Built to be trusted with your data.
Messaging touches your customers’ phone numbers, conversations, and consent, so security isn’t a feature, it’s the foundation. SimplyRCS is SOC 2 Type II, encrypts your data, runs on US-based infrastructure, and builds compliance in at every layer. Here’s exactly how we protect it.
- SOC 2 Type II
- Encrypted in transit & at rest
- US-based infrastructure
- TCPA & 10DLC compliant
- Direct Tier-1 carriers
HTTPS and TLS everywhere in transit, encrypted at rest, and media served through signed URLs rather than open links.
Roles enforced in the interface and at every API endpoint, keys scoped to read, write or admin, webhooks signed, SSO supported.
STOP and HELP honored above your bots and agents, consent checked before every send, every consent event logged.
US-based data centers, monitored and communicated on, with automatic fallback across RCS, MMS and SMS.
Direct Tier-1 carrier connections, so there are fewer intermediaries between your message and the handset.
Security isn’t bolted on. It’s the architecture.
Some platforms treat security as a checklist they pass once a year. We treat it as how the product is built. Compliance keywords are enforced above the application, not left to a developer to remember. Access is scoped by default. Carrier connections are direct, not resold through layers you can’t audit. The result is a platform you can put in front of regulated customers, and in the critical path of your own product, with confidence.
Security as a checklist
- Audited once a year, then filed away
- Compliance left to application code to remember
- Traffic resold through layers you cannot audit
Security as architecture
- Controls verified as operating effectively over time
- Keywords enforced beneath the application, above your code
- Direct carrier connections, fewer hands on your traffic
Independently verified.
The credentials enterprise and regulated buyers look for, confirmed. Pick one to read what it covers.
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality. Type II means our controls are verified as operating effectively over time, not just at a single point in time. Contact our security team to request the report.
TCPA compliance
The platform enforces TCPA requirements directly: immutable STOP, START, and HELP keyword handling, per-channel consent tracking, and a complete audit trail of every consent event.
10DLC and carrier vetting
Brand and campaign registration through The Campaign Registry, plus carrier vetting for every sender, so your messaging is sanctioned by the carriers, not skirting their rules.
Your data, encrypted and contained.
Customer data, phone numbers, message content, conversations, and consent records, is protected in transit and at rest, and access to it is tightly controlled. We collect what is needed to deliver and measure your messaging, and nothing gratuitous.
Encrypted in transit
All data moving to and from SimplyRCS is encrypted over HTTPS and TLS.
Encrypted at rest
Stored data, including message content and contact records, is encrypted at rest.
Durable, controlled storage
Customer assets and records are stored durably with controlled access; media is served via signed URLs, not open links.
Data minimization
We collect and retain the data needed to run your messaging and reporting. Your customer data is yours, used to deliver your service, not repurposed.
Least privilege, by default.
Access to your account and data is scoped, authenticated, and revocable, for your team and for any system connecting through the API.
Role-based permissions
Team members get roles, Admin, Brand Admin, Agent, Viewer, enforced both in the interface and at every API endpoint, so people only access what their role allows.
Scoped API keys
API keys are scoped to read, write, or admin, can be rotated or revoked at any time, and the plaintext secret is shown only once at creation.
Signed webhooks
Every webhook is cryptographically signed so you can verify it genuinely came from SimplyRCS before acting on it.
SSO support
Single sign-on is supported so you can manage access through your own identity provider.
Rules a bug can’t break.
This is where SimplyRCS goes beyond a checklist. Compliance isn’t left to application code that could have a bug or an oversight, it’s enforced at the platform layer, beneath everything else. STOP, HELP, and opt-out keywords are honored instantly and unconditionally, above both your AI bots and your agents. Per-channel consent is checked before every send. The most restrictive rule wins across platform, organization, and customer content rules. A developer’s mistake, an agent’s slip, or an AI’s misstep can’t override a customer’s opt-out; the platform won’t let it.
- Immutable STOP and HELP: opt-out keywords enforced above AI and agents, always honored
- Consent checked per send: the platform suppresses sends to anyone not opted in on that channel
- Layered content rules: the most restrictive rule always wins, automatically
- Complete audit trail: every consent event and submission logged and reviewable
Carrier-grade, US-based, dependable.
SimplyRCS runs on direct Tier-1 carrier connections and US-based infrastructure, built by a team with deep telecom operating experience. Direct connections mean fewer intermediaries handling your traffic, automatic fallback means messages still deliver when RCS isn’t supported, and the platform is built to sit in critical messaging paths like verification and alerts.
No reseller sits between the platform and the carrier.
Your data and message traffic stay on US infrastructure.
The message lands on whichever the handset supports.
Platform health and incidents are tracked and communicated.
Found something? Tell us.
We welcome reports from security researchers and treat them seriously. If you believe you’ve found a vulnerability, email our security team directly. We respond promptly, follow responsible-disclosure practices, and credit researchers who help us keep the platform safe.
- We respond promptly
- We follow responsible-disclosure practices
- We credit researchers who help keep the platform safe
Security questions.
Is SimplyRCS secure?
Yes. SimplyRCS is SOC 2 Type II, encrypts data in transit and at rest, runs on US-based infrastructure, scopes access by role and API key, and enforces compliance, including opt-outs and consent, at the platform level. Security is built into the architecture, not added as a feature.
Is RCS messaging secure for business?
RCS supports verified senders, which lets customers confirm a message is genuinely from your brand, a meaningful security improvement over plain SMS, where senders can be spoofed. On the platform side, SimplyRCS adds encryption, scoped access, signed webhooks, and audit logging to protect your messaging program end to end.
Is SimplyRCS SOC 2 compliant?
Yes, SimplyRCS is SOC 2 Type II, meaning its security, availability, and confidentiality controls have been independently audited as operating effectively over time. Customers can request the SOC 2 report and security documentation by contacting the security team.
How is my customer data protected?
Customer data, phone numbers, message content, conversations, and consent records, is encrypted in transit and at rest, stored with controlled access, and served via signed URLs. Access is governed by role-based permissions and scoped API keys, and SimplyRCS practices data minimization, using your data to deliver your service rather than repurposing it.
Where is my data stored?
SimplyRCS runs on US-based infrastructure, keeping your data and message traffic in-country.
How does SimplyRCS handle opt-outs and consent?
Opt-out keywords like STOP and HELP are enforced at the platform level, above your AI bots and agents, so they are always honored instantly. Consent is tracked per channel and checked before every send, and every consent event is logged in a complete audit trail, so compliance cannot be bypassed by application code.
How do I report a security vulnerability?
Email [email protected]. We respond promptly, follow responsible-disclosure practices, and credit researchers who help keep the platform secure.
Put it in front of your security team.
Book a demo and bring your security and compliance questions. We’ll walk through our posture, share documentation under NDA, and complete your security questionnaire. No commitment.