Enterprise Compliance & Security

Security that scales with your business

Single-tenant architecture. CCPA and GDPR compliant. 10DLC registered. HIPAA coming in 2026. Enterprise-grade compliance built into every layer — not bolted on as an afterthought.

Compliance at a glance

10DLC

Business SMS standard

Registered

TCPA

Consumer consent rules

Fully Compliant

PCI DSS

Payment card security

Compliant (via Stripe)

GDPR

EU data protection

Compliant

CCPA

California privacy rights

Compliant

HIPAA

Patient data protection

Coming 2026

SOC 2

Security & availability

Planned 2026

Your data, your instance, your rules

Unlike multi-tenant platforms where your data shares space with thousands of other businesses, every VirtualText deployment runs on its own isolated infrastructure. Complete data separation isn't optional — it's the architecture.

  • Dedicated instance per customer — never co-mingled
  • Complete data isolation at the infrastructure level
  • Globally deployable to meet data-residency requirements
  • Privacy by design, not privacy by policy
  • Full database-level separation for audit and compliance
Architecture Overview
Single-Tenant (VirtualText)
Customer A
Own DB
Encrypted
Customer B
Own DB
Encrypted
Customer C
Own DB
Encrypted
Each instance fully isolated with dedicated DB & encryption
Multi-Tenant (Others)
Shared Server
Co. A
Co. B
Co. C
Shared DB — data co-mingled
HIPAA Compliance Dashboard
BAA Status
Active — Signed & executed
Data at Rest
AES-256 Encrypted
Data in Transit
TLS 1.3 Enforced
Recent Audit Log
09:41 AMPHI record accessed by Dr. Smith
09:38 AMEncrypted message sent to patient
09:35 AMPII redaction applied to export
Single-tenant isolation active — no shared infrastructure

HIPAA coming in 2026

Healthcare providers need messaging that meets strict patient privacy requirements. VirtualText's single-tenant architecture and end-to-end encryption are designed to support HIPAA compliance.

  • BAA (Business Associate Agreement) targeted for 2026
  • Single-tenant deployment with complete data isolation
  • End-to-end encryption across all channels
  • Audit trails for every message and action
  • PII redaction capabilities built in

SMS compliance, fully automated

10DLC registration, TCPA consent management, opt-in/opt-out handling — VirtualText automates the regulatory complexity so you can focus on conversations, not compliance paperwork.

  • 10DLC Registration

    Native TCR integration with campaign status tracking and phone number assignment rules

  • Opt-In Management

    Automatic opt-in footer appending and per-campaign consent tracking

  • STOP Handling

    Instant STOP keyword recognition blocks all outbound to opted-out contacts

  • Opt-Back-In

    Customers can re-subscribe with full audit trail

  • Campaign Compliance

    Per-campaign consent verification before every message

10DLC Compliance Panel
Campaign Status Approved
BrandVirtualText Healthcare
Campaign IDTCR-2025-08431
Use CaseCustomer Care
Opt-In Rate 94.2%
1,247 opted-in77 opted-out
STOP Keyword Log
10:02aSTOP+1 (555) 012-3456 — blocked
09:47aSTART+1 (555) 987-6543 — re-subscribed
09:31aSTOP+1 (555) 234-5678 — blocked
Customer Care
Appointment Reminders
Account Alerts
Marketing (Pending)
Security Dashboard
Channel Encryption Status
WebChat
E2E Encrypted
SMS / MMS
E2E Encrypted
Voice Transcripts
E2E Encrypted
Email
E2E Encrypted
Recent Audit Trail
11:22a
User login — sarah@clinic.com — 2FA verified
11:18a
Message sent — conversation #4821 — encrypted
11:15a
Contact export — PII redaction applied
11:10a
Security scan — 0 vulnerabilities found
Brakeman
0 warnings
Bundler Audit
All clear
Sentry
Monitoring

Encrypted at every layer

From the moment a message is sent to the moment it's read, your data is protected. End-to-end encryption across webchat, SMS/MMS, voice transcripts, and shared inboxes.

  • End-to-end encryption across all channels
  • Encrypted credential storage
  • Sentry error tracking and monitoring
  • Brakeman security scanning
  • Bundler-audit dependency checking
  • Comprehensive audit trails for every action

Built-in spam protection

Quarantine suspicious messages, verify contacts automatically, and keep your inbox clean.

Quarantine System

Unverified contacts are quarantined automatically. Review or auto-clean at your pace.

  • Automatic quarantine for unknown senders
  • One-click approve or dismiss
  • Configurable quarantine rules

Contact Verification

Verify contacts via SMS or email verification codes. Only verified contacts reach your team.

  • SMS and email verification codes
  • Verified badge on contact profiles
  • Fraud prevention at the contact level

Auto-Cleanup

Scheduled cleanup of unverified contacts keeps your workspace tidy and your metrics accurate.

  • Configurable retention periods
  • Background job automation
  • Clean metrics without manual effort

Our compliance roadmap

We're building toward the most comprehensive compliance posture in business messaging.

Available Now
  • 10DLC Registered
  • TCPA Compliant
  • Single-Tenant
  • E2E Encryption
  • GDPR Compliant
  • CCPA Compliant
  • PCI DSS (via Stripe)
2026
  • HIPAA Ready (BAA)
  • SOC 2 Type II
Coming Soon
  • FedRAMP
  • ISO 27001

Compliance FAQ

Is VirtualText HIPAA-ready?

HIPAA readiness, including Business Associate Agreements (BAAs), is targeted for 2026. Our single-tenant architecture and end-to-end encryption are designed to support full HIPAA compliance when available.

What is single-tenant architecture?

Single-tenant means your VirtualText instance runs on its own dedicated infrastructure — your data is never co-mingled with other customers. This provides the strongest possible data isolation, making compliance with HIPAA, GDPR, and other regulations straightforward.

How does VirtualText handle SMS opt-in/opt-out?

VirtualText automates TCPA compliance end-to-end. Opt-in footers are appended automatically, STOP keywords are recognized instantly, and all outbound messaging is blocked to opted-out contacts. Per-campaign consent tracking provides a complete audit trail.

What is 10DLC and why does it matter?

10DLC (10-Digit Long Code) is the industry standard for business SMS messaging. VirtualText includes native TCR registration, campaign status tracking, and phone number assignment rules — ensuring your messages are delivered reliably and in compliance with carrier requirements.

Can VirtualText meet data residency requirements?

Yes. VirtualText's single-tenant architecture allows deployment in specific geographic regions to meet local data-residency and sovereignty requirements. Contact our sales team for region-specific deployment options.

What security certifications are planned?

We comply with CCPA, GDPR, and PCI DSS (via Stripe). We offer 10DLC registration and TCPA compliance. HIPAA readiness (BAA) and SOC 2 Type II are targeted for 2026, with FedRAMP and ISO 27001 on the roadmap after that.

Ready to communicate with confidence?

Start with a Connect SMS or webchat trial, then complete porting, 10DLC, and Workspace compliance steps when you are ready to scale.

CCPA & GDPR Compliant Single-tenant isolation 10DLC registered