Skip to content
ColdTexting

SMS Platform Security and Data Protection

ColdTexting protects contact data and conversations with encryption in transit and at rest, role-based access, a full audit log of every send and change, and consent records per contact. Enterprise adds SAML SSO, SCIM provisioning, an IP allowlist, a DPA and a security questionnaire pack.

Controls

Security controls and the plans that include them

Text messages carry phone numbers, names and the words people write back. These are the controls that protect them.

ColdTexting security controls, what each covers and which plans include it
ControlWhat it coversPlans
Encryption in transitEvery connection to the app, the API and webhooks uses TLSAll plans
Encryption at restDatabases and backups holding contacts, messages and consent records are encrypted on diskAll plans
Roles and permissionsOwner, admin, manager and agent roles decide who sends, imports, exports and changes settingsCustom roles on Scale and Enterprise, owner and member on every plan
Audit logSends, imports, consent changes, opt-outs, exports and settings changes with user and timeAll plans, export on Scale and Enterprise
Consent proof exportA PDF per contact with source, timestamp, IP address and the wording they agreed toScale and Enterprise
Data retention and deletionYou decide how long contacts and conversations stay, delete them at any time and request full deletion of the workspaceAll plans
SAML SSO and SCIMSign-in through your identity provider and automatic user provisioning and removalEnterprise
IP allowlistAccess to the workspace only from the office or VPN addresses you listEnterprise
DPA and questionnaire packA data processing agreement and a ready set of answers for vendor security reviewsEnterprise

Plan limits and prices for each tier are on the pricing page. Enterprise is bought in the same self-serve checkout as every other plan.

Access and accountability

Who can do what and a record of everything they did

Role-based access control is a permission model where each user gets a role and the role, not the person, decides which actions are allowed.

The audit log doubles as compliance evidence: the same entries that show who exported a list also show when a contact opted out and that no text followed. How that evidence fits the consent rules is explained on the TCPA compliance page.

Your data

Where data lives and how long it stays

Customer data is hosted in the EU, and the workspace owner controls how long contacts and conversations are kept.

We keep what the product needs to work and to prove compliance: contacts, consent records, messages, opt-outs and the audit log. You can delete single contacts, whole lists or conversations at any time, and an owner can request deletion of the entire workspace. Opt-out entries are the one record we keep as a bare phone number after deletion, because forgetting a STOP would mean texting that person again.

We never sell or share contact lists, and contacts from one workspace are never visible to another. Card payments are handled by our payment operator, so card numbers never touch our servers. The full terms are in the privacy policy.

Sub-processors by category

  • Hosting provider in the EU

    Runs the application, databases and backups

  • Payment operator

    Processes subscription payments and stores card data

  • Email delivery provider

    Sends sign-in codes and account emails

  • Telecom carrier

    Delivers text messages to and from US numbers

Vendor reviews

Answers for your security review

Enterprise includes a data processing agreement and a security questionnaire pack, available in the account right after checkout.

The pack covers access control, encryption, backups, incident handling, retention and the sub-processor categories above, so a procurement review rarely needs a call. SAML SSO and SCIM keep user access in your identity provider, and the IP allowlist limits sign-in to your network. Agencies running many client workspaces get the same controls per client, described on the SMS for agencies page.

Responsible disclosure

Found a vulnerability? Write to [email protected] with the steps to reproduce it. We confirm receipt, keep you updated while we fix it and ask that you do not access other customers' data or disrupt the service while testing.

FAQ

Questions about security and data protection

Yes. Data is encrypted in transit with TLS and at rest on our hosting infrastructure in the EU.

Give your team texting with controls a reviewer can check

Roles, an audit log and consent records come with every plan. Enterprise adds SAML SSO, SCIM, an IP allowlist and a DPA.