Trust & compliance.
We run a regulated communications platform. This page documents how we protect data, how we comply with U.S. and international telecom rules, and how to reach us if something goes wrong.
01Overview
Message.com LLC is a unified customer-conversation platform headquartered in Houston, Texas. We operate chat, ticketing, voice, and SMS services across 60+ countries and we hold ourselves to the security, privacy, and telecommunications-compliance posture that responsible carriers expect from their resellers.
This page summarises that posture and links out to the underlying policies. The detail lives in our Privacy Policy, Terms of Use, and Acceptable Use Policy.
02Security
We protect customer data with a layered programme of administrative, technical, and physical controls.
- Encryption in transit. TLS 1.2 or higher for all customer connections; HSTS enforced on message.com and app.message.com.
- Encryption at rest. AES-256 for databases, object storage, and backups. Call recordings encrypted at rest with per-tenant keys.
- Access control. Role-based access with least-privilege defaults. Mandatory multi-factor authentication for every employee. Production access is logged and reviewed.
- Network. Private VPCs, WAF and DDoS protection at the edge (Cloudflare), and continuous vulnerability scanning.
- Application security. Static analysis on every pull request, dependency scanning, and quarterly penetration testing by an independent firm.
- Incident response. A documented IR plan with 24/7 on-call rotation. We notify affected customers and regulators within 72 hours of a confirmed incident where required by law.
- Backups. Encrypted, geographically separated, retained for 35 days; tested restore quarterly.
03Privacy and data residency
- GDPR and UK GDPR compliant. Standard Contractual Clauses (SCCs) and UK IDTA executed with all sub-processors where required.
- CCPA / CPRA, VCDPA, CPA, and CTDPA aligned. Data-subject requests handled within statutory timeframes.
- HIPAA-aligned controls; Business Associate Agreements available for Healthcare-plan customers.
- Customer Data is never used to train AI models.
- Sub-processor list is public, see below and the Privacy Policy.
04Telecom compliance
Message operates as a communications platform built on top of regulated U.S. and international carrier infrastructure. We comply with the obligations that apply to non-facilities-based resellers under the Communications Act of 1934, the TRACED Act, the FCC's 47 CFR Part 64, and equivalent rules in the jurisdictions we serve. The sections below detail the specific frameworks that apply.
05STIR/SHAKEN
Message participates in the STIR/SHAKEN caller-ID authentication framework through our upstream carriers. Outbound voice traffic is signed with:
- A-level attestation, for numbers we have verified the customer is authorised to use (ported in, provisioned by Message, or documented via Letter of Authorisation)
- B-level attestation, for numbers we have associated with the customer but cannot fully verify
- C-level attestation, for transit traffic or numbers we cannot associate with a Message customer
Our Acceptable Use Policy forbids customers from spoofing numbers they do not own. We honour Industry Traceback Group (ITG) requests, FCC traceback orders, and carrier-of-record requests, and we cooperate with the Robocall Mitigation Database (RMD) framework.
06TCPA and DNC
Customers using Message Phone for outbound calling or messaging must comply with the Telephone Consumer Protection Act of 1991, the FCC's implementing rules, and corresponding state laws.
- Prior express written consent is required for autodialed or pre-recorded calls and texts to mobile and residential numbers
- The National Do Not Call Registry must be scrubbed at least every 31 days; state DNC lists must be respected where stricter
- Internal company-specific DNC requests must be honoured for at least five years
- Calling hours are 8:00am–9:00pm in the called party's local time, subject to stricter state limits
- A2P SMS via 10DLC requires brand and campaign registration through The Campaign Registry before traffic is enabled; opt-in records must be retained for at least four years
The Acceptable Use Policy contains the full set of obligations.
07Customer Proprietary Network Information (CPNI)
Message safeguards Customer Proprietary Network Information as defined under Section 222 of the Communications Act and 47 CFR §64.2001 et seq.
- CPNI is used only to provide the service the Customer subscribes to, to bill for that service, and for purposes permitted by law
- CPNI is not shared with marketing affiliates or sold to third parties
- Customer authentication is required before disclosing CPNI; password reset and security-question flows comply with the FCC's 2007 CPNI Order
- CPNI breaches are reported to the U.S. Secret Service and the FBI within seven business days, and to affected customers as required
- We file the annual CPNI compliance certification (FCC Form, EB Docket No. 06-36) by 1 March each year
Our written CPNI compliance policy is available to upstream carriers and regulators on request at [email protected].
08E911 service
Message Phone is an interconnected VoIP service. Emergency calling on VoIP differs from traditional telephone service:
- Each phone number used for outbound calling must have a Registered Service Address on file. Customers are required to keep this address current.
- Emergency calls are routed to the Public Safety Answering Point (PSAP) serving the Registered Service Address, not the physical location of the device at the time of the call.
- If power or internet is lost, emergency calling is unavailable. Customers are notified of this limitation at sign-up and in the product UI.
- Acknowledgement of the E911 limitation is captured during number provisioning.
09Number porting
We honour the FCC's local-number-portability rules and our upstream carriers' port-in and port-out procedures.
- Port-in. Free of charge. We submit valid Letters of Authorisation to the losing carrier within one business day of receiving them. Typical port-in completes in 2–4 weeks, controlled by the losing carrier.
- Port-out. No port-out fees, no withholding. We release the number to the gaining carrier within 24 hours of a validated port request, subject to the FCC's 2009 anti-slamming rules.
- Anti-port-out fraud. Port-out requests are authenticated; suspicious requests are flagged to the Customer before release.
10Abuse handling
- Abuse reports acknowledged within 24 hours; investigation within 5 business days
- Traceback requests from the Industry Traceback Group and law-enforcement authorities responded to within the timeframes required by the TRACED Act
- Confirmed violations result in number disablement, campaign suspension, account termination, and notification to upstream carriers and the Robocall Mitigation Database where required
- Severe violations (illegal robocalls, fraud, CSAM, threats to life) are escalated immediately and preserved for lawful disclosure
11Sub-processors
The full sub-processor list is in our Privacy Policy. Customers are notified at least 30 days before a new sub-processor is engaged. Telecom-relevant sub-processors include:
- Carrier-grade SIP partners, voice trunking, DIDs, SMS
- DigitalOcean, LLC, compute, managed database, object storage
- Cloudflare, Inc., edge security and DDoS mitigation
- Stripe, Inc., subscription billing
12Certifications and registrations
- SOC 2 Type II, audit in progress; Type I report available on request under NDA
- GDPR, compliant; DPA available on request
- HIPAA, aligned; BAA available for Healthcare-plan customers
- FCC Registration Number, 0038415493. Registered as a non-facilities-based provider of interconnected VoIP and messaging services. Verifiable in the FCC's CORES public lookup.
- The Campaign Registry (TCR), registered Campaign Service Provider (CSP) for A2P 10DLC messaging
- Robocall Mitigation Database, entry filed May 13, 2026 under Message.com LLC. Verifiable in the FCC's RMD public lookup.
13Report an issue
Security vulnerabilities, [email protected], acknowledged within 24 hours, every day.
Abuse, spam, fraud, [email protected], acknowledged within 24 hours.
Traceback requests, [email protected], for ITG and law-enforcement authorities.
Privacy and data-subject requests, [email protected]
Legal notices, [email protected]
General, [email protected] · (844) 600-8444
Mailing address for legal process:
Message.com LLC, 363 North Sam Houston Pkwy E, Suite 125, Houston, TX 77060, United States.