Skip to main content
Blog

The Orbit blog

Field notes on AI-era growth, deliverability, voice, and messaging for developers and teams building on Orbit by Devotel.

  • Orbit Editorial Team

    This week in Orbit — October 22, 2026

    This week in Orbit by Devotel: the time-bound announcement series runs again — OpenAI's 2026 deprecation cycle decoded, the VoLTE/VoNR and IMS-retirement wave explained, eIDAS 2.0 mapped to SMS verification, and the AI-voice compliance audit consolidated to one deep link.

    • changelog
    • weekly
    • news
    • voice
    • compliance
    • openai
    • eidas
  • Orbit Editorial Team

    One toggle per regime: AI disclosure for the EU, Korea, California, and Utah

    Four AI-disclosure regimes now share the same "tell the person it's an AI" shape, and Orbit stores them as one settings row with one master switch. The regime-to-toggle map, the workspace-wide scope caveat, the configuration sequence, and the pre-publishing checklist.

    • AI disclosure
    • EU AI Act
    • SB 243
    • Korea AI Basic Act
    • Utah AI Policy Act
    • compliance
    • AI agents
    • 2026
  • Orbit Editorial Team

    Four AI-disclosure regimes, one settings surface: EU AI Act, California SB 243, Utah, and Korea

    The EU AI Act, California SB 243, the Utah AI Policy Act, and Korea's AI Basic Act all demand the same primitive — the person must know they are talking to an AI. How the four regimes differ, and how Devotel Orbit's tenant-owned disclosure toggles cover all four from one surface.

    • AI disclosure
    • EU AI Act
    • SB 243
    • Korea AI Basic Act
    • Utah AI Policy Act
    • compliance
    • 2026
  • Orbit Editorial Team

    BYOK on a CPaaS, Without the Diagram Deck — Register, Activate, Rotate, Revoke

    A buyer-to-procurement walkthrough of Devotel Orbit's customer-managed keys (BYOK) lifecycle — register the ARN from your own KMS, activate with enforce, rotate quarterly, revoke on off-boarding — mapped to the docs page's state machine and the exact four endpoint calls under /api/v1/compliance/byok.

    • BYOK
    • encryption
    • compliance
    • customer-managed keys
    • KMS
    • 2026
  • Orbit Editorial Team

    The Compliance-Bundles Hub — HIPAA, Fintech, E-commerce, and PCI Packs Sequenced in One Place

    A buyer-side sequencing of Devotel Orbit's four vertical compliance bundles — healthcare HIPAA, fintech KYC, e-commerce, and PCI payments — naming what each activation provisions, the walkthrough it deep-links, the tenant-owned controls for that vertical, and the go-live checklist back to the docs pillar pages, so a compliance review runs start to finish from one page.

    • compliance
    • HIPAA
    • KYC
    • PCI
    • e-commerce
    • vertical bundles
    • buyer hub
    • 2026
  • Orbit Editorial Team

    Compliance-health scores: read the 0–100 before carriers throttle

    Your organization, every sending number, and every campaign gets a 0–100 score built from the four signals carriers act on — consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections. The surface is read-only; the score tells you who is about to get throttled, and what to do with it stays your call.

    • compliance
    • deliverability
    • 10dlc
    • runbook
  • Orbit Editorial Team

    A Regulator Fine Lands: The CPaaS Tenant's Four-Step Enforcement Response Playbook

    FCC robocall actions, ICO PECR penalties, and EU regulator complaints all end at the same desk — the tenant's. This playbook walks the four steps a CPaaS tenant runs when a fine lands (complaint intake, evidence preservation, litigation hold, and post-fine posture update) and maps each step to the tenant-owned Devotel Orbit control that makes it survivable.

    • enforcement
    • fines
    • FCC
    • ICO
    • TCPA
    • GDPR
    • evidence
    • compliance
    • litigation hold
    • response playbook
  • Orbit Editorial Team

    Number Recycling and Consent Ownership: Which Scrub Belongs at Which SendGate Stage

    Two registries watch recycled numbers — the FCC's Reassigned Numbers Database and the carrier deactivation feed — and a buyer still has to decide which one answers which question. This post gives the one-paragraph exposure framing, the RND-vs-deactivation-vs-DNC decision table, the SendGate wiring for both checks, and the tenant-owned checklist your counsel signs off on.

    • compliance
    • TCPA
    • RND
    • deactivation scrub
    • list hygiene
    • messaging
    • 2026
  • Orbit Editorial Team

    Turkey Messaging Rules, Decoded: KVKK Scope vs GDPR and BTK Sender IDs

    A deep-dive on launching SMS into Turkey on Devotel Orbit: KVKK and the GDPR-tricking scope question (controller obligations, foreign representative, cross-border transfer), BTK's reserved sender prefixes (GOV, BANK, SGK, MEB), strict sender-ID mode's restricted_prefix code, sender registration with KYC documents, Turkish opt-out vocabulary (DUR, İPTAL, ÇIKIŞ), and the data-residency posture for TR records.

    • Turkey
    • KVKK
    • BTK
    • KVK
    • sender ID
    • restricted prefix
    • compliance
    • opt-out
    • data residency
    • 2026
  • Orbit Editorial Team

    The Compliance-Audit Deep-Link — AI Voice, Attestation, RMD, Call-Recording Consent, and E911 in One Place

    A buyer-side consolidation of the four voice-compliance classes Devotel Orbit ships as tenant-owned controls — EU AI Act Article 50 disclosure, the RMD filing lifecycle, STIR/SHAKEN attestation with call-recording consent, and E911 emergency-address registration — resolved to the shipped endpoints and docs so a legal-team review can run start to finish from one page.

    • compliance
    • voice
    • AI agents
    • STIR/SHAKEN
    • RMD
    • E911
    • EU AI Act
    • call recording
    • buyer guide
    • 2026
  • Orbit Editorial Team

    CPaaS data residency for voice and SMS — the tenant-owned guide

    Devotel Orbit's data-residency posture as a concept, not a claim — which record classes a voice + SMS workload produces, where each one lives, the retention windows you set yourself, and the configurations to run in your own operations workflows. GDPR and HIPAA integration notes for buyers writing residency into their review.

    • data residency
    • GDPR
    • HIPAA
    • voice
    • SMS
    • compliance
    • 2026
  • Orbit Editorial Team

    E911 in practice: registering a dispatchable address and knowing where the obligation splits

    A hands-on walkthrough of E911 address registration on Devotel Orbit — the four-state lifecycle from registered to dispatchable, which duties sit with the carrier and which stay on your side of the ledger, worked API and dashboard examples, and the U.S. boundary of the feature.

    • E911
    • emergency calling
    • dispatchable address
    • RAY BAUM
    • Kari's Law
    • compliance
    • walkthrough
    • USA
  • Orbit Editorial Team

    This week in Orbit — September 24, 2026

    This week in Orbit by Devotel: the blog and changelog now serve coded RSS feeds, Meta's per-user WhatsApp marketing frequency cap decoded, one-click vertical compliance bundles announced, new head-to-head compares against Bird (MessageBird) and Klaviyo, and setup tips in the ToS channel picker.

    • changelog
    • weekly
    • RSS
    • whatsapp
    • compliance
    • integrations
  • Orbit Editorial Team

    The BAA lifecycle on a CPaaS — a healthcare walkthrough from signature to PHI audit row

    A healthcare walkthrough of the Business Associate Agreement lifecycle on Devotel Orbit — what a CPaaS BAA actually covers, the not_required → pending → executed → expired states, who can do what across the PHI surfaces, how the PHI audit row rolls into your DPA processing records, and why the whole posture is tenant-owned.

    • HIPAA
    • BAA
    • healthcare
    • compliance
    • CPaaS
    • walkthrough
  • Orbit Editorial Team

    Do-Not-Originate (DNO) Explained — the Caller-ID Guard Against Spoofing

    A Do-Not-Originate list holds the numbers that must never appear as your outbound caller ID — spoofed government, bank, or IRS lines, inbound-only toll-free, unassigned ranges. Why origination-time screening is the anti-spoofing control carriers ask about first, and how extend / replace / subtract override modes work on Devotel Orbit.

    • voice
    • caller ID
    • spoofing
    • Do-Not-Originate
    • DNO
    • robocall mitigation
    • compliance
  • Orbit Editorial Team

    Emergency Stop: The Org-Wide Kill Switch for Outbound Traffic

    When a scrubbed list or a throttled channel is not enough, one flag halts every outbound dispatch path for your organization before it reaches a provider. Here is when to reach for Devotel Orbit's emergency stop, how it behaves, what it deliberately doesn't freeze, and how to drill it so the first activation isn't during a real incident.

    • compliance
    • incident response
    • send gates
    • emergency stop
    • messaging
    • voice
    • 2026
  • Orbit Editorial Team

    Reassigned Numbers Database (RND): The Safe-Harbor Check That Follows the Subscriber, Not the Number

    A recycled phone number carries its previous owner's opt-outs and known-litigator exposure. The FCC's Reassigned Numbers Database answers one question before every re-contact — was this number permanently disconnected after your consent date? Here is how Devotel Orbit's RND scrub wires that check into the send-gate chain.

    • compliance
    • TCPA
    • RND
    • safe harbor
    • list hygiene
    • messaging
    • 2026
  • Orbit Editorial Team

    Vacated vs Still-Live: How the One-to-One Consent Vacatur Interacts with State Overlays

    The Eleventh Circuit vacated the FCC's one-to-one consent rule in January 2025 — but seven state mini-TCPA overlays and the federal 8-to-9 recipient-local window never depended on it. This explainer bridges the vacatur news to the controls a Devotel Orbit tenant actually configures: state-calling-window intersections, refuse-by-default marketing posture, audit-logged opt-in receipts, and known-litigator scrub.

    • TCPA
    • one-to-one consent
    • state calling windows
    • compliance
    • consent posture
    • quiet hours
  • Orbit Editorial Team

    UK PECR and ePrivacy, Decoded — the Opt-in Layer Beside UK GDPR

    The UK's Privacy and Electronic Communications Regulations sit beside UK GDPR and ask a separate question about marketing SMS, email, calls, and push — was the message itself something you could send before consent. This explainer covers where PECR fits in the omnichannel consent matrix beside TCPA, CAN-SPAM, and CASL, and the tenant-owned consent baseline a UK program configures.

    • UK PECR
    • ePrivacy
    • UK GDPR
    • soft opt-in
    • consent records
    • omnichannel compliance
    • compliance
  • Orbit Editorial Team

    Georgia SMS Sender-ID Whitelisting: Register Your Alphanumeric Sender for Marketing Traffic

    A single-market playbook for Georgia (+995): the country's ComCom regulator sits in the sender-ID whitelisting wave of markets, so unregistered alphanumeric marketing traffic is swapped for a generic numeric ID or filtered outright. How to clear exclusivity, distinctiveness, and the generic-name trap, what documents to file, where the country-rules lookup answers, and how the tenant-owned sender registry tracks approval.

    • sender ID
    • sender registration
    • whitelist
    • Georgia
    • ComCom
    • marketing SMS
    • alphanumeric sender
    • compliance
  • Orbit Editorial Team

    Video session recording and co-browse: the compliance posture support teams actually configure

    Support teams deploying video session recording and co-browse own the consent and retention decision — the platform ships the controls; the tenant answers them. The two controls that matter, which calls record and how participants are told, mapped onto Devotel Orbit's video channel.

    • video buyer guide
    • video API
    • recording
    • co-browse
    • compliance
    • consent
    • retention
    • 2026
  • Orbit Editorial Team

    The Smishing Prevention Playbook: Brand-Impersonation Defense with Tenant-Owned Sender Controls

    Move defense left: register the sender identities you own (10DLC, alphanumeric sender IDs, RCS verified senders), protect your own drafts with a compose-time URL-reputation linter, watch hostile candidates off a tenant-owned watchlist, and file takedowns with a filing-ready evidence pack. The four-layer playbook, mapped to shipped Orbit controls.

    • smishing
    • brand impersonation
    • sender ID registration
    • takedown
    • compliance
    • SMS security
  • Orbit Editorial Team

    Consent-Proof-First Messaging: Tenant-Owned Controls for 2026

    How to run messaging consent so the proof arrives before the campaign — the fields a consent record must carry, where Orbit surfaces them, what to hand counsel, and a quarterly review that keeps the ledger true.

    • consent
    • compliance
    • messaging
    • TCPA
    • GDPR
  • Orbit Editorial Team

    The CPNI Annual Certification, Walked End to End — From March‑1 Deadline to Signed, Filed Attestation

    For carriers and resellers on Devotel Orbit, CPNI's §64.2009(e) annual certification is a tenant lifecycle — open the certification, record consent decisions, certify with an officer signature, file with the FCC, record the reference. This post walks the full day-zero-to-filing arc and maps it to the CPNI runbook.

    • CPNI
    • FCC
    • telecommunications
    • compliance
    • carriers
    • resellers
  • Orbit Editorial Team

    Inside a Vertical-Bundle Activation: The Go-Live Checklist, Step by Step

    What activating a compliance pack in Devotel Orbit hands back — the checklist steps that complete automatically, the ones only you can clear, and the per-pack step each of the four verticals adds. Everything on the list is yours to approve, never the platform's mandate.

    • compliance
    • HIPAA
    • KYC
    • PCI
    • activation checklist
    • product explainer
  • Orbit Editorial Team

    One-Click Vertical Compliance Bundles — HIPAA, Fintech KYC, E-commerce, and PCI Packs, Announced

    The Devotel Orbit settings catalog ships four vertical compliance bundles — healthcare, fintech, e-commerce, and payments. One activation provisions a draft compliance profile, draft campaigns, a vertical-tuned AI agent, and a double-opt-in flow, then hands you the go-live checklist. Nothing sends until you clear it.

    • compliance
    • HIPAA
    • KYC
    • PCI
    • e-commerce
    • product announcement
    • activation bundles
  • Orbit Editorial Team

    The SMS Marketing Playbook 2026: Consent, Quiet Hours, 10DLC Routing, and the CTR Benchmarks That Tell You It Is Working

    SMS marketing runs on a different rulebook than transactional SMS — promotional consent classes, quiet hours, 10DLC campaign registration, opt-out SLA, and a metrics surface that tells delivered from clicked. This playbook defines the marketing-as-program discipline, works through the marketing vs transactional class boundary, and maps every control to the tenant-owned surface in Devotel Orbit that enforces it.

    • SMS marketing
    • TCPA
    • quiet hours
    • 10DLC
    • CTR benchmarks
    • opt-in
    • compliance
    • campaigns
  • Orbit Editorial Team

    SIPREC call recording on a CPaaS: what it is, and why compliance buyers ask about it

    SIPREC is RFC 7866's protocol for recording a SIP session on the network side, with no desk phones and no client software. That makes it the architecture financial-recording and MiFID II buyers ask for. Here is how the recorder-to-api path joins your platform's carrier, and which controls stay tenant-owned on Devotel Orbit.

    • SIPREC
    • call recording
    • compliance
    • MiFID II
    • voice
    • RFC 7866
  • Orbit Editorial Team

    This week in Orbit — September 10, 2026

    This week in Orbit by Devotel: email domains show the provider's live verification status with one-click Cloudflare DNS setup, video room templates spin up consistent rooms, SMPP bind submits stop flooding the Inbox by default, the STT Playground links failures to the credential settings, and a full guide to the Opt-outs console.

    • changelog
    • weekly
    • email
    • video
    • smpp
    • compliance
  • Orbit Editorial Team

    The KYC Loop Checklist: Filing Sender IDs and Compliance Profiles Worldwide

    The full tenant-owned compliance loop on Devotel Orbit: read the per-country rules before you send, upload each KYC document once, bind it to a compliance profile, reference it in the Sender-ID registration, and keep the expiry watch alive in CI — worked for Brazil, the UK, and India.

    • KYC
    • compliance
    • sender ID
    • sender registration
    • DLT
    • numbers
  • Orbit Editorial Team

    SOC 2 vs ISO 27001 — the CPaaS buyer's guide to assurance frameworks

    Which assurance framework a CPaaS RFP is really asking for, what SOC 2 Type II and ISO 27001 certificates each prove, the tenant-owned controls that answer either one, and the checklist of questions to run against every vendor on your short list.

    • SOC 2
    • ISO 27001
    • compliance
    • procurement
    • security
    • checklist
  • Orbit Editorial Team

    The FCC Robocall Mitigation Database, Explained: What a Filing Is and How Orbit Tracks Its Lifecycle

    Every US voice service provider must file in the FCC's Robocall Mitigation Database before it originates calls, and terminating carriers are required to refuse unfiled providers. What 47 CFR § 64.6305 asks for, the filing lifecycle from draft to recertification, and how Devotel Orbit keeps the record, the countdown, and the opt-in origination guard while the filing itself stays with you.

    • voice
    • RMD
    • robocall mitigation
    • STIR/SHAKEN
    • compliance
    • FCC
    • 2026
  • Orbit Editorial Team

    This week in Orbit — September 4, 2026

    This week in Orbit by Devotel: a dashboard console for the contact PII vault, a numbers lookup fraud-score card, the knowledge-gap miner now suggests the fix for each miss, live-call card capture over a masked keypad, and per-message channel fallback on smart-send from the API.

    • changelog
    • weekly
    • dashboard
    • cdp
    • agents
    • compliance
  • Orbit Editorial Team

    How to Run a Compliant Voice Broadcast Campaign with Answer-Rate Optimization

    Voice broadcasting reaches a contact list with pre-recorded audio or text-to-speech — but the campaigns that work optimize on answer rate, not dials. This guide walks through Devotel Orbit's broadcast wizard, the guardrails that keep it compliant, and a worked 50,000-contact example.

    • voice
    • voice broadcasting
    • outbound
    • A/B testing
    • answer rate
    • compliance
    • 2026
  • Orbit Editorial Team

    Emergency calling on a CPaaS — what E911 actually means for buyers in 2026

    An E911 explainer for CPaaS buyers — what carrier-grade emergency calling means, which parts of it are tenant-owned (a dispatchable address per number), how Devotel Orbit handles the surface, and the deployments where you cannot rely on VoIP emergency dialing at all.

    • E911
    • emergency calling
    • RToS
    • VoIP 911
    • voice
    • compliance
    • CPaaS
    • buyer guide
    • 2026
  • Orbit Editorial Team

    Quiet Hours as a Settings API — Recipient-Local Send Windows, Now Scriptable

    The cross-channel quiet-hours policy — recipient-local send windows that gate outbound sends — is now readable and writable through the workspace settings API. Two endpoints expose the policy document and the effective window per channel, so an organization that manages compliance configuration in code no longer clicks through the dashboard to review or change its send windows.

    • quiet hours
    • settings API
    • compliance
    • product announcement
    • 2026
  • Orbit Editorial Team

    Sender-ID Registration by Country: Which Markets Require What (a Playbook for Launch)

    The three registration levels (none, recommended, required), a five-step launch checklist, a country-by-country walk-through of the markets Devotel Orbit customers launch into (France, Germany, Brazil, Singapore, India, UK, US, Canada, APAC), India DLT, US 10DLC, and the documents regulators ask for, with the live per-country rules API behind it.

    • sender ID
    • registration
    • 10DLC
    • DLT
    • TRAI
    • MEF
    • compliance
    • SMS
    • 2026
  • Orbit Editorial Team

    What KYC Documents a CPaaS Customer Should Prepare

    A buyer's guide to the document classes regulators ask for when you activate numbers and sender identities on Devotel Orbit — what to gather before you start, how the compliance-profile lifecycle works, and when to renew before expiry costs you a number.

    • compliance
    • KYC
    • onboarding
    • sender registration
    • numbers
  • Orbit Editorial Team

    Call-Recording Consent Rules in 2026: What CPaaS Tenants Must Configure

    Call-recording consent is not one rule but fifty of them, and the 2026 posture has shifted — carriers and platforms now treat your consent configuration as part of the message-and-call policy you are accountable for. The one-party vs. two-party split, modelled as the two controls every CPaaS tenant owns (which calls record, and how callers are told), and how to set them in Devotel Orbit.

    • call recording
    • consent
    • compliance
    • two-party consent
    • 2026
  • Orbit Editorial Team

    HIPAA-ready CPaaS — the buyer's checklist for messaging, voice, and AI agents

    A runnable checklist for evaluating a CPaaS vendor on HIPAA — where PHI actually lands (SMS callbacks, voice transcripts, agent assist), what a BAA must cover, and the tenant-owned controls to configure on Devotel Orbit once it is signed.

    • HIPAA
    • healthcare
    • compliance
    • CPaaS
    • buyer checklist
    • 2026
  • Orbit Editorial Team

    TCPA Quiet Hours vs State Calling Windows: Recipient-Local Rules, Done Right

    The federal TCPA window (8 AM–9 PM recipient-local) is the floor, seven US states run stricter overlays, and the result depends on how they intersect. This guide walks through the difference, per-state deferral examples, and how to read the state-calling-windows reference page so an Orbit tenant can schedule compliantly without guessing.

    • TCPA
    • quiet hours
    • state calling windows
    • compliance
    • dialing window
    • recipient-local time
  • Orbit Editorial Team

    PCI-DSS on messaging channels — the CPaaS buyer's checklist for scope separation

    A runnable checklist for evaluating a CPaaS vendor on PCI-DSS scope when payment flows touch SMS, email, RCS, or WhatsApp — which channel surfaces carry cardholder data, how Devotel Orbit's Stripe-based SAQ A posture applies per channel, and when to bring in a QSA.

    • PCI DSS
    • messaging
    • compliance
    • security
    • buyer checklist
    • 2026
  • Orbit Editorial Team

    Compliance Posture Is a Quarterly Discipline, Not a Launch Checklist

    Why consent drift, DSAR readiness, and recording announcements decay between audits — and a four-check quarterly review built on Orbit's tenant-owned compliance surfaces, from the health score to the evidence binder.

    • compliance
    • posture
    • GDPR
    • operations
    • 2026
  • Orbit Editorial Team

    EU AI Act 2026 — what it means for communications platforms and AI voice agents

    The EU AI Act's Article 50 transparency obligations have applied to AI voice agents and chatbots since August 2, 2026. What deployers of human-facing AI on communications platforms must do, and how Devotel Orbit's tenant-owned disclosure controls map to it.

    • EU AI Act
    • compliance
    • AI agents
    • voice
    • 2026
  • Orbit Editorial Team

    GDPR and data residency — a buyer's checklist for voice and SMS CPaaS vendors

    A runnable questionnaire for evaluating a voice + SMS platform on GDPR and data residency — the three data classes that matter, where recordings, biometrics, and opt-out records actually live, and the questions to put in your vendor review, each mapped to a Devotel Orbit docs page you can test against.

    • GDPR
    • data residency
    • voice
    • compliance
    • 2026
  • Orbit Editorial Team

    SMS pumping and gray-route fraud: the operator explainer

    The 2026 SMS pumping and gray-route wave in plain terms — how artificial traffic inflation to premium numbers and unregistered-origin routes actually work, why regulators and carriers moved this year, and the tenant-owned controls (pre-send fraud checks, sender registration, frequency caps, suppression, conversion-anomaly reporting) that put the cost back on the attacker.

    • SMS pumping
    • gray routes
    • SIM farming
    • fraud
    • verification API
    • OTP
    • sender registration
    • compliance
    • 2026
  • Orbit Editorial Team

    Voice data residency on Devotel Orbit — the announcement, and how to configure it

    Devotel Orbit now ships per-region voice data residency covering call recordings, voicemail, live media, and transcription — with tenant-owned region pinning and retention. What stays in-region, what you configure, and a worked EU deployment with recording residency.

    • voice
    • data residency
    • GDPR
    • compliance
    • 2026
  • Orbit Editorial Team

    How to Evaluate an SMS API in 2026 — Pricing Model, Network Path & Compliance

    Picking an SMS API comes down to a handful of concrete checks: a published self-serve rate card versus a sales-quoted tier, a direct carrier connection versus a resold aggregator hop, and A2P 10DLC and anti-fraud tooling. This guide runs that checklist across ten providers, alphabetically.

    • SMS API
    • evaluation guide
    • messaging
    • deliverability
    • compliance

Ready to build on Orbit?

Start free and ship your first voice, messaging, or email flow today, or talk to our team about your rollout. No annual contract, one pay-as-you-go bill across every channel.

See transparent pay-as-you-go pricing

Blog — Orbit by Devotel