messagemessage.com
  • Products
  • Solutions
  • Pricing
  • Customers
  • Resources
  • Docs
Sign inStart free→
  • Products
    • Unified Inbox
    • Live Chat
    • Tickets
    • Phone
    • message.ai
    • Knowledge Base
  • Solutions
    • Ecommerce
    • SaaS
    • Healthcare
    • Education
    • Financial services
    • Real estate
  • Pricing
  • Customers
  • Resources
    • Help center
    • Blog
    • Community
    • Why message
    • Developers
    • Apps
  • Docs
Sign inStart free trial →
Trust

Trust & compliance.

We run a regulated communications platform. This page documents how we protect data, how we comply with U.S. and international telecom rules, and how to reach us if something goes wrong.

Last updated May 13, 2026Security [email protected]Abuse [email protected]
On this page
  1. Overview
  2. Security
  3. Privacy and data residency
  4. Telecom compliance
  5. STIR/SHAKEN
  6. TCPA and DNC
  7. CPNI
  8. E911 service
  9. Number porting
  10. Abuse handling
  11. Sub-processors
  12. Certifications
  13. Report an issue

01Overview

Message.com LLC is a unified customer-conversation platform headquartered in Houston, Texas. We operate chat, ticketing, voice, and SMS services across 60+ countries and we hold ourselves to the security, privacy, and telecommunications-compliance posture that responsible carriers expect from their resellers.

This page summarises that posture and links out to the underlying policies. The detail lives in our Privacy Policy, Terms of Use, and Acceptable Use Policy.

02Security

We protect customer data with a layered programme of administrative, technical, and physical controls.

  • Encryption in transit. TLS 1.2 or higher for all customer connections; HSTS enforced on message.com and app.message.com.
  • Encryption at rest. AES-256 for databases, object storage, and backups. Call recordings encrypted at rest with per-tenant keys.
  • Access control. Role-based access with least-privilege defaults. Mandatory multi-factor authentication for every employee. Production access is logged and reviewed.
  • Network. Private VPCs, WAF and DDoS protection at the edge (Cloudflare), and continuous vulnerability scanning.
  • Application security. Static analysis on every pull request, dependency scanning, and quarterly penetration testing by an independent firm.
  • Incident response. A documented IR plan with 24/7 on-call rotation. We notify affected customers and regulators within 72 hours of a confirmed incident where required by law.
  • Backups. Encrypted, geographically separated, retained for 35 days; tested restore quarterly.

03Privacy and data residency

  • GDPR and UK GDPR compliant. Standard Contractual Clauses (SCCs) and UK IDTA executed with all sub-processors where required.
  • CCPA / CPRA, VCDPA, CPA, and CTDPA aligned. Data-subject requests handled within statutory timeframes.
  • HIPAA-aligned controls; Business Associate Agreements available for Healthcare-plan customers.
  • Customer Data is never used to train AI models.
  • Sub-processor list is public, see below and the Privacy Policy.

04Telecom compliance

Message operates as a communications platform built on top of regulated U.S. and international carrier infrastructure. We comply with the obligations that apply to non-facilities-based resellers under the Communications Act of 1934, the TRACED Act, the FCC's 47 CFR Part 64, and equivalent rules in the jurisdictions we serve. The sections below detail the specific frameworks that apply.

05STIR/SHAKEN

Message participates in the STIR/SHAKEN caller-ID authentication framework through our upstream carriers. Outbound voice traffic is signed with:

  • A-level attestation, for numbers we have verified the customer is authorised to use (ported in, provisioned by Message, or documented via Letter of Authorisation)
  • B-level attestation, for numbers we have associated with the customer but cannot fully verify
  • C-level attestation, for transit traffic or numbers we cannot associate with a Message customer

Our Acceptable Use Policy forbids customers from spoofing numbers they do not own. We honour Industry Traceback Group (ITG) requests, FCC traceback orders, and carrier-of-record requests, and we cooperate with the Robocall Mitigation Database (RMD) framework.

06TCPA and DNC

Customers using Message Phone for outbound calling or messaging must comply with the Telephone Consumer Protection Act of 1991, the FCC's implementing rules, and corresponding state laws.

  • Prior express written consent is required for autodialed or pre-recorded calls and texts to mobile and residential numbers
  • The National Do Not Call Registry must be scrubbed at least every 31 days; state DNC lists must be respected where stricter
  • Internal company-specific DNC requests must be honoured for at least five years
  • Calling hours are 8:00am–9:00pm in the called party's local time, subject to stricter state limits
  • A2P SMS via 10DLC requires brand and campaign registration through The Campaign Registry before traffic is enabled; opt-in records must be retained for at least four years

The Acceptable Use Policy contains the full set of obligations.

07Customer Proprietary Network Information (CPNI)

Message safeguards Customer Proprietary Network Information as defined under Section 222 of the Communications Act and 47 CFR §64.2001 et seq.

  • CPNI is used only to provide the service the Customer subscribes to, to bill for that service, and for purposes permitted by law
  • CPNI is not shared with marketing affiliates or sold to third parties
  • Customer authentication is required before disclosing CPNI; password reset and security-question flows comply with the FCC's 2007 CPNI Order
  • CPNI breaches are reported to the U.S. Secret Service and the FBI within seven business days, and to affected customers as required
  • We file the annual CPNI compliance certification (FCC Form, EB Docket No. 06-36) by 1 March each year

Our written CPNI compliance policy is available to upstream carriers and regulators on request at [email protected].

08E911 service

Message Phone is an interconnected VoIP service. Emergency calling on VoIP differs from traditional telephone service:

  • Each phone number used for outbound calling must have a Registered Service Address on file. Customers are required to keep this address current.
  • Emergency calls are routed to the Public Safety Answering Point (PSAP) serving the Registered Service Address, not the physical location of the device at the time of the call.
  • If power or internet is lost, emergency calling is unavailable. Customers are notified of this limitation at sign-up and in the product UI.
  • Acknowledgement of the E911 limitation is captured during number provisioning.

09Number porting

We honour the FCC's local-number-portability rules and our upstream carriers' port-in and port-out procedures.

  • Port-in. Free of charge. We submit valid Letters of Authorisation to the losing carrier within one business day of receiving them. Typical port-in completes in 2–4 weeks, controlled by the losing carrier.
  • Port-out. No port-out fees, no withholding. We release the number to the gaining carrier within 24 hours of a validated port request, subject to the FCC's 2009 anti-slamming rules.
  • Anti-port-out fraud. Port-out requests are authenticated; suspicious requests are flagged to the Customer before release.

10Abuse handling

  • Abuse reports acknowledged within 24 hours; investigation within 5 business days
  • Traceback requests from the Industry Traceback Group and law-enforcement authorities responded to within the timeframes required by the TRACED Act
  • Confirmed violations result in number disablement, campaign suspension, account termination, and notification to upstream carriers and the Robocall Mitigation Database where required
  • Severe violations (illegal robocalls, fraud, CSAM, threats to life) are escalated immediately and preserved for lawful disclosure

11Sub-processors

The full sub-processor list is in our Privacy Policy. Customers are notified at least 30 days before a new sub-processor is engaged. Telecom-relevant sub-processors include:

  • Carrier-grade SIP partners, voice trunking, DIDs, SMS
  • DigitalOcean, LLC, compute, managed database, object storage
  • Cloudflare, Inc., edge security and DDoS mitigation
  • Stripe, Inc., subscription billing

12Certifications and registrations

  • SOC 2 Type II, audit in progress; Type I report available on request under NDA
  • GDPR, compliant; DPA available on request
  • HIPAA, aligned; BAA available for Healthcare-plan customers
  • FCC Registration Number, 0038415493. Registered as a non-facilities-based provider of interconnected VoIP and messaging services. Verifiable in the FCC's CORES public lookup.
  • The Campaign Registry (TCR), registered Campaign Service Provider (CSP) for A2P 10DLC messaging
  • Robocall Mitigation Database, entry filed May 13, 2026 under Message.com LLC. Verifiable in the FCC's RMD public lookup.

13Report an issue

Security vulnerabilities, [email protected], acknowledged within 24 hours, every day.
Abuse, spam, fraud, [email protected], acknowledged within 24 hours.
Traceback requests, [email protected], for ITG and law-enforcement authorities.
Privacy and data-subject requests, [email protected]
Legal notices, [email protected]
General, [email protected] · (844) 600-8444

Mailing address for legal process:
Message.com LLC, 363 North Sam Houston Pkwy E, Suite 125, Houston, TX 77060, United States.

For carrier partners and regulators evaluating Message for resale or interconnection, full compliance documentation (CPNI policy, robocall mitigation plan, attestation procedure, BAA, DPA, SOC 2 report) available under NDA at [email protected].
messagemessage.com

One platform for every customer conversation. Built in Texas. SOC 2 Type II, GDPR, and HIPAA-ready.

𝕏in▶{ }

Products

  • Unified Inbox
  • Live Chat
  • Tickets
  • Phone
  • Knowledge Base
  • message.ai

Solutions

  • Ecommerce
  • SaaS
  • Healthcare
  • Financial services
  • Real estate
  • All industries

Company

  • About
  • Customers
  • Careers
  • Affiliate
  • Press
  • Brand
  • Contact

Resources

  • Help center
  • Blog
  • Community
  • Why message
  • Apps
  • Developers
  • Status

Legal

  • All documents
  • Privacy
  • Terms
  • SMS Terms
  • DPA
  • Security
  • Trust
  • Report abuse
message.
© 2026 Message.com LLC All rights reserved.PrivacyTermsAUPTrustReport abuseBuilt in Houston, TX · GDPR