> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance Posture FAQ

> The recurring operator questions about Orbit's compliance posture — who owns the gates, what defaults open, what fails open versus closed, why an enabled toggle may not be blocking yet, and which approvals carry external lead time.

# Compliance Posture FAQ

Answering the questions operators bring once they've read the
[posture map](/compliance/posture-overview): *I enabled the toggle —
why is nothing blocked yet? Why did a number only on the federal DNC
read back clear? What does the platform actually enforce for me, and
what is mine to own?*

Each answer below points at the deep page that owns the topic. Read
this page for the mental model; read the linked page before you build
on it.

<Warning>
  This page describes Orbit's platform controls. It is **not legal
  advice.** Which laws apply to your traffic, and what posture is
  adequate, depends on your jurisdiction, your recipients, and what you
  send. Confirm with qualified counsel.
</Warning>

***

## Are any of these gates platform-mandatory?

**No — with exactly one exception.** Compliance controls are
tenant-owned: Orbit gives you the control surface (gates, windows,
scrubs, registries), each gated control ships off, and it enforces
what you set rather than mandating a posture. The single exception is
the **US TCPA federal voice dialing window**: campaign and dialer
voice to US (+1) recipients outside the 8 AM–9 PM recipient-local
window is hard-blocked (`422 TCPA_FEDERAL_DIALING_WINDOW_BLOCKED`)
with no tenant toggle, no per-organization bypass, and no fail-open on
a timezone-unresolved recipient. The $500–$1,500 per-call statutory
penalty is not the tenant's to waive.

Stricter state mini-TCPA overlays (Florida's Sunday ban, Mississippi's
7:30 PM close, and the Oklahoma/Louisiana/Alabama/West Virginia
windows) sit on top of that federal rail and are likewise not a
tenant knob. Everything else — quiet hours, DNC, RND, STIR/SHAKEN
floors, HIPAA mode, DSAR, KYC gates — is yours to flip, default open.
The full asymmetry list is on
[What is not tenant-toggleable](/compliance/posture-overview).

***

## What does the compliance-health score never block?

Everything on the health surface is read-only: it reports your
posture, it never changes it. `GET /compliance/health` (plus
`/health/numbers` and `/health/campaigns`) blends consent coverage,
opt-out velocity, STOP-reply rate, and carrier rejections into a 0–100
score with a ranked `warnings` array — it never blocks a send,
suppresses a contact, or gates your traffic. Use it as an
early-warning read: which sender a carrier is about to throttle,
before the traffic degrades. The same rule holds for the quiet-hours
preview endpoint — it answers "would this send be held?" without
holding anything. See
[Compliance Health Scores](/compliance/compliance-health).

***

## I enabled quiet hours — does that protect my campaign sends?

Yes, if either of the two knobs is set. Campaign, drip, and journey
sends are evaluated against the **campaign fallback window** (set in
Settings → Campaign limits, or
`PUT /api/v1/campaigns/quiet-hours/settings`); if you never set one,
they fall back to the platform default 21:00–09:00. For 1:1 and
ad-hoc traffic, protection only exists where a channel is enabled on
the org gate (`settings → quiet_hours.<channel>.enabled`). So "quiet
hours on" must mean at least one of: a channel enabled on the org
gate, or a fallback window your campaign traffic inherits. Check
`GET /compliance/quiet-hours/preview` before a rollout to see exactly
what would be held and until when. The two-knob model is on
[Quiet hours configuration](/guides/quiet-hours-configuration).

Note again the one platform exception above: campaign and dialer voice
to US recipients is always held by the federal 8 AM–9 PM window even
with both toggles off — see
[Send Gates](/compliance/send-gates).

***

## Is Sender-ID approval instant?

**No.** Registering a Sender ID in Orbit submits it into the
compliance workflow, but final approval is granted by the regulator or
carrier in each country — not by the platform. A country entry sits at
`pending` (or returns `rejected` with a reason) until that external
decision lands, and A2P SMS into a country that requires a registered
Sender ID is **fail-closed**: blocked until that country's entry reads
`approved`. Plan lead time — some markets take days to weeks — and
attach the country's KYC documents up front to avoid a re-submission
loop. See [Sender-ID Registration](/compliance/sender-id-registration)
and the recovery workflow on
[Troubleshoot a pending number or Sender ID](/compliance/troubleshooting-pending-gated-surfaces).

The same external-lead-time pattern applies to US 10DLC (brand and
campaign review, 1–5 business days typical, per-carrier statuses
tracked separately) and to regulated-country number purchases, which
idle at `pending_compliance` until an approved compliance profile is
attached.

***

## Will the DNC scrub work out of the box on SaaS?

Partially — and the gap is the operator question this FAQ exists for.
The DNC chain scrubs your **own** layers (contact DNC flags, DNC
list, suppression, consent opt-outs) plus the platform list as soon as
you opt in with `dnc_sync_enabled`. The **federal/state/TCR feed
layer** only backs the check once a snapshot is synced, and on the
Devotel-hosted SaaS the TCR feed is only populated when the operator
iconectiv TCR partner credentials (`DEVOTEL_TCR_API_KEY` /
`DEVOTEL_TCR_PARTNER_ID`) are configured — if either is unset the
connector no-ops and no feed arrives. Until it does, two consequences
follow:

* `GET /compliance/dnc/check` returns `403 DNC_SYNC_NOT_ENABLED` until
  you opt in, and even after opting in it returns
  `federal_feeds_synced: false` on every response — a number only on
  the FTC federal register **reads back clear** in that state. Never
  treat a clear verdict as federal safe-harbor unless
  `federal_feeds_synced: true`.
* `GET /compliance/rnd/check` degrades similarly: until the FCC feed
  is synced, every verdict is `no_data` (no safe harbor), and enabling
  `rnd_scrub_enabled` is refused with a `409` until the feed is
  connected.

Read the source and freshness fields on every response, and see the
fail-open caveat on [DNC Scrubbing](/compliance/dnc-scrub) and the
feed configuration on
[10DLC registration](/guides/10dlc-registration). On the SaaS, Orbit
maintains the synced snapshots centrally once feeds are connected —
you never wire your own register integration per tenant.

***

## Which controls fail open and which fail closed?

Condensed from the [posture map](/compliance/posture-overview) — the
column to internalize before you trust a toggle:

| Control                                               | Default            | Unresolvable input                                                                                                                       |
| ----------------------------------------------------- | ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Quiet hours (per-channel org gate, campaign fallback) | Off                | **Fails open** — timezone-unresolved non-US recipients pass under the default `skip` policy                                              |
| DNC scrub                                             | Off                | **Fails open** — no federal feed synced means a solely-federal number reads clear                                                        |
| RND scrub                                             | Off                | **Fails open / no-data** — unsynced feed degrades every verdict to `no_data`, no safe harbor                                             |
| STIR/SHAKEN attestation + inbound floor               | No floor           | **Fails open** — a failed ownership lookup attests C and admits the call rather than blocking                                            |
| Emergency stop                                        | Inactive           | **Fails open by design** — blocks nothing until you pull it                                                                              |
| Preference center                                     | Not configured     | **Fails open** — absent a config, no contact-facing surface exists                                                                       |
| Sender-ID registration                                | Nothing registered | **Fails closed** — regulated A2P SMS blocked until the country's entry is `approved`                                                     |
| Suppression entries                                   | Empty list         | **Fails closed for entries that exist** — a suppressed address is dropped pre-dispatch                                                   |
| HIPAA mode                                            | Off                | **Fails closed toward PHI** — HIPAA mode will not enable and PHI sends are rejected (`422 HIPAA_BAA_REQUIRED`) until the BAA is executed |
| KYC-gated numbers                                     | None required      | **Fails closed for gated assets** — a regulated-country number idles at `pending_compliance`                                             |
| US federal voice window + state overlays              | Always active      | **Fails closed, platform-owned** — the one rail you do not control                                                                       |

The pattern: anything that protects a **recipient or a regulator**
fails closed or is platform-level; anything that protects **your own
list hygiene** is opt-in and fails open. The deep pages behind each
row are on [Send Gates](/compliance/send-gates).

***

## Is any of this legal advice?

No. Orbit is the conduit and the ledger: it carries your sends,
enforces the gates you set, and keeps the auditable record (consent
decisions, suppression entries, scrub results, certifications). It
does not decide that a send is compliant, does not file with a
regulator for you, and does not send customer notices for you. The
posture you choose is additive from an open default, and the
responsibility for choosing it stays yours. Confirm your obligations
with qualified counsel.

***

## Related references

* [Your Tenant Compliance Posture: The Toggle Map](/compliance/posture-overview) — the full map this FAQ condenses.
* [Send Gates](/compliance/send-gates) — every send-time gate and its exact gate behaviour.
* [DNC Scrubbing](/compliance/dnc-scrub) — sources, freshness, and the fail-open caveat.
* [Compliance Health Scores](/compliance/compliance-health) — the read-only signal layer.
* [Troubleshoot a pending number or Sender ID](/compliance/troubleshooting-pending-gated-surfaces) — gated assets stuck behind external approval.
* [Platform FAQ](/reference/faq) — non-compliance questions (authentication, billing, channels, webhooks).
