Skip to main content

Compliance Posture FAQ

Answering the questions operators bring once they’ve read the posture map: I enabled the toggle — why is nothing blocked yet? Why did a number only on the federal DNC read back clear? What does the platform actually enforce for me, and what is mine to own? Each answer below points at the deep page that owns the topic. Read this page for the mental model; read the linked page before you build on it. The first block — the one-line questions, a quick index — covers the short “what does X mean / does X block?” lookups operators land on from help-search, each pointing at the deep page that owns it. The platform-level questions follow it.
This page describes Orbit’s platform controls. It is not legal advice. Which laws apply to your traffic, and what posture is adequate, depends on your jurisdiction, your recipients, and what you send. Confirm with qualified counsel.

The one-line questions — the Q&A index

What does fail-open mean here?

Fail-open means the gate passes traffic when its input cannot be resolved, rather than blocking. Quiet hours, DNC, RND, the STIR/SHAKEN attestation floor, and the preference center all fail open by design: a timezone-unresolved non-US recipient passes under the default skip policy, an unsynced federal feed renders solely-federal numbers clear as no_data, and a failed attestation-ownership lookup signals C instead of blocking the call. Every gate ships off / open, and no gate blocks while its input is unreadable — you tighten from an open default, never loosen from a restrictive one. The rows marked Fail-open on the posture map list the surfaces, and Send Gates has the exact per-gate behaviour.

What is fail-closed by design?

Fail-closed means the gate blocks when enabled criteria catch, or when a required approval is missing. Sender-ID registration blocks regulated A2P SMS until the country’s entry is approved; a suppression entry drops the address pre-dispatch regardless of entry point; the US state mini-TCPA overlays hard-block campaign and dialer voice on the most-restrictive-wins rule; and HIPAA mode refuses PHI sends with 422 HIPAA_BAA_REQUIRED until the BAA is executed. The opt-in RMD origination guard, when you turn it on, blocks outbound voice at origination when your filing is deficient. The pattern holds from the platform level down: whatever protects a recipient or a regulator blocks; whatever protects your own list hygiene is opt-in and fails open. The rows marked Fail-closed on the posture map enumerate the surfaces — do not wire a recipient-protection gate as fail-open.

Where do I see my gates?

Two places. In the dashboard, the Settings → Compliance group of routes holds every writable gate; over the API, the GET /api/v1/settings/compliance/* reads report each toggle’s current value — unknown-consent marketing policy, consent default policy, country allowlist, inbound country gate, fraud caps, channel-rate overrides, AI-turn audit, and the inbox-AI privacy gates. The GET /compliance/health scores and the GET /compliance/quiet-hours/preview endpoint are the read-only surfaces for the same posture. Verify every write with the paired GET — never assume a PUT took. The Settings → Compliance surface is mapped row by row on the posture map, and Configure Your Tenant’s Posture Before the First Send walks it in day-one order.

How many minutes to set up a posture?

Two flips for either of the two most common postures. For “Marketing to US mobiles”: (1) enable the sms channel on the org quiet-hours gate, and (2) bulk-import any legacy opt-out list with POST /compliance/suppression-list/import while you complete brand and campaign registration — US long-code traffic degrades without it regardless of gate posture. See Posture A. For “Healthcare appointment reminders”: (1) execute the BAA and enable HIPAA mode (PUT /api/v1/settings/hipaa — the mode refuses to enable until then), and (2) close the inbox-AI gates with PATCH /api/v1/settings/compliance/inbox-ai-privacy (auto_categorize: false, auto_summarize: false), because both ship on and send inbound message bodies to a third-party LLM. See Posture D and the full HIPAA onboarding walkthrough.

How do I audit what a gate did?

Read the auditable record — Orbit logs every gate decision, covering consent decisions, suppression entries, scrub results, certifications, and the owner-only settings flips in the org audit log. For a specific send the record answers why it was held or passed: quiet-hours holds report the resolved window and the preview endpoint the next_allowed_at timestamp, and voice blocks report outside_state_window / state_blocked_day reasons so state holds are separable from federal ones. When the audit question outgrows gate-level rows: one-click, framework-mapped packs on Evidence Binder (SOC 2 / ISO 27001 / GDPR / HIPAA), verbatim AI-turn records on AI Turn Audit (off by default — it persists multi-year verbatim PII, so enable it per written policy), and the GDPR Art. 33/34 clock on Breach Incident Register.
No. The gates and their audit trail are tenant-owned controls, and the responsibility for choosing a posture — and for deciding whether a posture is adequate — stays yours. Orbit is the conduit and the ledger; it does not decide that a send is compliant, does not file with a regulator for you, and does not send customer notices for you. Which laws apply to your traffic depends on where you and your recipients are and what you send. Confirm your obligations with qualified counsel before you rely on any posture described here.

Are any of these gates platform-mandatory?

No — with exactly one exception. Compliance controls are tenant-owned: Orbit gives you the control surface (gates, windows, scrubs, registries), each gated control ships off, and it enforces what you set rather than mandating a posture. The single exception is the US TCPA federal voice dialing window: campaign and dialer voice to US (+1) recipients outside the 8 AM–9 PM recipient-local window is hard-blocked (422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED) with no tenant toggle, no per-organization bypass, and no fail-open on a timezone-unresolved recipient. The 500–500–1,500 per-call statutory penalty is not the tenant’s to waive. Stricter state mini-TCPA overlays (Florida’s Sunday ban, Mississippi’s 7:30 PM close, and the Oklahoma/Louisiana/Alabama/West Virginia windows) sit on top of that federal rail and are likewise not a tenant knob. Everything else — quiet hours, DNC, RND, STIR/SHAKEN floors, HIPAA mode, DSAR, KYC gates — is yours to flip, default open. The full asymmetry list is on What is not tenant-toggleable.

What does the compliance-health score never block?

Everything on the health surface is read-only: it reports your posture, it never changes it. GET /compliance/health (plus /health/numbers and /health/campaigns) blends consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100 score with a ranked warnings array — it never blocks a send, suppresses a contact, or gates your traffic. Use it as an early-warning read: which sender a carrier is about to throttle, before the traffic degrades. The same rule holds for the quiet-hours preview endpoint — it answers “would this send be held?” without holding anything. See Compliance Health Scores.

I enabled quiet hours — does that protect my campaign sends?

Yes, if either of the two knobs is set. Campaign, drip, and journey sends are evaluated against the campaign fallback window (set in Settings → Campaign limits, or PUT /api/v1/campaigns/quiet-hours/settings); if you never set one, they fall back to the platform default 21:00–09:00. For 1:1 and ad-hoc traffic, protection only exists where a channel is enabled on the org gate (settings → quiet_hours.<channel>.enabled). So “quiet hours on” must mean at least one of: a channel enabled on the org gate, or a fallback window your campaign traffic inherits. Check GET /compliance/quiet-hours/preview before a rollout to see exactly what would be held and until when. The two-knob model is on Quiet hours configuration. Note again the one platform exception above: campaign and dialer voice to US recipients is always held by the federal 8 AM–9 PM window even with both toggles off — see Send Gates.

Is Sender-ID approval instant?

No. Registering a Sender ID in Orbit submits it into the compliance workflow, but final approval is granted by the regulator or carrier in each country — not by the platform. A country entry sits at pending (or returns rejected with a reason) until that external decision lands, and A2P SMS into a country that requires a registered Sender ID is fail-closed: blocked until that country’s entry reads approved. Plan lead time — some markets take days to weeks — and attach the country’s KYC documents up front to avoid a re-submission loop. See Sender-ID Registration and the recovery workflow on Troubleshoot a pending number or Sender ID. The same external-lead-time pattern applies to US 10DLC (brand and campaign review, 1–5 business days typical, per-carrier statuses tracked separately) and to regulated-country number purchases, which idle at pending_compliance until an approved compliance profile is attached.

Will the DNC scrub work out of the box on SaaS?

Partially — and the gap is the operator question this FAQ exists for. The DNC chain scrubs your own layers (contact DNC flags, DNC list, suppression, consent opt-outs) plus the platform list as soon as you opt in with dnc_sync_enabled. The federal/state/TCR feed layer only backs the check once a snapshot is synced, and on the Devotel-hosted SaaS the TCR feed is only populated when the operator iconectiv TCR partner credentials (DEVOTEL_TCR_API_KEY / DEVOTEL_TCR_PARTNER_ID) are configured — if either is unset the connector no-ops and no feed arrives. Until it does, two consequences follow:
  • GET /compliance/dnc/check returns 403 DNC_SYNC_NOT_ENABLED until you opt in, and even after opting in it returns federal_feeds_synced: false on every response — a number only on the FTC federal register reads back clear in that state. Never treat a clear verdict as federal safe-harbor unless federal_feeds_synced: true.
  • GET /compliance/rnd/check degrades similarly: until the FCC feed is synced, every verdict is no_data (no safe harbor), and enabling rnd_scrub_enabled is refused with a 409 until the feed is connected.
Read the source and freshness fields on every response, and see the fail-open caveat on DNC Scrubbing and the feed configuration on 10DLC registration. On the SaaS, Orbit maintains the synced snapshots centrally once feeds are connected — you never wire your own register integration per tenant.

Which controls fail open and which fail closed?

Condensed from the posture map — the column to internalize before you trust a toggle: The pattern: anything that protects a recipient or a regulator fails closed or is platform-level; anything that protects your own list hygiene is opt-in and fails open. The deep pages behind each row are on Send Gates.

Does this page cover the EU AI Act’s Annex III high-risk tier?

No — and the split follows the same tenant-owned pattern as everything else on this page. Orbit ships the Article 50 transparency surface: AI-interaction disclosure notices, AI-generated-content marking, and exportable evidence, configured per workspace on EU AI Act — Article 50 Transparency. Annex III is a separate tier: the high-risk use cases (for example emotion recognition, biometric categorization, and the other listed classes) carry risk-management, data-governance, technical-documentation, and conformity-assessment obligations on a later timeline than the transparency obligation. The classification — whether your deployment falls into an Annex III use case at all — is yours to make with qualified counsel; the controls either way stay tenant-owned, exactly as with the gates above. If an Annex III use case does apply, Article 50 transparency still applies on top.
No. Orbit is the conduit and the ledger: it carries your sends, enforces the gates you set, and keeps the auditable record (consent decisions, suppression entries, scrub results, certifications). It does not decide that a send is compliant, does not file with a regulator for you, and does not send customer notices for you. The posture you choose is additive from an open default, and the responsibility for choosing it stays yours. Confirm your obligations with qualified counsel.