Skip to contentSkip to navigationSkip to topbar
Page tools
Useful for sharing or LLM
Accelerate development with AI

On this page
Looking for more inspiration?Visit the

Compliance Toolkit for Programmable Messaging


(information)

Limited to US-terminating SMS messages in English

This feature supports SMS messages terminating in the United States written in English language only.

To help with regulatory compliance, Compliance Toolkit embeds AI-powered safeguards into your messaging workflows. To prevent issues before sending messages, it detects possible violations, identifies high-risk recipients, and applies intelligent transmission controls.

To learn about Compliance Toolkit pricing, see SMS Pricing(link takes you to an external page) or contact Sales(link takes you to an external page).


Compliance concepts

compliance-concepts page anchor

Quiet Hours are defined as the time in which an organization can't deliver non-essential messages to recipients. Compliance Toolkit enforces federal and state Quiet Hours rules based on the recipient's location. Twilio determines location from recipient data: either the area code of the phone number (default) or the ZIP Code (recommended). To provide the ZIP codes of the your recipients, set them with the Contact API.

The US Federal Communications Commission (FCC) defines these hours under the Telephone Consumer Protection Act (TCPA)(link takes you to an external page) as 9:00 PM to 8:00 AM in the recipient's local time zone.

Compliance Toolkit also enforces state-specific quiet hours mandates.

StateUS Time ZoneQuiet hours

Alabama

Central

8:00 PM – 8:00 AM

Connecticut

Eastern

8:00 PM – 9:00 AM

Florida

Eastern

8:00 PM – 8:00 AM

Louisiana

Central

8:00 PM – 8:00 AM

Maryland

Eastern

8:00 PM – 8:00 AM

Mississippi

Central

8:00 PM – 8:00 AM

Nevada

Mountain

8:00 PM – 9:00 AM

Oklahoma

Central

8:00 PM – 8:00 AM

Tennessee

Eastern

8:00 PM – 8:00 AM

Texas

Central

9:00 PM – 9:00 AM (Mon.-Sat.)

Texas

Central

9:00 PM – 12:00 PM (Sun.)

Washington

Pacific

8:00 PM – 8:00 AM

Non-essential messages that fall into these restricted windows get re-scheduled and delivered once Quiet Hours end.

(warning)

Consult legal advice on additional restrictions

Compliance Toolkit doesn't enforce any restrictions or requirements outside of federal and state quiet hours. To ensure your compliance when using any Twilio Service, check with your legal counsel for any additional requirements.

Essential vs. non-essential messages

essential page anchor

If the message falls within Quiet Hours, the Compliance Toolkit classifies the message using an AI model as essential or non-essential. This classification is based on the message content and context.

(information)

Recommended

To define the use case for each message, add the messageIntent parameter. Its value always overrides the Compliance Toolkit AI/ML message classification model. If you specify the messageIntent, Compliance Toolkit honors your classification as the source of truth, overriding the prediction from its models.

The following table lists which use cases you can configure for the messageIntent parameter and the Quiet Hours mapping assigned for that use case.

EssentialNon-Essential
Use casemessageIntent value
Two-factor auth (2FA) and one-time passcodes (OTP)otp
Account notifications, two-way conversational messagingnotifications
Fraud alertsfraud
Security alerts, emergency announcementssecurity
Customer carecustomercare
Delivery notificationsdelivery

Get started with Compliance Toolkit

get-started-with-compliance-toolkit page anchor

To activate Compliance Toolkit, go to your account settings in the Twilio Console.

Twilio ConsoleLegacy Console
  1. Log in to the Twilio Console(link takes you to an external page)
  2. Go to Communications > Messaging > Settings > General(link takes you to an external page). The General Messaging Settings page appears.
  3. Scroll to Compliance Toolkit Settings.
  4. Click Enabled. The Compliance Toolkit modal displays.
  5. Review the text of this modal, then click Twilio Compliance Toolkit: AI/ML and Product Terms Addendum(link takes you to an external page).
  6. Click Done. The Compliance Toolkit modal closes.
  7. Click Save.

Once activated, the toolkit runs on your existing messaging flows. You don't need to take further action.


Compliance Toolkit checks

compliance-toolkit-checks page anchor

Once you enable Compliance Toolkit, all US outbound SMS traffic in the enabled account passes through Compliance Toolkit. In asking the following questions, the toolkit helps identify and resolve possible compliance violations:

Check message type

check-type page anchor

To avoid interruptions to your critical communications, Compliance Toolkit distinguishes between different types of messages using its AI/ML message classification model.

  • Essential: Delivers non-promotional messages to the recipient.
  • Non-Essential: Processes marketing or promotional messages as given in the following table:
CheckMessageReturns error
Recipient has opted outBlocked21610
Recipient has Reassigned Phone NumberBlocked21610
Recipient is TCPA Known LitigatorBlocked30640
Non-essential message sent during Quiet Hours with default settings1Rescheduled30640
Non-essential message sent during Quiet Hours with block setting2Blocked30640

You can override the message type that the Compliance Toolkit AI/ML message classification model set. To change the message type, add the messageIntent parameter. If you specify the messageIntent, Compliance Toolkit honors your classification as the source of truth and overrides its model predictions.

Check for re-assigned numbers

check-reassign page anchor

The Compliance Toolkit Reassigned Number check verifies that the intended recipient's phone number belongs to the original recipient who provided explicit consent. The Compliance Toolkit checks your recipient's phone number against the US FCC Reassigned Numbers Database(link takes you to an external page).

To provide accurate verification, the Compliance Toolkit establishes a date_of_consent for every number.

  • If you provide the date_of_consent for a phone number through the Consent Management API, Compliance Toolkit uses this specific date as the source of truth for reassigned number checks.
  • If you don't provide a date_of_consent, it uses the date the customer onboarded to the Compliance Toolkit. This value becomes the value against which it checks the Reassigned Number Database. This is used to verify the number hasn't been reassigned since you activated Compliance Toolkit.

If Twilio identifies a phone number reassignment to a different consumer after the established date_of_consent, Compliance Toolkit performs three actions:

  1. Updates the phone number consent status to opt-out.
  2. Blocks any future message attempts.
  3. Returns Error 21610 for API requests to that phone number.

To align with FCC safe harbor standards, Compliance Toolkit verifies the reassigned status of a phone number every 30 days.

Check sending time against Quiet Hours

check-quiet page anchor

When Twilio tries to send a message, Compliance Toolkit compares the send time with the regulated Quiet Hours of the recipient.

By default, Twilio reschedules non-essential messages sent during Quiet Hours1. To block non-essential messages instead, set this to block. The message gets blocked and returns a 30610 error.

To track scheduled messages, use existing webhooks, logs and Messaging Insights.

Check for TCPA known litigators

check-litigator page anchor

To safeguard your messaging from potential TCPA litigation(link takes you to an external page) issues, contact sales(link takes you to an external page) or Twilio Support(link takes you to an external page) to enable the TCPA Known Litigators Check. This feature identifies and blocks messages to phone numbers believed to be associated with prior TCPA-related legal activity.

(warning)

No substitute for your due diligence

This safeguard stop non-essential messages to phone numbers believed to be associated with individuals or entities with a history of filing TCPA-related legal actions. This feature can't identify all potential litigants and doesn't guarantee no potential legal action. Twilio doesn't represent that this feature identifies every litigious entity or eliminates all risk. You comply with all applicable laws and understand any unwanted or noncompliant messages, no matter who receives them, might create the risk of TCPA or other litigation.

After the initial check, Compliance Toolkit re-verifies the litigator status of a given phone number every seven days.


Tune your Compliance Toolkit setup

tune-your-compliance-toolkit-setup page anchor

To meet your specific messaging needs, customize the Compliance Toolkit using three API resources.

  1. Contact API sets the known ZIP code for each end user. To improve Quiet Hours accuracy, use the recipient's location rather than the area code of their phone number.
  2. Consent Management API sets the opt-in status for each recipient. To block or allow messages, Twilio uses these up-to-date, verified preferences.
  3. Twilio Programmable Messaging API sets the risk check for messages.
    • To evaluate messages for US-terminating traffic, set the riskCheck parameter. When set to disable, Compliance Toolkit doesn't evaluate that message. You also don't incur associated charges.

      (warning)

      Risk check applies to messages terminating in the US only

      Never set "riskCheck": "disable" for any destination outside of the United States. This setting protects your account with Twilio global fraud prevention mechanisms, including SMS Pumping Protection.

    • The messageIntent parameter lets you explicitly define the use case for each message. The value provided in messageIntent always overrides Twilio's Compliance Toolkit AI/ML message classification model. If you specify the messageIntent, Compliance Toolkit honors your classification as the source of truth and overrides the prediction from its models.

      • If you set the messageIntent to an essential use case value like otp, customercare, or notifications, Twilio exempts it from Quiet Hours checks and the known litigators check, and delivers it immediately.
      • If you set the messageIntent to a non-essential use case value like marketing or events, Twilio enforces Quiet Hours. If the message is sent during the Quiet Hours window, Compliance Toolkit automatically reschedules it for delivery after Quiet Hours.

To analyze aggregate trends and drill into Compliance Toolkit outcomes on your account, use Messaging Insights.

To view messages that meet certain conditions, filter messages in Messaging Insights:

Twilio ConsoleLegacy Console

The filter applied in this procedure serves as an example. You can choose other filters.

  1. Log in to the Twilio Console(link takes you to an external page)
  2. Go to Performance > Insights > Messaging(link takes you to an external page). The Messaging Insights page appears.
  3. Click Delivery and Errors. The Delivery and Errors page appears.
  4. Click Add filters.
  5. From the Filter categories menu, click Used Scheduling. A Used Scheduling filter button appears.
  6. Click Used Scheduling. A dropdown menu appears.
    1. Change Operator to Equals.
    2. Change Used Scheduling to Yes.
    3. Click Apply.
  7. The values on the rest of the page update in response to your filter choices.
  8. To remove all filters, click Add filters, then click Clear Filters on the Filter categories menu.

To filter messages based on certain conditions, set the filter values to the following:

View messages that includeFilter byOperatorValue
Rescheduled for Quiet HoursUsed SchedulingEqualsYes
Phone numbers without consentError CodeEquals21610
Phone numbers of known litigatorsError CodeEquals30640

Twilio AI Nutrition Facts(link takes you to an external page) provide an overview of this AI feature. This overview helps you better understand how AI works with your data. The following Nutrition Facts label outlines the qualities of Compliance Toolkit.

AI Nutrition Facts

Compliance Toolkit for Programmable Messaging

Description
Compliance Toolkit is a product available to Twilio Messaging customers that uses Artificial Intelligence to help manage their obligations with respect to certain local regulatory or compliance requirements.
Privacy Ladder Level
3
Feature is Optional
Yes
Model Type
Machine Learning
Base Model
Logistic Regression

Trust Ingredients

Base Model Trained with Customer Data
Yes

Model training uses customer messaging metadata. Data from HIPAA-enabled accounts is excluded.

Customer Data is Shared with Model Vendor
No
Training Data Anonymized
Yes
Data Deletion
Yes
Human in the Loop
Yes
Data Retention
30 days

Compliance

Logging & Auditing
Yes

Standard service logging is applied and logs are stored for future review.

Guardrails
Yes
Input/Output Consistency
Yes
Other Resources

Frequently asked questions

  1. When this non-essential message was sent during Quiet Hours, Twilio doesn't deliver it. It sets ScheduleType to fixed and sendAt to a timestamp in ISO 8601(link takes you to an external page) format outside Quiet Hours. A successful change returns "status": "scheduled". ↩ ↩2

  2. When you opt to block messages attempted to be sent during Quiet Hours, rather than reschedule these messages, Compliance Toolkit returns error 30610. ↩