Skip to main content
Blog

The Orbit blog

Field notes on AI-era growth, deliverability, voice, and messaging for developers and teams building on Orbit by Devotel.

  • Orbit Editorial Team

    One toggle per regime: AI disclosure for the EU, Korea, California, and Utah

    Four AI-disclosure regimes now share the same "tell the person it's an AI" shape, and Orbit stores them as one settings row with one master switch. The regime-to-toggle map, the workspace-wide scope caveat, the configuration sequence, and the pre-publishing checklist.

    • AI disclosure
    • EU AI Act
    • SB 243
    • Korea AI Basic Act
    • Utah AI Policy Act
    • compliance
    • AI agents
    • 2026
  • Orbit Editorial Team

    Four AI-disclosure regimes, one settings surface: EU AI Act, California SB 243, Utah, and Korea

    The EU AI Act, California SB 243, the Utah AI Policy Act, and Korea's AI Basic Act all demand the same primitive — the person must know they are talking to an AI. How the four regimes differ, and how Devotel Orbit's tenant-owned disclosure toggles cover all four from one surface.

    • AI disclosure
    • EU AI Act
    • SB 243
    • Korea AI Basic Act
    • Utah AI Policy Act
    • compliance
    • 2026
  • Orbit Editorial Team

    BYOK on a CPaaS, Without the Diagram Deck — Register, Activate, Rotate, Revoke

    A buyer-to-procurement walkthrough of Devotel Orbit's customer-managed keys (BYOK) lifecycle — register the ARN from your own KMS, activate with enforce, rotate quarterly, revoke on off-boarding — mapped to the docs page's state machine and the exact four endpoint calls under /api/v1/compliance/byok.

    • BYOK
    • encryption
    • compliance
    • customer-managed keys
    • KMS
    • 2026
  • Orbit Editorial Team

    Compliance-health scores: read the 0–100 before carriers throttle

    Your organization, every sending number, and every campaign gets a 0–100 score built from the four signals carriers act on — consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections. The surface is read-only; the score tells you who is about to get throttled, and what to do with it stays your call.

    • compliance
    • deliverability
    • 10dlc
    • runbook
  • Orbit Editorial Team

    A Regulator Fine Lands: The CPaaS Tenant's Four-Step Enforcement Response Playbook

    FCC robocall actions, ICO PECR penalties, and EU regulator complaints all end at the same desk — the tenant's. This playbook walks the four steps a CPaaS tenant runs when a fine lands (complaint intake, evidence preservation, litigation hold, and post-fine posture update) and maps each step to the tenant-owned Devotel Orbit control that makes it survivable.

    • enforcement
    • fines
    • FCC
    • ICO
    • TCPA
    • GDPR
    • evidence
    • compliance
    • litigation hold
    • response playbook
  • Orbit Editorial Team

    Number Recycling and Consent Ownership: Which Scrub Belongs at Which SendGate Stage

    Two registries watch recycled numbers — the FCC's Reassigned Numbers Database and the carrier deactivation feed — and a buyer still has to decide which one answers which question. This post gives the one-paragraph exposure framing, the RND-vs-deactivation-vs-DNC decision table, the SendGate wiring for both checks, and the tenant-owned checklist your counsel signs off on.

    • compliance
    • TCPA
    • RND
    • deactivation scrub
    • list hygiene
    • messaging
    • 2026
  • Orbit Editorial Team

    Turkey Messaging Rules, Decoded: KVKK Scope vs GDPR and BTK Sender IDs

    A deep-dive on launching SMS into Turkey on Devotel Orbit: KVKK and the GDPR-tricking scope question (controller obligations, foreign representative, cross-border transfer), BTK's reserved sender prefixes (GOV, BANK, SGK, MEB), strict sender-ID mode's restricted_prefix code, sender registration with KYC documents, Turkish opt-out vocabulary (DUR, İPTAL, ÇIKIŞ), and the data-residency posture for TR records.

    • Turkey
    • KVKK
    • BTK
    • KVK
    • sender ID
    • restricted prefix
    • compliance
    • opt-out
    • data residency
    • 2026
  • Orbit Editorial Team

    Preparing a CPaaS vendor security review — the walkthrough a buyer should be able to run unassisted

    Vendor security reviews succeed when the vendor publishes its trust surface where procurement can find it without a sales call. How Devotel Orbit's Trust Center, Security page, and subprocessor list answer the common infosec questionnaire, and which tenant-owned controls the reviewer still checks on your side.

    • security review
    • vendor assessment
    • procurement
    • trust center
    • SOC 2
    • GDPR
    • subprocessors
  • Orbit Editorial Team

    GDPR and DSGVO Fines — What European Regulators Actually Publish, and How to Stay Audit-Ready

    Regulators across the EU publish every fine in structured public registers — the GDPR CMS tracker and EDPB decision lists tell you exactly what they cited. This post unpacks what those publications contain and shows the four Devotel Orbit surfaces that keep a CPaaS tenant audit-ready before a fine ever lands.

    • GDPR
    • DSGVO
    • fines
    • enforcement
    • EU compliance
    • supervisory authority
    • EDPB
    • audit-ready
  • Orbit Editorial Team

    CPaaS data residency for voice and SMS — the tenant-owned guide

    Devotel Orbit's data-residency posture as a concept, not a claim — which record classes a voice + SMS workload produces, where each one lives, the retention windows you set yourself, and the configurations to run in your own operations workflows. GDPR and HIPAA integration notes for buyers writing residency into their review.

    • data residency
    • GDPR
    • HIPAA
    • voice
    • SMS
    • compliance
    • 2026
  • Orbit Editorial Team

    E911 in practice: registering a dispatchable address and knowing where the obligation splits

    A hands-on walkthrough of E911 address registration on Devotel Orbit — the four-state lifecycle from registered to dispatchable, which duties sit with the carrier and which stay on your side of the ledger, worked API and dashboard examples, and the U.S. boundary of the feature.

    • E911
    • emergency calling
    • dispatchable address
    • RAY BAUM
    • Kari's Law
    • compliance
    • walkthrough
    • USA
  • Orbit Editorial Team

    eIDAS 2.0 and Messaging Verification — Buyer Guide

    The EU's eIDAS 2.0 regulation expands digital-identity trust services, and CPaaS buyers are asking what it means for their OTP and verification stack. Here is what the regulation says, where identity-proofing meets SMS verification on Devotel Orbit, why it is not the same thing as KYC, and which of the controls are tenant-owned.

    • eIDAS
    • KYC
    • digital identity
    • verification
    • industry news
  • Orbit Editorial Team

    The BAA lifecycle on a CPaaS — a healthcare walkthrough from signature to PHI audit row

    A healthcare walkthrough of the Business Associate Agreement lifecycle on Devotel Orbit — what a CPaaS BAA actually covers, the not_required → pending → executed → expired states, who can do what across the PHI surfaces, how the PHI audit row rolls into your DPA processing records, and why the whole posture is tenant-owned.

    • HIPAA
    • BAA
    • healthcare
    • compliance
    • CPaaS
    • walkthrough
  • Orbit Editorial Team

    Do-Not-Originate (DNO), Explained: The Caller-ID Guard Between Your Numbers and Spoofers

    Do-Not-Originate registries list numbers meant to receive calls, never place them — inbound hotlines, government lines, support queues. This explainer covers what DNO is, where the screening happens in the call path, why an outbound caller ID that sits on a registry gets blocked, and the guard every outbound program should run before launch.

    • Do-Not-Originate
    • DNO
    • caller ID
    • spoofing protection
    • ANI screening
    • voice compliance
  • Orbit Editorial Team

    Do-Not-Originate (DNO) — the caller-ID guard that blocks spoofed originating numbers

    Do-Not-Originate (DNO) is the mirror of Do-Not-Call: instead of protecting recipients from unwanted calls, it protects the network from fabricated caller IDs. This explainer covers what DNO is, why a TRACED-Act-era guard matters, how prefix matching works on the Devotel Orbit dial path, and how to curate your own DNO list.

    • DNO
    • caller ID
    • spoofing
    • voice compliance
    • STIR/SHAKEN
    • outbound voice
  • Orbit Editorial Team

    Do-Not-Originate (DNO) Explained — the Caller-ID Guard Against Spoofing

    A Do-Not-Originate list holds the numbers that must never appear as your outbound caller ID — spoofed government, bank, or IRS lines, inbound-only toll-free, unassigned ranges. Why origination-time screening is the anti-spoofing control carriers ask about first, and how extend / replace / subtract override modes work on Devotel Orbit.

    • voice
    • caller ID
    • spoofing
    • Do-Not-Originate
    • DNO
    • robocall mitigation
    • compliance
  • Orbit Editorial Team

    Emergency Stop: The Org-Wide Kill Switch for Outbound Traffic

    When a scrubbed list or a throttled channel is not enough, one flag halts every outbound dispatch path for your organization before it reaches a provider. Here is when to reach for Devotel Orbit's emergency stop, how it behaves, what it deliberately doesn't freeze, and how to drill it so the first activation isn't during a real incident.

    • compliance
    • incident response
    • send gates
    • emergency stop
    • messaging
    • voice
    • 2026
  • Orbit Editorial Team

    Reassigned Numbers Database (RND): The Safe-Harbor Check That Follows the Subscriber, Not the Number

    A recycled phone number carries its previous owner's opt-outs and known-litigator exposure. The FCC's Reassigned Numbers Database answers one question before every re-contact — was this number permanently disconnected after your consent date? Here is how Devotel Orbit's RND scrub wires that check into the send-gate chain.

    • compliance
    • TCPA
    • RND
    • safe harbor
    • list hygiene
    • messaging
    • 2026
  • Orbit Editorial Team

    Vacated vs Still-Live: How the One-to-One Consent Vacatur Interacts with State Overlays

    The Eleventh Circuit vacated the FCC's one-to-one consent rule in January 2025 — but seven state mini-TCPA overlays and the federal 8-to-9 recipient-local window never depended on it. This explainer bridges the vacatur news to the controls a Devotel Orbit tenant actually configures: state-calling-window intersections, refuse-by-default marketing posture, audit-logged opt-in receipts, and known-litigator scrub.

    • TCPA
    • one-to-one consent
    • state calling windows
    • compliance
    • consent posture
    • quiet hours
  • Orbit Editorial Team

    UK PECR and ePrivacy, Decoded — the Opt-in Layer Beside UK GDPR

    The UK's Privacy and Electronic Communications Regulations sit beside UK GDPR and ask a separate question about marketing SMS, email, calls, and push — was the message itself something you could send before consent. This explainer covers where PECR fits in the omnichannel consent matrix beside TCPA, CAN-SPAM, and CASL, and the tenant-owned consent baseline a UK program configures.

    • UK PECR
    • ePrivacy
    • UK GDPR
    • soft opt-in
    • consent records
    • omnichannel compliance
    • compliance
  • Orbit Editorial Team

    Georgia SMS Sender-ID Whitelisting: Register Your Alphanumeric Sender for Marketing Traffic

    A single-market playbook for Georgia (+995): the country's ComCom regulator sits in the sender-ID whitelisting wave of markets, so unregistered alphanumeric marketing traffic is swapped for a generic numeric ID or filtered outright. How to clear exclusivity, distinctiveness, and the generic-name trap, what documents to file, where the country-rules lookup answers, and how the tenant-owned sender registry tracks approval.

    • sender ID
    • sender registration
    • whitelist
    • Georgia
    • ComCom
    • marketing SMS
    • alphanumeric sender
    • compliance
  • Orbit Editorial Team

    The Smishing Prevention Playbook: Brand-Impersonation Defense with Tenant-Owned Sender Controls

    Move defense left: register the sender identities you own (10DLC, alphanumeric sender IDs, RCS verified senders), protect your own drafts with a compose-time URL-reputation linter, watch hostile candidates off a tenant-owned watchlist, and file takedowns with a filing-ready evidence pack. The four-layer playbook, mapped to shipped Orbit controls.

    • smishing
    • brand impersonation
    • sender ID registration
    • takedown
    • compliance
    • SMS security
  • Orbit Editorial Team

    How to Register for 10DLC: The Step-by-Step TCR Walkthrough (Brand + Campaign)

    The affirmative 10DLC registration walkthrough — Brand registration fields TCR vets (legal entity, EIN, address, vertical), campaign use-case selection with approved sample messages, vetting score and throughput tiers, the console runbook on Devotel Orbit, and the rejection patterns that trip first submissions.

    • 10DLC
    • TCR
    • brand registration
    • campaign registration
    • A2P messaging
    • SMS compliance
  • Orbit Editorial Team

    CPaaS API Security in 2026: Key Scoping, Webhook Forgery, and Account Takeover at the Provider Layer

    SMS pumping made CPaaS fraud visible, but the quieter 2026 discussion is about the API surface itself — leaked keys bought by CAPTCHA farms, forged webhook payloads injecting fraud events, and dashboard takeovers that mint attacker-owned credentials. This explainer walks the three shapes, the shipped tenant-owned controls that answer them, and the checklist to run in a CPaaS deal.

    • API security
    • API keys
    • webhook security
    • SAML
    • account takeover
    • buyer checklist
    • 2026
  • Orbit Editorial Team

    Encryption at rest, webhook signatures, and API-key scoping: the data-protection posture in one map

    The API-abuse explainer covers what attacks do; the SCIM checklist covers identity plumbing. This map covers how stored data is protected — the always-on envelope encryption layer, the BYOK control plane on top of it, the exact webhook signature contract, and what API-key scope has to do with any of it — with a buyer's checklist keyed to the shipped surfaces.

    • encryption
    • webhook security
    • API keys
    • BYOK
    • buyer checklist
    • 2026
  • Orbit Editorial Team

    How SAML SSO Secures Tenant-Isolated Dashboard Access at Orbit

    A deep dive into the SAML 2.0 flow Devotel Orbit runs per organization — signed assertions, audience and replay checks, IdP-group role mapping, and the org-binding gate that keeps one tenant's sign-in from touching another.

    • SSO
    • SAML
    • tenant isolation
    • role mapping
    • SCIM
  • Orbit Editorial Team

    Consent-Proof-First Messaging: Tenant-Owned Controls for 2026

    How to run messaging consent so the proof arrives before the campaign — the fields a consent record must carry, where Orbit surfaces them, what to hand counsel, and a quarterly review that keeps the ledger true.

    • consent
    • compliance
    • messaging
    • TCPA
    • GDPR
  • Orbit Editorial Team

    The CPNI Annual Certification, Walked End to End — From March‑1 Deadline to Signed, Filed Attestation

    For carriers and resellers on Devotel Orbit, CPNI's §64.2009(e) annual certification is a tenant lifecycle — open the certification, record consent decisions, certify with an officer signature, file with the FCC, record the reference. This post walks the full day-zero-to-filing arc and maps it to the CPNI runbook.

    • CPNI
    • FCC
    • telecommunications
    • compliance
    • carriers
    • resellers
  • Orbit Editorial Team

    The FCC One-to-One Consent Rule, Vacated — What Outbound Teams Must Still Capture

    The FCC adopted a one-to-one consent rule for comparison-shopping lead generators in December 2023; the Eleventh Circuit vacated it in IMC v. FCC in January 2025, before it took effect. The base TCPA prior-express-written-consent requirement plus state mini-TCPAs still apply. This explainer covers the rule, the vacating, and the tenant-owned consent-record design that keeps lead source, timestamp, scope, and seller identity bound to every contact.

    • TCPA
    • one-to-one consent
    • lead generation
    • consent records
    • outbound calling
    • industry news
  • Orbit Editorial Team

    The KYC Loop Checklist: Filing Sender IDs and Compliance Profiles Worldwide

    The full tenant-owned compliance loop on Devotel Orbit: read the per-country rules before you send, upload each KYC document once, bind it to a compliance profile, reference it in the Sender-ID registration, and keep the expiry watch alive in CI — worked for Brazil, the UK, and India.

    • KYC
    • compliance
    • sender ID
    • sender registration
    • DLT
    • numbers
  • Orbit Editorial Team

    SOC 2 vs ISO 27001 — the CPaaS buyer's guide to assurance frameworks

    Which assurance framework a CPaaS RFP is really asking for, what SOC 2 Type II and ISO 27001 certificates each prove, the tenant-owned controls that answer either one, and the checklist of questions to run against every vendor on your short list.

    • SOC 2
    • ISO 27001
    • compliance
    • procurement
    • security
    • checklist
  • Orbit Editorial Team

    The 10DLC Sanction Sweep, Explained: Why US Campaigns Are Being Deactivated — and How to Stay Registered

    US carriers have moved to enforcing 10DLC registration instead of tolerating drift — unregistered traffic suspended, dormant brands re-vetted, secondary vetting on the campaigns that drifted. This explainer covers what is being swept, why the enforcement window opened now, and the tenant-owned audit that keeps a campaign on the wire.

    • 10DLC
    • TCR
    • sanction sweep
    • A2P messaging
    • campaign deactivation
    • industry news
  • Orbit Editorial Team

    Emergency calling on a CPaaS — what E911 actually means for buyers in 2026

    An E911 explainer for CPaaS buyers — what carrier-grade emergency calling means, which parts of it are tenant-owned (a dispatchable address per number), how Devotel Orbit handles the surface, and the deployments where you cannot rely on VoIP emergency dialing at all.

    • E911
    • emergency calling
    • RToS
    • VoIP 911
    • voice
    • compliance
    • CPaaS
    • buyer guide
    • 2026
  • Orbit Editorial Team

    SMS short codes vs 10DLC vs toll-free — a buyer comparison

    A short code is a dedicated 5- or 6-digit number for very high-volume two-way SMS in the US and Canada, 10DLC is a standard 10-digit number whose throughput depends on registered brand and campaign vetting, and a toll-free number sends and receives texting-enabled toll-free traffic. This comparison covers how they differ on throughput, trust, cost, and time to provision — and how to pick.

    • SMS
    • short codes
    • 10DLC
    • toll-free SMS
    • messaging infrastructure
  • Orbit Editorial Team

    What KYC Documents a CPaaS Customer Should Prepare

    A buyer's guide to the document classes regulators ask for when you activate numbers and sender identities on Devotel Orbit — what to gather before you start, how the compliance-profile lifecycle works, and when to renew before expiry costs you a number.

    • compliance
    • KYC
    • onboarding
    • sender registration
    • numbers
  • Orbit Editorial Team

    Call-Recording Consent Rules in 2026: What CPaaS Tenants Must Configure

    Call-recording consent is not one rule but fifty of them, and the 2026 posture has shifted — carriers and platforms now treat your consent configuration as part of the message-and-call policy you are accountable for. The one-party vs. two-party split, modelled as the two controls every CPaaS tenant owns (which calls record, and how callers are told), and how to set them in Devotel Orbit.

    • call recording
    • consent
    • compliance
    • two-party consent
    • 2026
  • Orbit Editorial Team

    HIPAA-ready CPaaS — the buyer's checklist for messaging, voice, and AI agents

    A runnable checklist for evaluating a CPaaS vendor on HIPAA — where PHI actually lands (SMS callbacks, voice transcripts, agent assist), what a BAA must cover, and the tenant-owned controls to configure on Devotel Orbit once it is signed.

    • HIPAA
    • healthcare
    • compliance
    • CPaaS
    • buyer checklist
    • 2026
  • Orbit Editorial Team

    TCPA Litigator Scrubs: How to Keep Professional Plaintiffs Out of Your Outbound

    Known TCPA litigators treat your dialer as a revenue source. How the Devotel Orbit Litigator-Known scrub gates SMS/MMS at send time, why a 36-month lawsuit-history feed with a daily re-scrub cadence is what makes it honest, why send gates share one consent and suppression ledger, and the two exports that answer a discovery request.

    • TCPA
    • litigator scrub
    • known litigators
    • SMS compliance
    • outbound dialing
  • Orbit Editorial Team

    TCPA Quiet Hours vs State Calling Windows: Recipient-Local Rules, Done Right

    The federal TCPA window (8 AM–9 PM recipient-local) is the floor, seven US states run stricter overlays, and the result depends on how they intersect. This guide walks through the difference, per-state deferral examples, and how to read the state-calling-windows reference page so an Orbit tenant can schedule compliantly without guessing.

    • TCPA
    • quiet hours
    • state calling windows
    • compliance
    • dialing window
    • recipient-local time
  • Orbit Editorial Team

    EU AI Act 2026 — what it means for communications platforms and AI voice agents

    The EU AI Act's Article 50 transparency obligations have applied to AI voice agents and chatbots since August 2, 2026. What deployers of human-facing AI on communications platforms must do, and how Devotel Orbit's tenant-owned disclosure controls map to it.

    • EU AI Act
    • compliance
    • AI agents
    • voice
    • 2026
  • Orbit Editorial Team

    GDPR and data residency — a buyer's checklist for voice and SMS CPaaS vendors

    A runnable questionnaire for evaluating a voice + SMS platform on GDPR and data residency — the three data classes that matter, where recordings, biometrics, and opt-out records actually live, and the questions to put in your vendor review, each mapped to a Devotel Orbit docs page you can test against.

    • GDPR
    • data residency
    • voice
    • compliance
    • 2026
  • Orbit Editorial Team

    Programmable fax in 2026 — the channel healthcare and legal still can't drop

    Fax refuses to die in healthcare, legal, and government — so it has to be an API, not a machine. Covers T.38/G.711 outbound, per-DID inbound routing, delivery receipts, success-only billing, and when Devotel Orbit's Fax channel replaces a dedicated fax service.

    • fax API
    • healthcare
    • compliance messaging
    • channels
    • 2026
  • Orbit Editorial Team

    Voice data residency on Devotel Orbit — the announcement, and how to configure it

    Devotel Orbit now ships per-region voice data residency covering call recordings, voicemail, live media, and transcription — with tenant-owned region pinning and retention. What stays in-region, what you configure, and a worked EU deployment with recording residency.

    • voice
    • data residency
    • GDPR
    • compliance
    • 2026
  • Orbit Editorial Team

    Why 10DLC Campaigns Get Rejected — and How to Pass TCR Vetting First Try

    The four rejection reasons that actually kill 10DLC campaigns (EIN mismatch, sample messages that don't match the use case, missing opt-out language, political verticals without a Campaign Verify token), how CSP-level approval differs from per-carrier review, what the throughput tiers buy you per number, and the pre-submission checklist.

    • 10DLC
    • TCR
    • campaign vetting
    • A2P messaging
    • SMS compliance

Ready to build on Orbit?

Start free and ship your first voice, messaging, or email flow today, or talk to our team about your rollout. No annual contract, one pay-as-you-go bill across every channel.

See transparent pay-as-you-go pricing

Blog — Orbit by Devotel