Skip to main content
Compliance

Compliance — you set the posture, the platform enforces it

What is Tenant-Owned Compliance Controls?

A tenant-owned compliance posture is the set of send gates, quiet hours, consent and suppression lists, sender registries, and privacy workflows that decide which of your sends may go out — decided by you, not by the platform. On Orbit you flip the toggles and the platform supplies the whole toggle map: every control ships open by default, every change you make is enforced at send time and written to an auditable record, and read-only 0–100 health scores report the posture you actually have. With one deliberately hard rail — the US federal TCPA 8 AM–9 PM recipient-local dialing window on campaign and dialer voice, which accepts no tenant opt-out — everything else is yours to switch.

What Compliance on Orbit includes

CapabilityWhat you get
Send gates & decision forkEvery send passes a gate stack before dispatch — BAA, quiet hours, DNC and RND scrubs, preference checks, and the voice pre-flight blocks — and the decision-fork page documents exactly which gate held or passed each send. Gates ship opt-in per channel and fail open where your input can't be resolved, except the one federal voice rail.
Quiet hours & previewRecipient-local send windows per channel, enabled per organization, with a preview endpoint that answers "would this send be held right now, and until when?" before you schedule it.
10DLC brand & campaign profilesUS A2P long-code SMS registration as a pair of compliance profiles — the brand entity and the declared campaign use case — with the campaign profile gating send time and structured rejection handling.
Sender-ID registrationRecord alphanumeric sender IDs per country with their supporting documents, track each approval, and let the send-time gate hold traffic to countries that require a registered sender until yours is approved.
Opt-out suppression & consentSTOP keywords, the public preference center, the Consent API, and CSV bulk imports all feed one suppression ledger with a channel scope per entry — a suppressed address is dropped before dispatch on any entry point, and a phone scope of "all" gates voice and dialer traffic too.
DSAR self-service portalData-subject requests (GDPR, CCPA/CPRA, LGPD, PDPA, PIPEDA, DPDP) arrive through an operator queue or a public portal that proves identity with email + SMS one-time codes, with a per-jurisdiction SLA tracker (30 days GDPR, 45 CCPA/CPRA, 15 LGPD). Executed erasures can issue a signed proof-of-deletion certificate.
KYC documents & identity modelUpload documents once into your library, reference them by ID across compliance profiles and sender registrations, and get renewal alerts before an aging document idles a number — the document → profile → destination triangle behind regulated-market sending.
Compliance health scoresA read-only 0–100 score per organization, per sender, and per campaign, blending consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a band with ranked fix recommendations — an early warning before a carrier throttles a sender.
STIR/SHAKEN postureVoice caller-identity controls: ownership resolution toward full (A) attestation, delegate certificates that raise external numbers from C to B (never A, deliberately), a per-DID inbound attestation floor, and a reporting policy that measures the posture you set.
HIPAA mode & BAAHealthcare organizations opt into HIPAA mode workspace-wide — an owner-only toggle — and every PHI send is gated fail-closed until an executed Business Associate Agreement is on file through the e-sign flow, with annual re-execution.
BYOK — customer-managed keysRegister a reference to an encryption key held in your own KMS (AWS KMS, Google Cloud KMS, Azure Key Vault, HashiCorp Vault), activate, rotate, and revoke it — no key material ever leaves your KMS, and every lifecycle write lands in the audit log.
Emergency stopThe org-wide kill switch: one owner/admin call halts all outbound SMS, MMS, voice, and dialer traffic mid-incident, with transactional Verify/OTP sends and email deliberately carved out so login codes still reach recipients.

Common use cases

  • Healthcare — HIPAA & PHI sends

    Execute the BAA through the e-sign flow, flip HIPAA mode on, close the inbox AI privacy gates, set your PHI retention window, and run a vertical bundle that drafts your compliance profile and go-live checklist — the platform refuses PHI sends fail-closed until the BAA is executed.

  • Retail — 10DLC, quiet hours & opt-outs

    Register the brand and campaign pair for US A2P SMS, enable per-channel quiet hours, bulk-import legacy opt-out lists, and let STOP handling plus the preference center keep the suppression ledger clean before the first campaign.

  • Finance — archive, legal hold & audit export

    Apply legal holds, run the archival and audit-export surfaces, and keep the tamper-evident audit ledger behind every consent and suppression decision, with an evidence binder available for review.

Compliance — frequently asked

Who owns compliance on Orbit?
You do. Compliance for your traffic is your responsibility: Orbit supplies the control surface — gates, windows, scrubs, registries, and policy toggles — and enforces what you set, but it does not mandate a posture for you and does not decide that a send is compliant. The one exception is the US federal TCPA dialing window on campaign and dialer voice, which is a hard platform rail with no tenant opt-out.
What is a send gate?
A send gate is a regulatory check that runs at send time — BAA status, quiet hours, Do-Not-Call and Reassigned-Numbers scrubs, preference verification, and the voice pre-flight blocks such as do-not-originate and the per-country rate window. Each gate can hold or drop a message or call before dispatch, most gates ship opt-in and fail open on unresolvable input, and the decision fork documents which gate fired on a given send.
How does DSAR intake work?
Two paths feed one fulfillment pipeline: your team files operator requests through the API or dashboard, or a data subject files through the public self-service portal, which proves identity with an email plus SMS one-time code before anything is queued. The SLA tracker applies per jurisdiction (30 days GDPR, 45 CCPA/CPRA, 15 LGPD), and an executed erasure can issue a signed proof-of-deletion certificate as the receipt for the requester.
What is the 0–100 compliance health score?
A read-only early-warning score per organization, sender, and campaign. It blends consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a healthy/watch/at-risk/critical band with ranked recommendations, and it never blocks a send — it tells you which sender a carrier is about to throttle so you can act first.
Is any control not tenant-toggleable?
A deliberately short list: the US federal TCPA 8 AM–9 PM recipient-local window on campaign and dialer voice (which also fails closed on an unresolvable recipient timezone), state mini-TCPA overlays that stack most-restrictive-wins, the fixed emergency-stop carve-out for Verify/OTP and email, and the STIR/SHAKEN delegate-certificate ceiling of B attestation. Everything else on the toggle map is opt-in and tenant-owned.

Explore more

One platform for every channel

Compliance is one pillar of Orbit by Devotel — voice, messaging, email, video, AI agents, and customer data on one platform and one pay-as-you-go bill. Start free, or talk to our team.

See transparent pay-as-you-go pricing