, and we remain liable if a third-party agent processes that data inconsistently with the Principles. Personal data transferred to Click2Mail from the EU, UK, or Switzerland is processed and stored in the United States. See Data residency in Technical safeguards.

Unresolved privacy complaints under the DPF are referred to an independent dispute resolution mechanism operated by BBB National Programs, free of charge to the complainant. Binding arbitration is available for certain residual claims.

Microsoft 365 App Certification

The Click2Mail add-in for Microsoft Word has completed Microsoft 365 App Certification, a third-party review of data handling, security, and compliance posture published in the Microsoft app catalog.

What we do not currently hold

  • Click2Mail does not currently hold ISO 27001 certification.

4. HIPAA

Click2Mail routinely mails protected health information on behalf of covered entities and business associates. C2M, LLC is fully committed to complying with HIPAA and maintains a designated Compliance Officer.

Business Associate Agreements

We execute a Business Associate Agreement with any customer who requires one. Email [email protected] and our Compliance Officer will contact you to prepare the agreement.

Scope exclusions — read this before you send PHI

Click2Mail's HIPAA-compliant mailing scope does not include:

  • Self-mailers
  • Postcards
  • Open-faced cards
  • Any mailpiece submitted through Email-to-Mail

These formats either expose content to view in the mailstream or transit an unencrypted channel. If your mailing contains PHI, use a full-service envelope product submitted through the Click2Mail web application, the API, MailJack+, Automate or Click2Mail Connect.

5. USPS credentials and postal compliance

Click2Mail is an authorized affiliate of the United States Postal Service under license. We hold several USPS Mailer IDs (MID), CRIDs, and a Full-Service, Seamless certification. Our address standardization software is CASS-certified and our presort software is PAVE-certified.

Our postal operations include:

Intelligent Mail barcode (IMb). Click2Mail applies IMb to mailpieces and provides tracing through USPS Informed Visibility. IMb tracing has been available on most products since September 2009. Note: First-Class IMb tracing does not include a delivery scan. For confirmed delivery, use Certified Mail with Return Receipt or Priority Mail with Delivery Confirmation or both.

CASS certification. Address lists are processed through CASS-certified software before printing, standardizing and validating ZIP+4 and delivery point codes against USPS records.

NCOALink / Move Update. Click2Mail runs Move Update address correction against USPS change-of-address data as a standard part of list processing, at no additional charge. Addresses with a filed forwarding order are corrected before the mailpiece is printed.

Presort and worksharing. Mail is prepared, presorted, packaged, labeled, and trayed to USPS automation standards, and the resulting aggregated postage discount is passed through to you.

Certified Mail. Certified Mail is available with electronic or physical green card Return Receipt. Click2Mail does not enable customers to print Certified Mail labels or postage themselves; these are produced in our facilities.

Certificate of Mailing (CoM). An official USPS record documenting the date the mailpiece was received by the USPS, including the sender, the recipient, and the date of mailing. A Certificate of Mailing does not provide proof of delivery.

Verified Mail Record (VMR). An official Click2Mail record documenting the dispatch, induction and complete lifecycle of the mailpiece, including the sender, the addressee and the time and date of mailing. Each digitally archived VMR includes the complete document as mailed by Click2Mail with a cryptographic hash for integrity verification, and all associated USPS Informed Visibility (IV) scan events, including a logical/virtual delivery scan when made available by USPS. A VMR is evidence of mailing. It is not proof of delivery and it is not a proof of service.

6. Technical safeguards

  • Encryption in transit: All data is encrypted in transit using TLS 1.3.
  • Encryption at rest: Data at rest is encrypted using standard AES 256 encryption.
  • Authentication: Access to all systems and applications requires a unique username and password. MFA is enforced for all administrative accounts. Policies are enforced through our SSO and directory services manager.
  • Access control: We utilize role-based access control and least privilege access. Administrators and developers can see data if their job/role requires it to perform their duties.
  • Audit logging: All system activity, including PHI and document access, is logged. Logs are not available to customers.
  • Data retention and destruction: Customer job data is retained for 12 months from the mailing date — a 90-day fulfillment window plus nine months for USPS regulatory retention — and is then subject to deletion.
  • Vulnerability management: Annual penetration testing is conducted by Cobalt Labs, Inc. The current report covers testing completed in March 2025. The 2026 testing has been conducted and delivery of the report is pending. Customers and prospective customers may request the Executive Summary under NDA — see Requesting Documentation.
  • Subprocessors: See List of Subprocessors.
  • Data residency: All customer data is stored and processed in the United States. Printed Material and List Information are produced at Click2Mail facilities located in the United States. Click2Mail does not transfer customer data outside the U.S. for processing or production.

7. Business continuity and disaster recovery

Click2Mail maintains a documented Business Continuity and Disaster Recovery Plan, reviewed and tested annually.

Data backup: Click2Mail's IT systems are fully hosted in the cloud in AWS US-East-1 region with a mirrored recovery site stored at AWS US-West-2 region. Full backups are run weekly, supplemented with daily snapshots. Backups are rotated to keep a weekly and monthly backup available for one year.

Recovery objectives: Recovery Time Objective of 24 hours; Recovery Point Objective of 24 hours.

Production continuity: Mail production is distributed across multiple U.S. facilities. If a single facility becomes unavailable, non-HIPAA orders can be rerouted to an alternate production site.

System status: Current status, uptime, and incident history are available at status.click2mail.com .

8. Physical and personnel safeguards

Click2Mail's production facilities are physically secured and visitors are logged in and out. Assigned employees undergo background checks, sign confidentiality agreements, and receive annual HIPAA and security awareness training. All misprints and spoilage are destroyed securely. Mail containing PHI or otherwise designated for secure handling is produced at facilities with electronic badge access control, surveillance monitoring, and visitor logging.

9. Privacy and your rights

Our full Privacy Policy governs. In summary:

  • You may review, correct, or delete personal information we hold about you by contacting [email protected].
  • EU, UK, and Swiss individuals have the rights described under the DPF Principles, including access, correction, deletion, and independent recourse through BBB National Programs.
  • You may manage communication preferences in your account settings and unsubscribe from marketing email at any time.
  • We provide opt-out choice before sharing data with any third party other than our service providers, and opt-in for sensitive data.

10. Incident response and breach notification

  • We have a documented Incident Response Policy and an Incident Response Plan which are reviewed and tested annually. The Incident Response Team is led by a designated Security Officer.
  • We will notify you without undue delay after becoming aware of a security incident or nonpermitted use or disclosure.
  • Security contact for responsible disclosure [email protected]
  • We carry cyber security and technology insurance to mitigate the impact of a cyber intrusion with an aggregate limit of $5 million.

11. Requesting documentation

You need Contact Notes
SOC 2 report & bridge letter [email protected] Under NDA
HIPAA Business Associate Agreement [email protected] Compliance Officer will contact you
Completed security questionnaire (CAIQ, custom) [email protected]
List of subprocessors [email protected]
Uptime / incident history https://status.click2mail.com/
Privacy or data-rights request [email protected]
Responsible disclosure of a vulnerability [email protected]
Pen test executive summary [email protected]

12. Document control

Version Date Author Changes
1.0 August 4, 2026 Teri Drakopulos Initial publication

Click2Mail reviews this overview at least annually and subsequent to any material change to our certifications or controls.