> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Baseline compliance posture for US SMS traffic

> Everyday US SMS, marketing vs. transactional lane split, 10DLC rules, suppression and quiet-hours gates, and a checklist scaffold you run per sender — tenant-owned controls, not legal advice.

# Baseline compliance posture for US SMS traffic

Most tenants run the same everyday traffic: order updates, support replies,
marketing promotions — in short, **garden-variety application-to-person (A2P)
messaging**. For that traffic class, US carriers demand one thing above all
else: your **10DLC campaign must be approved as `MARKETING` or `MIXED`**, and
your **consent, opt-out, and quiet-hours controls must be wired before you
send**. This page is the baseline posture for exactly that sender. It does not
touch HIPAA or PCI-DSS; it is the every-day posture the healthcare and payments
verticals layer on top of.

<Note>
  Everything on this page is **tenant-owned**. Orbit supplies the controls and
  defaults them open — you set them, you file the registrations, and the
  go-live decision stays yours. This page is **not legal advice**. Confirm your
  TCPA, CTIA, and state-law obligations with qualified counsel.
</Note>

***

## The two lanes: marketing vs. transactional

Carriers evaluate your traffic by **use case**, and every campaign submission
declares one. The two you actually send fall into two lanes, and mixing them is
the most common cause of rejection:

* **Transactional** — account notifications, delivery updates, customer care,
  two-factor auth. Recipients expect the message; consent posture is usually
  informational; quiet-hours carve-outs are broader.
* **Marketing** — promotions, offers, sales outreach. Recipients gave you
  **prior express written consent**; opt-out and quiet-hours posture is the
  strictest; carriers vet the opt-in flow hardest.

A `MARKETING` campaign on a brand whose traffic is actually `CUSTOMER_CARE`
samples is the classic **use-case mismatch rejection** — file it under
`MARKETING` from the first submission and the mismatch vanishes. The
[10DLC rejections and re-vet guide](/guides/10dlc-rejections-and-revet) decodes
the exact codes when a filing comes back, and the wizard enforces the
distinction between the lanes on the summary step.

***

## 1. HIPAA and PCI transaction patterns (when your traffic is not garden-variety)

If your recipient set includes patients or cardholders, this page is the layer
**under** your vertical controls, not a replacement for them:

* **HIPAA-covered traffic** layers a per-organization toggle, BAA tracking,
  PHI access logging, and data-retention enforcement on top of these controls —
  see [HIPAA compliance controls](/compliance/hipaa). Toggle HIPAA mode before
  you put PHI in a message body; the 10DLC posture below stays the same.
* **PCI-adjacent traffic** never puts a full PAN or card data in a message body.
  The pre-send policy scanner blocks a full credit-card number or Social
  Security number in the body before dispatch — see [Pre-Send Policy Scanner &
  DLP](/compliance/policy-scanner). Use a secure link instead of inline card
  data; the [DLP specifics](/compliance/policy-scanner#dlp-sensitive-data-scanning)
  section names the exact rules.

For the everyday sender — retail promotions, order updates, appointment
reminders — the rest of this page is the complete baseline.

***

## 2. 10DLC rules on US SMS

US A2P traffic on standard 10-digit numbers runs through **The Campaign
Registry (TCR)**. The registration, rejection, and re-vet surfaces are the
same for every sender; the wizard is the recommended path.

* **Register a brand** — the legal entity TCR anchors the campaign to. For
  sole proprietors the anchor is a verified phone number by OTP; every other
  entity type files an EIN. See the
  [10DLC registration guide](/guides/10dlc-registration).
* **File the campaign as `MARKETING`** — when your traffic is promotions,
  do not file `CUSTOMER_CARE`; file `MARKETING` (or `MIXED` only when the same
  sender genuinely serves both lanes). The wizard and the single-shot campaign
  endpoint validate the use case before submission; the
  [10DLC registration wizard](/guides/10dlc-wizard) guide names the full flow,
  and the preflight linter scores your samples for SHAFT-C wording, shortener
  links, and missing STOP wording **before** the filing fee is charged.
* **Keep throughput ahead of volume** — the tier your vetting score grants
  caps your daily message count per number. When your volume approaches the
  cap, re-vet the brand; read the
  [10DLC rejections and re-vet guide](/guides/10dlc-rejections-and-revet) for
  the re-vet and throughput endpoints and the per-carrier class map.

***

## 3. Suppression and quiet-hours gates

These two are the hard send-side controls. Both are tenant-owned; both default
off; for the baseline posture you turn them on before go-live.

### Suppression — never message an opted-out address

Suppression is the legal-duty list: STOP, unsubscribed, bounced, complained.
Orbit treats it as a hard send-gate that halts the send before dispatch — no
campaign, contact import, or API call bypasses it.

* **Seed the list before the first send** — if you migrated from another
  platform, bulk-import the legacy suppression list once. The
  [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) page spells
  out the import endpoint and per-row results.
* **Scope it correctly** — scope `all` suppresses a phone number across
  every channel, including voice; email addresses scope to `email`. Use
  scope `all` for a phone STOP signal unless you intentionally want to keep
  the contact on voice.
* **Custom keywords on top of defaults** — when a branded STOP alias
  (another language, another brand) should trigger suppression, add it to an
  opt-out list on the matching messaging service; the platform defaults
  (`STOP`, `CANCEL`, `UNSUBSCRIBE` and their help/start complements) are
  mandatory and always present — see
  [Custom Opt-Out Keyword Lists](/guides/opt-out-lists).

### Quiet hours — hold the send until it is allowed

Marketing to a sleeping recipient is the single most common TCPA complaint on
US SMS. Orbit's quiet-hours gate is a tenant-owned, per-channel toggle; the
only hard platform rule is the federal voice window, which does not apply to
SMS. For SMS, the gate is yours:

* **Set an org-wide window** — enable the `sms` channel on the org gate and
  accept the platform window 08:00–21:00 recipient-local, or narrow it to
  your own regime. The
  [Quiet hours: org-wide channel gates](/guides/quiet-hours-configuration)
  page maps the per-channel surface and the fallback window drip campaigns
  inherit.
* **Pass the recipient timezone when you have it** — gate resolution is
  recipient-local; for +1 numbers the NANP area code resolves the timezone,
  and an explicit hint from your CRM beats the fallback. Read the same guide
  for the `unknown_timezone_policy` choice when a timezone cannot be
  resolved.
* **Keep transactional traffic exempt** — the transactional carve-out means
  an OTP or account notice does not pause at the gate. A marketing lane
  without the carve-out never helps anyone; keep the distinction when you
  tag sends.

***

## 4. Baseline checklist — tenant-owned, not legal advice

Run this once per sending brand before go-live, then again on each new
campaign. Assign an owner to every checkbox; the sign-off means the named
owner confirmed it.

* [ ] **Opt-in captured and provable.** The opt-in moment is recorded per
  contact with the source (web form, keyword, point-of-sale). When the opt-in
  is a handshake, a
  [confirmed double opt-in](/compliance/double-opt-in) row exists for the
  `(contact, channel)` pair. *Owner: Compliance.*
* [ ] **Suppression list seeded and honoured.** Legacy opt-outs imported once;
  every send passes the suppression gate; STOP replies land on the list in
  real time. *Owner: Operations.*
* [ ] **Quiet hours enabled on the marketing lane.** The `sms` channel gate is
  on, with a recipient-local window and the transactional carve-out preserved.
  *Owner: Operations.*
* [ ] **[Pre-send policy scanner](/compliance/policy-scanner) mode chosen.**
  The organization runs `warn` (default, findings recorded) or `strict`
  (blocking verdicts reject the send); SHAFT, shortener, spam-score, and DLP
  findings are wired to your review queue. *Owner: Compliance/Engineering.*
* [ ] **10DLC campaign registered as the right use case.** Brand approved,
  campaign filed as `MARKETING` (or `MIXED` only where both lanes genuinely
  coexist), sample messages match the actual traffic, and the per-day
  throughput tier covers your volume. *Owner: Operations.*
* [ ] **Evidence retained.** Opt-in records, suppression additions, and
  DLRs are exportable for audit; retention is set per your
  [Data Retention Policy](/compliance/data-retention-policy). *Owner:
  Compliance.*

<Warning>
  Compliance posture is your organization's decision, and the go-live call is
  yours. This checklist is the baseline posture, never a substitute for legal
  review of your TCPA, CTIA, or state obligations.
</Warning>

***

## Related references

* [Assemble your tenant's compliance posture](/guides/compliance-profiles-assemble) —
  how profiles, country rules, and vertical packs compose (the assembly this
  page plugs into).
* [10DLC registration](/guides/10dlc-registration) — brand and campaign
  filing, use-case codes, throughput tiers, and the preflight linter.
* [10DLC registration wizard](/guides/10dlc-wizard) — the recommended
  save-and-resume operator flow.
* [10DLC rejections and re-vet](/guides/10dlc-rejections-and-revet) — decode
  rejection codes, re-vet the brand, read throughput classes.
* [Quiet hours: org-wide channel gates](/guides/quiet-hours-configuration) —
  the per-channel surface, fallbacks, and timezone resolution.
* [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) — the
  import endpoint and how suppression is scoped.
* [Pre-Send Policy Scanner & DLP](/compliance/policy-scanner) — verdicts,
  scan mode, and the rules each channel runs.
* [HIPAA compliance controls](/compliance/hipaa) and
  [PCI DSS posture](/compliance/pci-dss) — when a sender carries patient or
  cardholder data, this page is the layer underneath.
