Security & compliance
Independently audited, continuously tested.
SOC 2 Type II and ISO 27001 certified, penetration tested every quarter, and reviewed by CTIA Security, our aggregator, and carrier security teams. Reports and certificates are self-service in the Trust Center.
Reports, policies and certificates are self-service at trust.mobilecommons.com.



How we operate
Security is enforced in the platform, not in a policy.
Every account carries multi-factor authentication. Administrative access runs over VPN with single sign-on and IP allow-listing. Sends require a broadcast PIN and a release approval, so an account alone cannot schedule or alter a message.
Consent, quiet hours, and opt-outs are enforced in the send path itself, so compliance does not depend on a campaign being built correctly.
Where we invested
The controls behind the certifications.
Deployed and verifiable, not a roadmap.
- IdentityLegacy authentication retired
Every authentication path enforces multi-factor authentication. No exceptions and no legacy bypass.
- IdentityMulti-factor authentication everywhere
Enforced on every employee account and every platform account.
- AccessVPN-gated administrative access
Administrative portals are reachable only by authorized employees over encrypted VPN.
- IntegrityBroadcast PIN and release controls
An unauthorized party cannot alter or schedule a send, even with account access.
- MonitoringContinuous access-log monitoring
All platforms, watched continuously for suspicious activity.
- PeopleMandatory security awareness training
100% of employees and contractors, several times a year, via KnowBe4.
- AccessEnterprise single sign-on and IP allow-listing
Single sign-on through Zitadel integrates with your identity provider. Access can be restricted to your approved IP ranges and locations.
- AssuranceSOC 2 Type II and ISO 27001 certified
Independently audited by Armanino LLP, covering Security, Availability and Confidentiality.
Controls at a glance
Defense in depth, not a policy document.
Identity & access
SSO, MFA on every account, least-privilege RBAC, VPN-only administrative access, IP allow-listing.
Data protection
Encryption in transit and at rest, with documented retention and handling policies.
Endpoint & MDM
Mobile device management and endpoint detection enforce patching, disk encryption and threat detection across employee devices.
Monitoring & response
Continuous log monitoring with managed SOC coverage and documented incident-response runbooks.
Message integrity
Broadcast PIN and scheduled-send approvals, with AI-assisted message screening in deployment.
Governance & risk
Annual risk assessments, vendor reviews, and an executive-sponsored ISMS program.
Investing ahead
What is next.
- AI-assisted message screening. Fraudulent or malicious content detected before it sends.
- Signature-based anomaly detection. Machine learning catches account-activity patterns rule-based monitoring would miss.
- Continuous controls monitoring and annual SOC 2 recertification.
- Quarterly penetration testing, ongoing.
For your procurement team
Documents
- SOC 2 Type II report
- ISO 27001 certificate and scope
- Penetration test summary
- Current subprocessor list
Agreements
- Data Processing Agreement
- Business Associate Agreement
- Standard contractual clauses
- TCPA and CTIA compliance terms