SMS Platform Security and Data Protection
ColdTexting protects contact data and conversations with encryption in transit and at rest, role-based access, a full audit log of every send and change, and consent records per contact. Enterprise adds SAML SSO, SCIM provisioning, an IP allowlist, a DPA and a security questionnaire pack.
Controls
Security controls and the plans that include them
Text messages carry phone numbers, names and the words people write back. These are the controls that protect them.
| Control | What it covers | Plans |
|---|---|---|
| Encryption in transit | Every connection to the app, the API and webhooks uses TLS | All plans |
| Encryption at rest | Databases and backups holding contacts, messages and consent records are encrypted on disk | All plans |
| Roles and permissions | Owner, admin, manager and agent roles decide who sends, imports, exports and changes settings | Custom roles on Scale and Enterprise, owner and member on every plan |
| Audit log | Sends, imports, consent changes, opt-outs, exports and settings changes with user and time | All plans, export on Scale and Enterprise |
| Consent proof export | A PDF per contact with source, timestamp, IP address and the wording they agreed to | Scale and Enterprise |
| Data retention and deletion | You decide how long contacts and conversations stay, delete them at any time and request full deletion of the workspace | All plans |
| SAML SSO and SCIM | Sign-in through your identity provider and automatic user provisioning and removal | Enterprise |
| IP allowlist | Access to the workspace only from the office or VPN addresses you list | Enterprise |
| DPA and questionnaire pack | A data processing agreement and a ready set of answers for vendor security reviews | Enterprise |
Plan limits and prices for each tier are on the pricing page. Enterprise is bought in the same self-serve checkout as every other plan.
Access and accountability
Who can do what and a record of everything they did
Role-based access control is a permission model where each user gets a role and the role, not the person, decides which actions are allowed.
The audit log doubles as compliance evidence: the same entries that show who exported a list also show when a contact opted out and that no text followed. How that evidence fits the consent rules is explained on the TCPA compliance page.
Your data
Where data lives and how long it stays
Customer data is hosted in the EU, and the workspace owner controls how long contacts and conversations are kept.
We keep what the product needs to work and to prove compliance: contacts, consent records, messages, opt-outs and the audit log. You can delete single contacts, whole lists or conversations at any time, and an owner can request deletion of the entire workspace. Opt-out entries are the one record we keep as a bare phone number after deletion, because forgetting a STOP would mean texting that person again.
We never sell or share contact lists, and contacts from one workspace are never visible to another. Card payments are handled by our payment operator, so card numbers never touch our servers. The full terms are in the privacy policy.
Sub-processors by category
Hosting provider in the EU
Runs the application, databases and backups
Payment operator
Processes subscription payments and stores card data
Email delivery provider
Sends sign-in codes and account emails
Telecom carrier
Delivers text messages to and from US numbers
Vendor reviews
Answers for your security review
Enterprise includes a data processing agreement and a security questionnaire pack, available in the account right after checkout.
The pack covers access control, encryption, backups, incident handling, retention and the sub-processor categories above, so a procurement review rarely needs a call. SAML SSO and SCIM keep user access in your identity provider, and the IP allowlist limits sign-in to your network. Agencies running many client workspaces get the same controls per client, described on the SMS for agencies page.
Responsible disclosure
Found a vulnerability? Write to [email protected] with the steps to reproduce it. We confirm receipt, keep you updated while we fix it and ask that you do not access other customers' data or disrupt the service while testing.
FAQ
Questions about security and data protection
Yes. Data is encrypted in transit with TLS and at rest on our hosting infrastructure in the EU.
Access follows roles and permissions, so reps see their assigned threads and admins control what each role can view or export.
Yes. Sends, imports, consent changes, opt-outs and settings changes are logged, and Scale and Enterprise can export the full log.
Yes. Enterprise includes a DPA and a security questionnaire pack.
No. Your contacts are used only to deliver your messages and are never sold or shared with other customers.
Related pages
Give your team texting with controls a reviewer can check
Roles, an audit log and consent records come with every plan. Enterprise adds SAML SSO, SCIM, an IP allowlist and a DPA.