Security at SimpleSMS

This page lists the security controls that are built into SimpleSMS today, in plain terms, with a link to where each one is documented. It is a summary of what the product does and what our legal documents commit to. It does not add promises of its own, and it does not list anything we have not built.

Credentials

  • API keys are stored as salted hashes. A key is shown once, when it is created. We cannot show it again, and neither can anyone who reads our database. Lose one and you roll it (authentication).
  • Test and live keys are separate. A test key cannot send real traffic or run up a bill, so a leaked test key is not an incident.
  • Keys can be restricted to scopes. A service that only sends messages can hold a key that can do nothing else. A restricted key used outside its scopes gets 403 insufficient_scope.
  • Verification codes are stored hashed and expire after 10 minutes.

Account access

  • Two-step sign-in. A password sign-in to the console is followed by a one-time code, sent by text to the phone you verified or by email, or generated by an authenticator app.
  • Roles. Admins manage keys, billing, webhooks, numbers and the team. Members work the inbox, contacts and broadcasts. Viewers read and change nothing (teams).
  • Passwords and sessions. Console passwords need at least 12 characters of mixed types, accounts lock temporarily after repeated failed sign-ins, and console sessions expire after 30 minutes of inactivity (security best practices).

Webhooks

  • Every webhook is signed. Each delivery carries an HMAC-SHA256 signature over a timestamp and the raw body, made with a secret unique to the endpoint. The SDKs verify it for you and reject deliveries older than 5 minutes (webhooks).
  • Secrets rotate on demand. An admin can rotate an endpoint's secret in the console. The rotation is recorded in the audit log.

Audit log

Changes to API keys, team members, webhooks, spend limits, numbers, consent and settings are recorded with the actor, the time and the IP address. Admins can read the log in the console, through the API, or as a CSV export, and it is kept for the life of the account (audit log).

Limits that contain a mistake

  • Spend limit. A monthly cap on live messaging spend. A send whose estimated charge would pass the cap is refused, and alerts fire at thresholds you choose (spend limits).
  • Opt-outs are enforced by the platform. One account-wide suppression list gates every ordinary send. A send to an opted-out number is refused and not billed (opt-out and consent).
  • Unregistered numbers cannot text the public. Until a US local number is linked to an approved registration it can reach only the recipients you have verified.
  • Verification fraud protection. Verify applies velocity limits and blocks destinations used for SMS pumping before you are charged (verify).

Data handling

  • Encryption. TLS for data in transit and encryption at rest.
  • Message content stays out of our tooling. Internal alerts and usage analytics carry account identifiers and counts, never message bodies or verification codes.
  • No training on your messages. Message content is not used to train models, by us or by a provider we use.
  • Retention is published. How long each kind of data is kept is listed in Data Retention: for example API request logs for up to 30 days, webhook delivery logs for 30 days, lookup results cached for 24 hours, and deletion of account data within 90 days of an account closing.
  • Subprocessors are listed by category in Subprocessors, and the Data Processing Addendum describes the technical and organizational measures in full.

What we do not claim

SimpleSMS does not claim a third-party security certification on this page. The Service is not PCI DSS validated for cardholder data, and we do not sign HIPAA business associate agreements. Do not send payment card numbers, passwords, government ID numbers or protected health information through it (Terms). If your procurement process needs something specific, ask us and we will tell you plainly what we have.

Report a vulnerability

Email support@joinsimplesms.com with the details. We read every report and appreciate responsible disclosure. Our email comes from joinsimplesms.com and our links point to joinsimplesms.com. We will never ask for your password or a full API key.