Built like your customer list depends on it.
Because it does. In SMS, a consent failure isn't a bug — carriers filter, providers suspend, and trust doesn't come back. So consent, opt-outs, and access control are properties of the system, not tasks on your staff's checklist. This page describes what the product actually does, in operational terms. If a question isn't answered here, ask us directly: security@autocampaign.ai.
Messaging compliance
SMS compliance is what carriers, providers, and your customers all expect of a business sender: provable consent, an opt-out that always works, and a registered sending identity. Here, each of those is system behavior — visible in the product, not promised in a policy PDF.
Consent is recorded — and never deleted
Every contact carries a consent source from the moment it's created: the keyword they texted, the form they submitted, the import that brought them in. Consent records are kept permanently, so "where did this number come from?" always has a per-contact answer — which turns a carrier or client audit into an afternoon, not a crisis.
STOP is honored automatically, before anything else
An opt-out request is processed first — before any other feature, and before any human could see it, misread it, or miss it in a busy inbox. The contact is marked opted out with a timestamp, and the opt-out is mirrored to the messaging provider so platform and carrier level agree.
One enforcement point sits in front of every send: campaigns, sequences, automations, keyword replies, and inbox messages all pass through the same check, so there aren't six places to get it wrong. And START is the only path back in — a form, an import, or a keyword can never quietly re-subscribe someone who opted out.
An email unsubscribe and an SMS opt-out are tracked separately, so respecting one channel's request never wrongly blocks — or wrongly unblocks — the other.
A2P 10DLC registration is guided, not outsourced to you
Brand and campaign registration workflows walk through the business details and consent description carriers expect, with registration status visible in-product. Registration is what carriers require of business senders; we make it work you can see and finish rather than a multi-day back-and-forth in a provider console.
Sending is limited and distributed by design
Set sending limits per number, so no single number carries more volume than you want it to. Sender Pools spread sending across numbers you control instead of concentrating everything on one identity. Automated sequences honor quiet hours.
Data protection
- Org-isolated data. Every request resolves to one organization, and every query is scoped to it. An agency's clients each live in their own workspace with their own numbers and wallet.
- Roles and permissions. Control who can do what with granular, per-action permissions and custom roles — front-desk staff can answer texts without being able to export the contact database or touch billing.
- Credentials encrypted at rest. Messaging-provider credentials and API keys are stored encrypted or hashed — keys are shown once, then rotatable and revocable, with key operations audited.
- Spend control. Prepaid credits, spend caps, and cost estimates before sending mean a compromised or careless account has a financial ceiling you set.
Product preview: a roles and permissions matrix with fictional roles — Owner, Manager, and Front Desk — against generic permission names for sending campaigns, exporting contacts, managing billing, and API keys. Owner holds every permission; Front Desk holds none of these.
AI, under your control
AI Employees draft customer replies from your business information — the content you give them, not the open internet. Drafts by default: nothing sends without your approval until you switch on Autopilot, and that's a per-conversation choice, not a global switch. Hand-off rules bring a person into the conversation with a summary, and your team can take over at any time. You can test-chat with an AI Employee before it ever talks to a real customer.
Product preview: an AI Employee draft reply waiting for approval, with Autopilot switched off and Approve and Edit controls. Nothing sends without approval. All sample data fictional.
Your data is yours
Export your contacts anytime — your list leaves with you, complete. A REST API and signed outbound notifications let you keep your own systems in sync, on credentials you can rotate and revoke. Deletion requests are honored: ask, and your data is removed.
Product preview: opt-out settings and a contact timeline side by side — the organization's stop keywords and auto-reply message on the left, and a contact record for fictional business "Harborlight Dental" at "(555) 014-2276" showing consent source, opt-in date, and an "Opted out — honored automatically" event on the right. All sample data fictional.
Consent and opt-out, recorded where you can point at them.
For your questionnaire, in one table
| The question you're asked | What the product does |
|---|---|
| Can you prove consent per contact? | Consent source mandatory at creation; consent records never deleted |
| What happens when someone texts STOP? | Honored automatically, first in line, mirrored to the provider; one check in front of every send |
| Are you registered senders? | Guided A2P 10DLC brand and campaign registration with in-product status |
| Who can access what? | Granular roles and permissions; org-scoped data on every query |
| How do integrations authenticate? | Org-scoped API keys — shown once, rotatable, revocable, audited; signed outbound notifications |
| What limits the damage from a mistake? | Per-number sending limits, spend caps, cost estimates before send |
| Are you SOC 2 / HIPAA / ISO certified? | Not today — see the section above. Roadmap, stated plainly. |
Where we are on certifications
Plainly: AutoCampaign.ai does not currently hold SOC 2, HIPAA, or ISO certification. We'd rather tell you that here than have you find it in a questionnaire.
What we practice today is described on this page in operational terms: org-scoped data isolation on every query, encrypted credentials, granular permissions, audited API-key operations, and consent handling enforced by the system rather than by policy documents. SOC 2 Type II is on our security roadmap. When a certification is achieved, it will be stated here — not before.
FAQ
Does using AutoCampaign.ai make my business TCPA-compliant?
No tool can promise that, and you should be wary of one that does. What the product does: records consent with its source, honors STOP automatically at platform and provider level, and guides A2P 10DLC registration. That's product behavior you can verify — not legal advice. For regulatory questions, talk to your counsel.
Are you SOC 2 certified?
Not yet, and we won't imply otherwise. SOC 2 Type II is on our security roadmap. Meanwhile, this page describes the specific controls in place today, and we'll answer your security questionnaire directly at security@autocampaign.ai.
Have a security question we didn't answer?
Write to security@autocampaign.ai — a person reads it. Or see the product's controls in context.
Consent recorded, opt-outs honored automatically.