Trust Center
Security and compliance you can verify — not just take our word for.
SMSGatewayHub powers OTP, transactional, and marketing messaging for banks, fintechs, and enterprises across Bulk SMS, WhatsApp Business API, RCS, and Voice SMS. Here's exactly how we protect your data and your customers' data.
🏅
ISO 27001 Certified
Information security
📋
SOC 2 Report
Available on request
🇮🇳
TRAI DLT Registered
TCCCPR compliant routing
⚡
99.97% Uptime
Last 30 days
Certifications
Independently audited and certified — not self-declared.
ISO 27001
Certified for information security management — covering how we protect the confidentiality, integrity, and availability of customer data.
ISO 9001:2015
Certified for quality management systems across our service delivery and operations.
SOC 2 Report
SOC 2 report covering security controls across our platform, available to enterprise customers on request.
VAPT Certified
Regular Vulnerability Assessment and Penetration Testing conducted on our infrastructure and applications. See our methodology →
TRAI DLT Registered
Registered under TRAI's TCCCPR framework. Every sender ID, template, and content category is DLT-registered and monitored, with blackout-window enforcement built in.
Meta Business Partner
Our WhatsApp Business API integration follows Meta's Business Messaging Policy — template approvals, 24-hour session windows, and opt-in requirements.
View Certificates →
VAPT — independently penetration tested
Regular Vulnerability Assessment and Penetration Testing across our APIs, webhooks, and infrastructure — with every finding remediated before it reaches production.
Key attack surfaces we test
Attack surface
API Gateways
Endpoint authentication, authorization, and rate-limiting controls across every public API.
Attack surface
Webhooks
Callback integrity checks so delivery-report and status webhooks can't be spoofed or intercepted.
Attack surface
Session & API Key Management
How API keys and session tokens are issued, rotated, and invalidated.
Attack surface
Data in Transit
Every channel is checked for unencrypted traffic that could allow eavesdropping.
Our VAPT methodology
Step 1
Information Gathering
Mapping public APIs, SDKs, documentation, and every messaging entry point.
Step 2
Vulnerability Assessment
Automated scanning for known bugs, open ports, and outdated cryptographic configurations.
Step 3
Penetration Testing
Manual attempts to bypass authorization, hijack sessions, or manipulate API parameters.
Step 4
Business Logic Testing
Evaluating messaging-specific abuse paths — OTP bypass attempts and traffic-pumping patterns.
Vulnerabilities we specifically test for
OTP Bypass & SMS Pumping
Guards against automated OTP-guessing attempts and artificial traffic generated to trigger fraudulent SMS volume.
Broken Object-Level Authorization
Checks that account or message identifiers in API requests can't be manipulated to access another customer's data.
Sender ID & Template Spoofing
Verifies that only DLT-registered, template-matched content can go out under an approved sender ID.
Toll & Traffic Fraud
Anomaly monitoring on Voice SMS and messaging volume to catch and rate-limit unusual spikes early.
Why enterprises require this
PCI DSS
Relevant when payment or card-authentication data passes through SMS or voice OTP flows.
HIPAA-aligned workflows
Relevant for healthcare senders transmitting appointment reminders or patient updates.
SOC 2 Type II
What enterprise procurement teams typically require to prove data is handled securely and confidentially.
VAPT report available on request under NDA. PCI DSS and HIPAA items describe why regulated customers require independent testing — confirm current certification scope with our team before citing it in a procurement response.
Compliance framework
Messaging in India runs on a strict regulatory backbone. We build to it, not around it.
TRAI TCCCPR / DLT
Every sender ID, message template, and content category on our platform is registered on the DLT ledger. Blackout-window enforcement (10 PM–9 AM restrictions), template-mismatch checks, and consent scrubbing happen before a message ever leaves our system.
DPDP Act, 2023
Our data collection, processing, and retention practices are aligned with the Digital Personal Data Protection Act 2023 and the 2025 Rules — covering consent, purpose limitation, and data principal rights.
WhatsApp Business Policy
Our WhatsApp Business API integration follows Meta's Business Messaging Policy — including template approval workflows, 24-hour session windows, and opt-in requirements.
Sector-specific readiness
For BFSI and healthcare clients, we support additional controls on request — audit logs, dedicated sender IDs, and data-handling addenda for regulated workflows.
Data safety, by default
The controls that apply to every account, every plan, with no extra configuration.
TLS Encryption in Transit
Per-Account API Keys
Role-Based Access & Audit Logs
DND & Consent Scrubbing
DLT Sender ID & Template Verification
India-Based Data Residency
Additional controls such as at-rest encryption standard, webhook signing, and PII retention windows are documented in our Security Overview — available on request below.
How your data is protected
Practical controls across the message lifecycle — from API call to delivery report.
Encryption
All API traffic is encrypted in transit via TLS. Sensitive fields, including OTP payloads, are never logged in plaintext in application logs.
API Authentication
Every account authenticates via a unique API key. Optional IP whitelisting restricts which servers can send on your behalf.
Access Control
Internal access to production systems and customer data is role-based and limited to personnel who need it for support or operations.
Monitoring & Logging
Delivery reports, API usage, and account activity are logged and available to you via dashboard and reporting APIs for full traceability.
Infrastructure
Our platform runs on hardened cloud infrastructure with regular patching, firewalling, and network-level access restrictions.
Business Continuity
Multi-route SMS delivery and redundant WhatsApp/RCS pathways reduce single points of failure in your messaging pipeline.
Policies & documentation
The documents most requested by security and procurement teams.
Frequently asked questions
Straight answers to what procurement and security teams usually ask first.
Is SMSGatewayHub compliant with India's DPDP Act, 2023?
Yes. Our data handling, consent, and privacy practices are aligned with the Digital Personal Data Protection Act, 2023 and its 2025 Rules. Full details are in our Privacy Policy.
Is SMSGatewayHub registered under TRAI's DLT framework?
Yes. As a registered entity under TRAI's TCCCPR framework, all SMS traffic is DLT-compliant — sender IDs, templates, and content categories are registered and actively monitored.
Is SMSGatewayHub ISO and SOC 2 certified?
Yes. We hold ISO 9001:2015 and ISO 27001 certifications, a SOC 2 report, and a VAPT certificate. Copies are available on our ISO Certified page.
Where is our data stored?
Customer and messaging data is stored on infrastructure located in India, in line with data residency expectations for Indian enterprise and government customers.
What does your VAPT process cover?
API gateways, webhooks, session and API-key management, and data-in-transit channels, plus business-logic testing for messaging-specific risks like OTP abuse and SMS pumping. See our VAPT methodology above.
How do you prevent SMS pumping and toll fraud?
Traffic is monitored for anomalous spikes, sender IDs and templates are DLT-verified before delivery, and unusual volume is rate-limited and flagged for review.
Do you sign NDAs or DPAs for enterprise deployments?
Yes — reach out to our team and we'll share the relevant documentation for your security or legal review.
How do we report a security concern?
Email info@smsgatewayhub.com with details. We acknowledge all reports and investigate promptly.
Need this for a vendor security review?
We'll share our full security documentation pack — architecture overview, data flow, and compliance statements — directly with your team.
Request Documentation Pack