TRUST CENTER

Built for the businesses everyone else won't touch.

OtterText is independently audited, carrier-vetted, and purpose-built for regulated industries. Here's an inside look at how we protect your data, your subscribers, and your ability to keep texting.

SOC 2

Type I & Type II

2022

Serving SHAFT clients since

10DLC

Registered with TCR

24/7

Human support & monitoring

SOC 2 Type I Audited by Thoropass
SOC 2 Type II Audited by Thoropass
CERTIFICATIONS

Independently audited. Not just self-reported.

Our controls around security, availability, and confidentiality are examined by Thoropass, an independent third-party auditor, against the AICPA’s Trust Services Criteria.

SOC 2 Type I

Confirms that OtterText's security controls were suitably designed at a specific point in time. Covers access control, encryption, change management, and monitoring across the OtterText platform.

Auditor: Thoropass

SOC 2 Type II

Confirms those same controls operated effectively over an extended observation period, not just on paper. This is the deeper, ongoing-proof standard enterprise buyers and compliance teams ask for.

Auditor: Thoropass

COMPLIANCE FRAMEWORKS

We built for regulated messaging from day one.

OtterText was founded to serve businesses other platforms turn away. That meant getting compliance right before it was optional — across carriers, regulators, and industry-specific rules.

SHAFT Compliance

Purpose-built onboarding, age-gating, and content review for Sex, Hate, Alcohol, Firearms/Explosives, and Tobacco-adjacent businesses — categories most SMS platforms won’t register.

10DLC & The Campaign Registry

Every campaign is registered through TCR with carrier-approved use cases, so messages reach inboxes without being throttled or filtered.

CTIA Messaging Principles

Opt-in, opt-out, and content practices align with CTIA’s Messaging Principles & Best Practices for commercial SMS/MMS.

Carrier Codes of Conduct

Campaigns and copy are reviewed against T-Mobile and AT&T Code of Conduct requirements before they ever reach a subscriber.

TCPA / FCC

Consent capture, STOP/HELP handling, and quiet-hours logic are built to support your compliance with the Telephone Consumer Protection Act.

Age-Gating for SHAFT

Opt-in flows for regulated categories confirm subscriber age before enrollment, in line with carrier and regulatory expectations.

SECURITY PRACTICES

The controls behind the audit.

SOC 2 is the proof; here’s what it’s actually verifying about how we run the platform day to day.

01

Encryption in transit & at rest

Customer and subscriber data is encrypted using TLS in transit and encrypted at rest across our infrastructure.

02

Role-based access control

Internal access to production systems and customer data is scoped by role, logged, and reviewed on a recurring basis.

03

Cloud infrastructure on AWS

Core messaging and email infrastructure, including AWS SES for email delivery, runs on Amazon Web Services with its own independently audited controls.

04

Continuous monitoring

Systems are monitored around the clock, with alerting tied into an internal incident response process.

05

Vendor & subprocessor review

Third-party vendors that touch customer data are reviewed before onboarding and periodically thereafter.

06

Employee security training

Team members complete security and confidentiality training as part of onboarding and on an ongoing basis.

SUBSCRIBER & DATA PROTECTIONS

Compliance your subscribers can feel, too.

Trust isn’t just an audit report — it’s what happens every time a subscriber opts in, texts STOP, or asks what happens to their data.

OtterText uses single opt-in, with clear program terms, sender identification, and consent capture shown at the point of signup.

Every subscriber can reply STOP to cancel or HELP for assistance at any time, honored automatically across campaigns.

We collect what’s needed to deliver the service and support compliance — not more.

Full detail lives in our Privacy Policy and Terms & Conditions.

RESPONSIBLE DISCLOSURE

Found something? Need something? Talk to a human.

Report a security issue

If you believe you've found a security vulnerability affecting OtterText, we want to hear from you directly before it goes anywhere else.

Request our security report or DPA

Need our SOC 2 report, a completed security questionnaire, or a signed Data Processing Agreement for procurement? We'll get it to you.