One Thread
See a demonstration

Security & compliance

Independently audited, continuously tested.

SOC 2 Type II and ISO 27001 certified, penetration tested every quarter, and reviewed by CTIA Security, our aggregator, and carrier security teams. Reports and certificates are self-service in the Trust Center.

SOC 2Type IIIndependently certified May 2026. Audited by Armanino LLP across mCommons, Waterfall, Rant & Rave and Hipcricket.
ISO27001Certified, valid through 2029. Full ISMS scope, with surveillance audits every 6 to 12 months.
CTIASecurity reviewedOur controls were reviewed and validated by CTIA Security, our aggregator, and carrier security teams.
PENQuarterly testingIndependent penetration testing every quarter, plus annual third-party assessment and continuous scanning.

Reports, policies and certificates are self-service at trust.mobilecommons.com.

AICPA SOC 2 for Service Organizations
SOC 2AICPA SOC 2 for Service Organizations
ISO/IEC 27001 Information Security Management
ISO 27001ISO/IEC 27001 Information Security Management
Certified Threat Intelligence Analyst
C|TIACertified Threat Intelligence Analyst

How we operate

Security is enforced in the platform, not in a policy.

Every account carries multi-factor authentication. Administrative access runs over VPN with single sign-on and IP allow-listing. Sends require a broadcast PIN and a release approval, so an account alone cannot schedule or alter a message.

100%Multi-factor authentication on employee and platform accountsEnforced, not optional
QuarterlyIndependent penetration testing, plus continuous scanningThird-party
24/7Access-log monitoring with managed security operations coverageAll platforms

Consent, quiet hours, and opt-outs are enforced in the send path itself, so compliance does not depend on a campaign being built correctly.

Where we invested

The controls behind the certifications.

Deployed and verifiable, not a roadmap.

  1. Identity
    Legacy authentication retired

    Every authentication path enforces multi-factor authentication. No exceptions and no legacy bypass.

  2. Identity
    Multi-factor authentication everywhere

    Enforced on every employee account and every platform account.

  3. Access
    VPN-gated administrative access

    Administrative portals are reachable only by authorized employees over encrypted VPN.

  4. Integrity
    Broadcast PIN and release controls

    An unauthorized party cannot alter or schedule a send, even with account access.

  5. Monitoring
    Continuous access-log monitoring

    All platforms, watched continuously for suspicious activity.

  6. People
    Mandatory security awareness training

    100% of employees and contractors, several times a year, via KnowBe4.

  7. Access
    Enterprise single sign-on and IP allow-listing

    Single sign-on through Zitadel integrates with your identity provider. Access can be restricted to your approved IP ranges and locations.

  8. Assurance
    SOC 2 Type II and ISO 27001 certified

    Independently audited by Armanino LLP, covering Security, Availability and Confidentiality.

Controls at a glance

Defense in depth, not a policy document.

Identity & access

SSO, MFA on every account, least-privilege RBAC, VPN-only administrative access, IP allow-listing.

Data protection

Encryption in transit and at rest, with documented retention and handling policies.

Endpoint & MDM

Mobile device management and endpoint detection enforce patching, disk encryption and threat detection across employee devices.

Monitoring & response

Continuous log monitoring with managed SOC coverage and documented incident-response runbooks.

Message integrity

Broadcast PIN and scheduled-send approvals, with AI-assisted message screening in deployment.

Governance & risk

Annual risk assessments, vendor reviews, and an executive-sponsored ISMS program.

Investing ahead

What is next.

  1. AI-assisted message screening. Fraudulent or malicious content detected before it sends.
  2. Signature-based anomaly detection. Machine learning catches account-activity patterns rule-based monitoring would miss.
  3. Continuous controls monitoring and annual SOC 2 recertification.
  4. Quarterly penetration testing, ongoing.

For your procurement team

Documents

  • SOC 2 Type II report
  • ISO 27001 certificate and scope
  • Penetration test summary
  • Current subprocessor list

Agreements

  • Data Processing Agreement
  • Business Associate Agreement
  • Standard contractual clauses
  • TCPA and CTIA compliance terms
Open the Trust Center

See it on your list2 questions, then a calendar