Compliance Toolkit for Programmable Messaging
Limited to US-terminating SMS messages in English
This feature supports SMS messages terminating in the United States written in English language only.
To help with regulatory compliance, Compliance Toolkit embeds AI-powered safeguards into your messaging workflows. To prevent issues before sending messages, it detects possible violations, identifies high-risk recipients, and applies intelligent transmission controls.
To learn about Compliance Toolkit pricing, see SMS Pricing or contact Sales.
In compliance with regional and national laws, Twilio allows recipients the choice to receive or not receive non-essential messages.
To opt-out, a recipient had replied to a prior message with one of the following keywords:
STOPUNSUBSCRIBEENDQUITSTOPALLREVOKEOPTOUTCANCEL
To block or allow messages, Twilio checks a consent status in the Consent Management API records and keyword-based signals.
With this API, you can manage the following user consent statuses:
| Status | User action |
|---|---|
opt in | Provided valid consent to receive SMS messages. |
opt out | Revoked consent or replied with STOP-like keywords. |
opt in | Opted in again after a prior opt-out. Overrides STOP keyword. |
Quiet Hours are defined as the time in which an organization can't deliver non-essential messages to recipients. Compliance Toolkit enforces federal and state Quiet Hours rules based on the recipient's location. Twilio determines location from recipient data: either the area code of the phone number (default) or the ZIP Code (recommended). To provide the ZIP codes of the your recipients, set them with the Contact API.
The US Federal Communications Commission (FCC) defines these hours under the Telephone Consumer Protection Act (TCPA) as 9:00 PM to 8:00 AM in the recipient's local time zone.
Compliance Toolkit also enforces state-specific quiet hours mandates.
| State | US Time Zone | Quiet hours |
|---|---|---|
Alabama | Central | 8:00 PM – 8:00 AM |
Connecticut | Eastern | 8:00 PM – 9:00 AM |
Florida | Eastern | 8:00 PM – 8:00 AM |
Louisiana | Central | 8:00 PM – 8:00 AM |
Maryland | Eastern | 8:00 PM – 8:00 AM |
Mississippi | Central | 8:00 PM – 8:00 AM |
Nevada | Mountain | 8:00 PM – 9:00 AM |
Oklahoma | Central | 8:00 PM – 8:00 AM |
Tennessee | Eastern | 8:00 PM – 8:00 AM |
Texas | Central | 9:00 PM – 9:00 AM (Mon.-Sat.) |
Texas | Central | 9:00 PM – 12:00 PM (Sun.) |
Washington | Pacific | 8:00 PM – 8:00 AM |
Non-essential messages that fall into these restricted windows get re-scheduled and delivered once Quiet Hours end.
Consult legal advice on additional restrictions
Compliance Toolkit doesn't enforce any restrictions or requirements outside of federal and state quiet hours. To ensure your compliance when using any Twilio Service, check with your legal counsel for any additional requirements.
If the message falls within Quiet Hours, the Compliance Toolkit classifies the message using an AI model as essential or non-essential. This classification is based on the message content and context.
Recommended
To define the use case for each message, add the messageIntent parameter. Its value always overrides the Compliance Toolkit AI/ML message classification model. If you specify the messageIntent, Compliance Toolkit honors your classification as the source of truth, overriding the prediction from its models.
The following table lists which use cases you can configure for the messageIntent parameter and the Quiet Hours mapping assigned for that use case.
| Use case | messageIntent value |
|---|---|
| Two-factor auth (2FA) and one-time passcodes (OTP) | otp |
| Account notifications, two-way conversational messaging | notifications |
| Fraud alerts | fraud |
| Security alerts, emergency announcements | security |
| Customer care | customercare |
| Delivery notifications | delivery |
To activate Compliance Toolkit, go to your account settings in the Twilio Console.
- Log in to the Twilio Console
- Go to Communications > Messaging > Settings > General. The General Messaging Settings page appears.
- Scroll to Compliance Toolkit Settings.
- Click Enabled. The Compliance Toolkit modal displays.
- Review the text of this modal, then click Twilio Compliance Toolkit: AI/ML and Product Terms Addendum.
- Click Done. The Compliance Toolkit modal closes.
- Click Save.
Once activated, the toolkit runs on your existing messaging flows. You don't need to take further action.
Once you enable Compliance Toolkit, all US outbound SMS traffic in the enabled account passes through Compliance Toolkit. In asking the following questions, the toolkit helps identify and resolve possible compliance violations:
- Is the message essential or non-essential?
- Has the recipient given consent to receive messages?
- Does the individual who gave consent remain associated with the phone number?
- Is a non-essential message being sent during federal or state quiet hours?
- Is the phone number of the recipient associated with a TCPA known litigator?
To avoid interruptions to your critical communications, Compliance Toolkit distinguishes between different types of messages using its AI/ML message classification model.
- Essential: Delivers non-promotional messages to the recipient.
- Non-Essential: Processes marketing or promotional messages as given in the following table:
| Check | Message | Returns error |
|---|---|---|
| Recipient has opted out | Blocked | 21610 |
| Recipient has Reassigned Phone Number | Blocked | 21610 |
| Recipient is TCPA Known Litigator | Blocked | 30640 |
| Non-essential message sent during Quiet Hours with default settings1 | Rescheduled | 30640 |
Non-essential message sent during Quiet Hours with block setting2 | Blocked | 30640 |
You can override the message type that the Compliance Toolkit AI/ML message classification model set. To change the message type, add the messageIntent parameter. If you specify the messageIntent, Compliance Toolkit honors your classification as the source of truth and overrides its model predictions.
To identify users who have opted out of receiving your messages, Twilio checks against its opt-out database. Using the Consent Management API, Twilio also checks the recipient's latest consent status.
Twilio blocks messages to opted-out recipients and returns error 21610. To learn more about opt out, see Twilio support for opt-out keywords.
The Compliance Toolkit Reassigned Number check verifies that the intended recipient's phone number belongs to the original recipient who provided explicit consent. The Compliance Toolkit checks your recipient's phone number against the US FCC Reassigned Numbers Database.
To provide accurate verification, the Compliance Toolkit establishes a date_of_consent for every number.
- If you provide the
date_of_consentfor a phone number through the Consent Management API, Compliance Toolkit uses this specific date as the source of truth for reassigned number checks. - If you don't provide a
date_of_consent, it uses the date the customer onboarded to the Compliance Toolkit. This value becomes the value against which it checks the Reassigned Number Database. This is used to verify the number hasn't been reassigned since you activated Compliance Toolkit.
If Twilio identifies a phone number reassignment to a different consumer after the established date_of_consent, Compliance Toolkit performs three actions:
- Updates the phone number consent status to
opt-out. - Blocks any future message attempts.
- Returns Error 21610 for API requests to that phone number.
To align with FCC safe harbor standards, Compliance Toolkit verifies the reassigned status of a phone number every 30 days.
When Twilio tries to send a message, Compliance Toolkit compares the send time with the regulated Quiet Hours of the recipient.
By default, Twilio reschedules non-essential messages sent during Quiet Hours1. To block non-essential messages instead, set this to block. The message gets blocked and returns a 30610 error.
To track scheduled messages, use existing webhooks, logs and Messaging Insights.
To safeguard your messaging from potential TCPA litigation issues, contact sales or Twilio Support to enable the TCPA Known Litigators Check. This feature identifies and blocks messages to phone numbers believed to be associated with prior TCPA-related legal activity.
No substitute for your due diligence
This safeguard stop non-essential messages to phone numbers believed to be associated with individuals or entities with a history of filing TCPA-related legal actions. This feature can't identify all potential litigants and doesn't guarantee no potential legal action. Twilio doesn't represent that this feature identifies every litigious entity or eliminates all risk. You comply with all applicable laws and understand any unwanted or noncompliant messages, no matter who receives them, might create the risk of TCPA or other litigation.
After the initial check, Compliance Toolkit re-verifies the litigator status of a given phone number every seven days.
To meet your specific messaging needs, customize the Compliance Toolkit using three API resources.
- Contact API sets the known ZIP code for each end user. To improve Quiet Hours accuracy, use the recipient's location rather than the area code of their phone number.
- Consent Management API sets the opt-in status for each recipient. To block or allow messages, Twilio uses these up-to-date, verified preferences.
- Twilio Programmable Messaging API sets the risk check for messages.
-
To evaluate messages for US-terminating traffic, set the
riskCheckparameter. When set todisable, Compliance Toolkit doesn't evaluate that message. You also don't incur associated charges.(warning)Risk check applies to messages terminating in the US only
Never set
"riskCheck": "disable"for any destination outside of the United States. This setting protects your account with Twilio global fraud prevention mechanisms, including SMS Pumping Protection. -
The
messageIntentparameter lets you explicitly define the use case for each message. The value provided inmessageIntentalways overrides Twilio's Compliance Toolkit AI/ML message classification model. If you specify themessageIntent, Compliance Toolkit honors your classification as the source of truth and overrides the prediction from its models.- If you set the
messageIntentto an essential use case value likeotp,customercare, ornotifications, Twilio exempts it from Quiet Hours checks and the known litigators check, and delivers it immediately. - If you set the
messageIntentto a non-essential use case value likemarketingorevents, Twilio enforces Quiet Hours. If the message is sent during the Quiet Hours window, Compliance Toolkit automatically reschedules it for delivery after Quiet Hours.
- If you set the
-
To manage multiple recipient consent statuses across your messaging channels, use the Consent Management API. Use it to store, sync, or update the opt-in status for your recipients. You can make updates across RCS, SMS, and MMS channels and include details about how and when you collected consent.
To synchronize large volumes of user consent preferences between two or more data sources, use the Consent Management API. One request can upsert multiple consent values.
To opt-in a recipient again, change their consent status to opt-in. This overrides the STOP keyword and lets you resume sending messages to this recipient.
To analyze aggregate trends and drill into Compliance Toolkit outcomes on your account, use Messaging Insights.
To view messages that meet certain conditions, filter messages in Messaging Insights:
The filter applied in this procedure serves as an example. You can choose other filters.
- Log in to the Twilio Console
- Go to Performance > Insights > Messaging. The Messaging Insights page appears.
- Click Delivery and Errors. The Delivery and Errors page appears.
- Click Add filters.
- From the Filter categories menu, click Used Scheduling. A Used Scheduling filter button appears.
- Click Used Scheduling. A dropdown menu appears.
- Change Operator to Equals.
- Change Used Scheduling to Yes.
- Click Apply.
- The values on the rest of the page update in response to your filter choices.
- To remove all filters, click Add filters, then click Clear Filters on the Filter categories menu.
To filter messages based on certain conditions, set the filter values to the following:
| View messages that include | Filter by | Operator | Value |
|---|---|---|---|
| Rescheduled for Quiet Hours | Used Scheduling | Equals | Yes |
| Phone numbers without consent | Error Code | Equals | 21610 |
| Phone numbers of known litigators | Error Code | Equals | 30640 |
Twilio AI Nutrition Facts provide an overview of this AI feature. This overview helps you better understand how AI works with your data. The following Nutrition Facts label outlines the qualities of Compliance Toolkit.
AI Nutrition Facts
Compliance Toolkit for Programmable Messaging
- Description
- Compliance Toolkit is a product available to Twilio Messaging customers that uses Artificial Intelligence to help manage their obligations with respect to certain local regulatory or compliance requirements.
- Privacy Ladder Level
- 3
- Feature is Optional
- Yes
- Model Type
- Machine Learning
- Base Model
- Logistic Regression
- Base Model Trained with Customer Data
- Yes
- Customer Data is Shared with Model Vendor
- No
- Training Data Anonymized
- Yes
- Data Deletion
- Yes
- Human in the Loop
- Yes
- Data Retention
- 30 days
- Logging & Auditing
- Yes
- Guardrails
- Yes
- Input/Output Consistency
- Yes
- Other Resources
Trust Ingredients
Model training uses customer messaging metadata. Data from HIPAA-enabled accounts is excluded.
Compliance
Standard service logging is applied and logs are stored for future review.
Learn more about this label at nutrition-facts.ai
-
When this non-essential message was sent during Quiet Hours, Twilio doesn't deliver it. It sets
ScheduleTypetofixedandsendAtto a timestamp in ISO 8601 format outside Quiet Hours. A successful change returns"status": "scheduled". ↩ ↩2 -
When you opt to block messages attempted to be sent during Quiet Hours, rather than reschedule these messages, Compliance Toolkit returns error 30610. ↩