Trust

Security & Trust Center

How SMS Gateway protects accounts, API access, and operational data—and where your team stays responsible for phones, SIMs, and operator credit. Last updated August 4, 2026.

01 / Compliance

Honest SOC 2 roadmap + policy links

02 / Privacy

Data categories & sharing limits

03 / Support

Security reports & vendor packets

Summary

Key takeaways

  • Security & Trust Center is the public summary of how SMS Gateway protects accounts, APIs, and operational data.
  • Service pricing is based on device count and total SMS sent through the gateway.
  • You need a working Android phone with a SIM and SMS credit from your mobile operator. Operator message costs are yours—we do not sell carrier SMS balance.
  • SOC 2 certification is on the roadmap; we do not claim a completed auditor report today.
  • Report vulnerabilities to info@sms-gateway.app (subject “Security report”) or via /.well-known/security.txt.
Overview

What is an SMS gateway security model?

SMS Gateway security is a split-trust model. Our cloud and Android app coordinate devices, authenticate API traffic, meter usage by devices and send volume, and store the account data required to bill and support you. Your handset and SIM perform the actual carrier send. That split is intentional: you keep operator economics and local number identity; we keep the orchestration layer secure and auditable.

You need a working Android phone with a SIM and SMS credit from your mobile operator. Operator message costs are yours—we do not sell carrier SMS balance. Enterprise buyers evaluating vendor risk should treat this page as the entry point, then request a signed questionnaire when procurement requires it.

For product setup and API key placement, see the setup guide and Developer Center. For messaging law and prohibited use, read the Acceptable Use Policy.

Controls

Security controls

Controls below describe production practice for the marketing site and gateway service surfaces. They are written for security questionnaires—not as marketing claims about unlimited risk elimination.

C01

Transport & browser hardening

Production traffic is HTTPS-only with HSTS. Marketing and app surfaces ship Content-Security-Policy, Permissions-Policy, Referrer-Policy, and Cross-Origin-Opener-Policy to reduce XSS, clickjacking, and unwanted cross-origin opener access.

Implemented
C02

API authentication

Gateway API calls require customer API keys. Keys should live in server-side environment variables, rotate on staff change or suspected exposure, and never be embedded in public client bundles or blog sample dumps with live values.

Implemented
C03

Device boundary you control

Phones, SIMs, and operator airtime stay under your operational control. Pairing establishes device trust with the service; it does not replace API-key hygiene on your backend. Physical access to handsets is your site-security responsibility.

Implemented
C04

Account & operational data

We process account registration, billing metadata, usage (devices and send volume), delivery reports, and support communications needed to run the service. See the Privacy Policy for categories, retention, and sharing limits.

Implemented
C05

Infrastructure & access

Cloud hosting and payment processors are limited subprocessors. Production access follows least privilege. Secrets are environment-based—not hardcoded in the public website repository.

Implemented
C06

Public contact form

The marketing contact form posts to a dedicated SES endpoint with origin allowlisting, honeypot, subject allowlist, and optional rate limiting. Form secrets never ship in the browser bundle. The Apache PHP fallback under public/assets loads SMTP credentials from environment only, enforces the same origin allowlist pattern, uses Reply-To (never open-CC of free-form addresses), and keeps vendor/logs out of HTTP reach.

Implemented
C07

Website analytics consent

The marketing site uses Google Analytics only after visitors accept analytics cookies (Consent Mode defaults deny analytics storage). Essential-only leaves analytics off. Preferences live in the browser and can be reopened from Cookie settings in the footer.

Implemented
C08

Abuse & monitoring

We monitor for fraud, credential stuffing, and Acceptable Use violations. Suspicious send patterns may be rate-limited or investigated. Customers remain responsible for recipient consent and local messaging law.

Implemented
Data

Privacy & data handling

Personal data categories, purposes, retention, and sharing are defined in the Privacy Policy. In short: we collect account and contact details you provide, usage and device metadata needed to operate the gateway, and support correspondence. We do not sell personal information for advertising.

Message bodies can contain sensitive codes or personal data. Design OTP and alert templates so SMS carries only what the recipient needs. Keep long-term PII in your systems of record, not in free-text SMS archives when a shorter token or ticket ID will do.

Payment card data is handled by payment processors (for example Stripe or PayPal) under their PCI programs—we do not ask you to paste full card numbers into support tickets. Contract terms live in the Terms & Conditions.

Compliance

Compliance posture

Roadmap

Certification status (plain language)

Secuno LLC is not claiming a completed SOC 2 Type I or Type II attestation on this page. We map operational controls to the SOC 2 Trust Services Criteria and maintain an internal roadmap toward independent audit. Sales and security teams must use this exact framing with prospects—never invent a badge or report date that does not exist.

Messaging compliance (TCPA, consent, STOP, local telecom rules) remains your obligation as the sender. Our Acceptable Use Policy states prohibited content and enforcement. Regional product context is covered on geo pages; it does not replace legal counsel in your jurisdiction.

External reference for SMS industry context: GSMA.

Contact

Support & security contact

General product support and vendor risk packets: email info@sms-gateway.app. Phone: +1 (315) 961-7074. Prefer the contact form for non-urgent requests. For suspected incidents, use subject “Security report” and avoid pasting production secrets in the first message. Machine-readable disclosure details live at /.well-known/security.txt (RFC 9116).

FAQ

Security FAQ

Is SMS Gateway SOC 2 certified?

Not yet. We operate security controls mapped to the SOC 2 Trust Services Criteria (security, availability, confidentiality, and privacy) and maintain a certification roadmap. We do not claim a completed SOC 2 Type I or Type II report until an independent auditor issues one. Enterprise buyers can request our current control summary and questionnaire responses via info@sms-gateway.app.

Where does SMS message content live?

Outbound SMS is sent from the Android device and SIM you connect. Carrier delivery happens on your operator network. Our service coordinates devices, API requests, delivery status, and account data. Treat message content as sensitive: use purpose-built templates, minimize PII in SMS bodies, and keep API keys on your servers—not in mobile apps or public repos.

Do you sell carrier SMS credits or rent phone numbers?

No. Service pricing is based on device count and total SMS sent through the gateway. You supply a working Android phone with a SIM and SMS credit from your mobile operator. Operator message costs are yours—we do not sell carrier SMS balance or rent long codes as a CPaaS aggregator.

How do we report a security issue?

Email info@sms-gateway.app with subject line “Security report”, or use Contact: mailto:info@sms-gateway.app from https://sms-gateway.app/.well-known/security.txt (RFC 9116). Include steps to reproduce, affected endpoints or surfaces, and impact. Do not include live production secrets in the initial report. We acknowledge responsible disclosures and prioritize confirmed issues that affect customer data or authentication.

What policies should security and legal teams review?

Start with this Trust Center, then review the Privacy Policy, Terms & Conditions, Acceptable Use Policy, and Refund Policy. For integration security, see the Developer Center (API keys, DLR, webhooks). Contact sales or support when you need a signed questionnaire or vendor risk packet.

Policies

Related policies

Summary: SMS Gateway security is priced and operated around devices and send volume on hardware you control. Use this Trust Center for vendor diligence, keep API keys off untrusted clients, and escalate real vulnerabilities through the security mailbox—not through public issue trackers with live credentials.

Get started

Ready to get started?

Download the app, connect your Android device, and start sending SMS through your own infrastructure. No credit card required.

Any Android device · Start in minutes