Built for the businesses everyone else won't touch.
OtterText is independently audited, carrier-vetted, and purpose-built for regulated industries. Here's an inside look at how we protect your data, your subscribers, and your ability to keep texting.
SOC 2
Type I & Type II
2022
Serving SHAFT clients since
10DLC
Registered with TCR
24/7
Human support & monitoring
Independently audited. Not just self-reported.
Our controls around security, availability, and confidentiality are examined by Thoropass, an independent third-party auditor, against the AICPA’s Trust Services Criteria.
- Completed
SOC 2 Type I
Confirms that OtterText's security controls were suitably designed at a specific point in time. Covers access control, encryption, change management, and monitoring across the OtterText platform.
Auditor: Thoropass
- Completed
SOC 2 Type II
Confirms those same controls operated effectively over an extended observation period, not just on paper. This is the deeper, ongoing-proof standard enterprise buyers and compliance teams ask for.
Auditor: Thoropass
We built for regulated messaging from day one.
OtterText was founded to serve businesses other platforms turn away. That meant getting compliance right before it was optional — across carriers, regulators, and industry-specific rules.
SHAFT Compliance
Purpose-built onboarding, age-gating, and content review for Sex, Hate, Alcohol, Firearms/Explosives, and Tobacco-adjacent businesses — categories most SMS platforms won’t register.
10DLC & The Campaign Registry
Every campaign is registered through TCR with carrier-approved use cases, so messages reach inboxes without being throttled or filtered.
CTIA Messaging Principles
Opt-in, opt-out, and content practices align with CTIA’s Messaging Principles & Best Practices for commercial SMS/MMS.
Carrier Codes of Conduct
Campaigns and copy are reviewed against T-Mobile and AT&T Code of Conduct requirements before they ever reach a subscriber.
TCPA / FCC
Consent capture, STOP/HELP handling, and quiet-hours logic are built to support your compliance with the Telephone Consumer Protection Act.
Age-Gating for SHAFT
Opt-in flows for regulated categories confirm subscriber age before enrollment, in line with carrier and regulatory expectations.
The controls behind the audit.
SOC 2 is the proof; here’s what it’s actually verifying about how we run the platform day to day.
01
Encryption in transit & at rest
Customer and subscriber data is encrypted using TLS in transit and encrypted at rest across our infrastructure.
02
Role-based access control
Internal access to production systems and customer data is scoped by role, logged, and reviewed on a recurring basis.
03
Cloud infrastructure on AWS
Core messaging and email infrastructure, including AWS SES for email delivery, runs on Amazon Web Services with its own independently audited controls.
04
Continuous monitoring
Systems are monitored around the clock, with alerting tied into an internal incident response process.
05
Vendor & subprocessor review
Third-party vendors that touch customer data are reviewed before onboarding and periodically thereafter.
06
Employee security training
Team members complete security and confidentiality training as part of onboarding and on an ongoing basis.
Compliance your subscribers can feel, too.
Trust isn’t just an audit report — it’s what happens every time a subscriber opts in, texts STOP, or asks what happens to their data.
- Opt-in transparency
OtterText uses single opt-in, with clear program terms, sender identification, and consent capture shown at the point of signup.
- STOP / HELP handling
Every subscriber can reply STOP to cancel or HELP for assistance at any time, honored automatically across campaigns.
- Data minimization
We collect what’s needed to deliver the service and support compliance — not more.
- Policies
Full detail lives in our Privacy Policy and Terms & Conditions.
Found something? Need something? Talk to a human.
Report a security issue
If you believe you've found a security vulnerability affecting OtterText, we want to hear from you directly before it goes anywhere else.
Request our security report or DPA
Need our SOC 2 report, a completed security questionnaire, or a signed Data Processing Agreement for procurement? We'll get it to you.