Security that scales with your business
Single-tenant architecture. CCPA and GDPR compliant. 10DLC registered. HIPAA coming in 2026. Enterprise-grade compliance built into every layer — not bolted on as an afterthought.
Compliance at a glance
10DLC
Business SMS standard
RegisteredTCPA
Consumer consent rules
Fully CompliantPCI DSS
Payment card security
Compliant (via Stripe)GDPR
EU data protection
CompliantCCPA
California privacy rights
CompliantHIPAA
Patient data protection
Coming 2026SOC 2
Security & availability
Planned 2026Your data, your instance, your rules
Unlike multi-tenant platforms where your data shares space with thousands of other businesses, every VirtualText deployment runs on its own isolated infrastructure. Complete data separation isn't optional — it's the architecture.
- Dedicated instance per customer — never co-mingled
- Complete data isolation at the infrastructure level
- Globally deployable to meet data-residency requirements
- Privacy by design, not privacy by policy
- Full database-level separation for audit and compliance
HIPAA coming in 2026
Healthcare providers need messaging that meets strict patient privacy requirements. VirtualText's single-tenant architecture and end-to-end encryption are designed to support HIPAA compliance.
- BAA (Business Associate Agreement) targeted for 2026
- Single-tenant deployment with complete data isolation
- End-to-end encryption across all channels
- Audit trails for every message and action
- PII redaction capabilities built in
SMS compliance, fully automated
10DLC registration, TCPA consent management, opt-in/opt-out handling — VirtualText automates the regulatory complexity so you can focus on conversations, not compliance paperwork.
- 10DLC Registration
Native TCR integration with campaign status tracking and phone number assignment rules
- Opt-In Management
Automatic opt-in footer appending and per-campaign consent tracking
- STOP Handling
Instant STOP keyword recognition blocks all outbound to opted-out contacts
- Opt-Back-In
Customers can re-subscribe with full audit trail
- Campaign Compliance
Per-campaign consent verification before every message
Encrypted at every layer
From the moment a message is sent to the moment it's read, your data is protected. End-to-end encryption across webchat, SMS/MMS, voice transcripts, and shared inboxes.
- End-to-end encryption across all channels
- Encrypted credential storage
- Sentry error tracking and monitoring
- Brakeman security scanning
- Bundler-audit dependency checking
- Comprehensive audit trails for every action
Built-in spam protection
Quarantine suspicious messages, verify contacts automatically, and keep your inbox clean.
Quarantine System
Unverified contacts are quarantined automatically. Review or auto-clean at your pace.
- Automatic quarantine for unknown senders
- One-click approve or dismiss
- Configurable quarantine rules
Contact Verification
Verify contacts via SMS or email verification codes. Only verified contacts reach your team.
- SMS and email verification codes
- Verified badge on contact profiles
- Fraud prevention at the contact level
Auto-Cleanup
Scheduled cleanup of unverified contacts keeps your workspace tidy and your metrics accurate.
- Configurable retention periods
- Background job automation
- Clean metrics without manual effort
Our compliance roadmap
We're building toward the most comprehensive compliance posture in business messaging.
- 10DLC Registered
- TCPA Compliant
- Single-Tenant
- E2E Encryption
- GDPR Compliant
- CCPA Compliant
- PCI DSS (via Stripe)
- HIPAA Ready (BAA)
- SOC 2 Type II
- FedRAMP
- ISO 27001
Compliance FAQ
Is VirtualText HIPAA-ready?
HIPAA readiness, including Business Associate Agreements (BAAs), is targeted for 2026. Our single-tenant architecture and end-to-end encryption are designed to support full HIPAA compliance when available.
What is single-tenant architecture?
Single-tenant means your VirtualText instance runs on its own dedicated infrastructure — your data is never co-mingled with other customers. This provides the strongest possible data isolation, making compliance with HIPAA, GDPR, and other regulations straightforward.
How does VirtualText handle SMS opt-in/opt-out?
VirtualText automates TCPA compliance end-to-end. Opt-in footers are appended automatically, STOP keywords are recognized instantly, and all outbound messaging is blocked to opted-out contacts. Per-campaign consent tracking provides a complete audit trail.
What is 10DLC and why does it matter?
10DLC (10-Digit Long Code) is the industry standard for business SMS messaging. VirtualText includes native TCR registration, campaign status tracking, and phone number assignment rules — ensuring your messages are delivered reliably and in compliance with carrier requirements.
Can VirtualText meet data residency requirements?
Yes. VirtualText's single-tenant architecture allows deployment in specific geographic regions to meet local data-residency and sovereignty requirements. Contact our sales team for region-specific deployment options.
What security certifications are planned?
We comply with CCPA, GDPR, and PCI DSS (via Stripe). We offer 10DLC registration and TCPA compliance. HIPAA readiness (BAA) and SOC 2 Type II are targeted for 2026, with FedRAMP and ISO 27001 on the roadmap after that.
Ready to communicate with confidence?
Start your free trial with SMS and webchat included, then complete porting and 10DLC registration when you are ready to send from your own numbers.