> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Navigating the Settings → Compliance Hub

> The Compliance Hub at Settings → Compliance organizes ~30 controls into eight task-group tabs. This guide maps each tab to the sections and deep links it owns, explains how URL hashes resolve to the right tab, and covers the unsaved-edit safety that keeps draft settings across tab switches.

# Navigating the Settings → Compliance Hub

The **Compliance Hub** at **Settings → Compliance** is the single
dashboard surface for every tenant-owned compliance control. It is a
persistent **tab strip**, not one long scroll: the \~30 controls are
grouped into eight task tabs, and only the active task group is on
screen at a time. The active tab is the "where am I" cue; the first tab
is the status overview.

The eight tabs, in order:

1. **Overview** — aggregate compliance health and profile status
2. **Consent & Preferences** — opt-in, consent ledger, preference center
3. **Privacy & Data Rights** — AI disclosure, inbox AI privacy, data residency
4. **Retention** — retention policy and data retention
5. **Audit & Evidence** — AI turn audit, audit export, SIEM streaming
6. **Messaging Compliance** — 10DLC, toll-free verification, brand identity, DNC, RND, fraud, emergency stop
7. **Security & Verification** — verify configuration, customer-managed keys
8. **Legal Policies** — HIPAA, DPA, subprocessors, legal hold

Each tab owns a fixed set of control sections, and each section keeps a
stable anchor id (`#ten-dlc`, `#hipaa`, `#brand-identity`,
`#data-retention`, and so on). Deep links from other surfaces — the
Numbers console, send dialogs, sibling compliance panels — resolve
to whichever tab owns the anchor, open that tab, and scroll the control
into view.

<Warning>
  This page describes Orbit's platform controls. It is **not legal
  advice.** Which obligations apply to your traffic depends on where you
  and your recipients are and what you send. The controls are
  tenant-owned: Orbit enforces what you configure, and the compliance
  posture decisions stay yours. Confirm your posture with qualified
  counsel before the first send.
</Warning>

***

## Tab-by-tab map

Each tab owns the section anchors below. Open the tab to work the
controls it contains; follow the linked page for the deep read on any
one control.

| Tab | Section anchors it owns | Controls embedded there | Deep reading |
| - | - | - | - |
| **Overview** | `#compliance-health` | Aggregate compliance health panel; compliance profile status | [Compliance health](/compliance/compliance-health), [Posture overview](/compliance/posture-overview) |
| **Consent & Preferences** | `#sms-double-opt-in`, `#consent-ledger`, `#consent-managers`, `#unknown-consent-policy`, `#consent-default-policy`, `#public-consent-form`, `#preference-center` | SMS double opt-in, consent ledger, consent managers, unknown-consent policy, consent default policy, public consent form, preference center | [Consent management](/compliance/consent-management), [Double opt-in](/compliance/double-opt-in), [Opt-out & suppression](/compliance/opt-out-suppression), [Preference center opt-out page](/guides/preference-center-opt-out-page) |
| **Privacy & Data Rights** | `#ai-disclosure`, `#inbox-ai-privacy`, `#data-residency` | AI disclosure, inbox AI privacy, data residency | [AI disclosure settings](/compliance/ai-disclosure-settings), [AI disclosure setup](/guides/ai-disclosure-setup), [Data residency overview](/compliance/data-residency-overview) |
| **Retention** | `#retention`, `#data-retention` | Retention policy, data retention panel | [Data retention policy](/compliance/data-retention-policy), [Settings data retention](/guides/settings-data-retention) |
| **Audit & Evidence** | `#ai-turn-audit`, `#audit-export`, `#siem-streaming` | AI turn audit, audit export, SIEM streaming | [Audit ledger posture rollup](/compliance/audit-ledger-posture-rollup), [Audit log](/guides/audit-log), [Audit log export](/guides/audit-log-export), [Evidence binder](/compliance/evidence-binder) |
| **Messaging Compliance** | `#brand-identity`, `#impersonation-monitor`, `#emergency-stop`, `#ten-dlc`, `#tfv`, `#rnd-scrub`, `#dnc-preflight`, `#dnc-scrub`, `#policy-scan-mode`, `#country-allowlist`, `#inbound-country-gate`, `#effective-send-rate`, `#fraud-caps`, `#voice-destination-blocks`, `#voice-fraud-analytics`, `#channel-rate-overrides` | Brand identity, impersonation monitor, emergency stop, 10DLC registration, toll-free verification, RND scrub, DNC preflight, DNC scrub, policy scan mode, country allowlist, inbound country gate, effective send rate, fraud caps, voice destination blocks, voice fraud analytics, channel rate overrides | [10DLC registration](/guides/10dlc-registration), [10DLC wizard](/guides/10dlc-wizard), [10DLC brand & campaign profiles](/compliance/10dlc-brand-campaign-profiles), [STIR/SHAKEN posture guide](/compliance/stir-shaken-posture-guide), [Branded calling](/compliance/branded-calling), [Emergency stop](/guides/compliance-emergency-stop), [Fraud Shield](/guides/compliance-fraud-shield), [RMD robocall mitigation](/guides/compliance-rmd-robocall-mitigation) |
| **Security & Verification** | `#verify-config` | Verify configuration, customer-managed keys (BYOK) | [Verify overview](/verify/overview), [Verify console](/guides/verify-console), [Customer-managed keys](/compliance/byok-customer-managed-keys), [BYOK keys guide](/guides/compliance-byok-keys) |
| **Legal Policies** | `#hipaa`, `#dpa`, `#subprocessors` | HIPAA, Data Processing Agreement, subprocessor registry, legal hold | [HIPAA](/compliance/hipaa), [BAA](/compliance/baa), [Data processing agreement](/compliance/data-processing-agreement), [Subprocessor registry](/compliance/subprocessor-registry), [Legal hold](/guides/compliance-legal-hold) |

A tab appears only when it has at least one control your role can see;
a role-restricted control is hidden rather than shown as a dead link.

***

## Deep links and URL hashes

The hub resolves three kinds of URL hash to the tab that owns it:

* **A group key** — the tab token itself. `#consent` opens the
  Consent & Preferences tab; `#legal` opens Legal Policies. Switching
  tabs reflects the active group back into the URL the same way, so the
  address bar always names the tab you are on and a link is shareable.
* **A section id** — the `compliance-section-*` form the page
  stamps on each group. `#compliance-section-privacy` opens the Privacy
  & Data Rights tab.
* **A control anchor** — the historical id a specific control
  keeps. `#ten-dlc` opens Messaging Compliance and scrolls to 10DLC
  registration; `#hipaa` opens Legal Policies and scrolls to the HIPAA
  section; `#brand-identity` and `#data-retention` resolve the same way.

Historical anchors keep working because each control keeps its original
DOM id regardless of which tab it lives behind. A link that worked
before the tab redesign — from the Numbers console, a send dialog,
or a sibling compliance panel — still lands on the same control;
the hub just opens the owning tab first, then scrolls. You do not need
to update existing links.

***

## Unsaved-changes safety across tabs

Switching tabs does not discard an unsaved draft. Once you open a tab,
its controls stay mounted in the background; when you switch away and
back, the form state is still there. This matters for the controls you
edit in passes — a half-filled HIPAA section, a retention window
you are still tuning, an AI disclosure draft — because an in-app
tab switch does not trigger a page unload, so a "leave page?" guard
would never fire for it.

The pattern is **once-opened, stays mounted**: a tab you have visited
at least once keeps its subtree in the DOM (hidden, not unmounted) so
its local state survives. Tabs you have not yet opened mount lazily on
first visit, so the page does not pay the render cost for every control
up front.

<Note>
  Save before you leave the page or close the browser tab. The
  unsaved-edit safety covers tab switches inside the hub; navigating
  away from the page still unloads it.
</Note>

***

## Recommended first-run pass

A new tenant configures the hub top to bottom once. Work the tabs in
this order; each later step reads the surfaces the earlier ones
populate.

1. **Start with the posture map.** Read
   [Configure your tenant's compliance posture before the first send](/compliance/tenant-posture-first-run)
   for the send-time gate sequence — consent baseline, opt-out,
   quiet hours, DNC and RND pre-flight, country rules, and the
   emergency kill switch — in the order you configure them.
2. **Build the compliance profile.** Walk the
   [compliance profile wizard](/guides/compliance-profile-wizard) to
   create the country-specific packet behind regulated numbers and
   senders, then attach it to the gated surface.
3. **Finish organization KYC.** Complete
   [organization KYC/KYB/IDV onboarding](/guides/organization-kyc-onboarding)
   so live traffic is approved; the hub's Messaging Compliance tab
   surfaces the registration controls KYC unlocks.
4. **Work the hub tabs in order.** Overview first (status), then
   Consent & Preferences, Privacy & Data Rights, Retention, Audit &
   Evidence, Messaging Compliance, Security & Verification, and Legal
   Policies. Each tab above links to the deep page for the control you
   are configuring.

Revisit the Overview tab after any change — the health panel
reflects the posture the rest of the hub produces.

***

## Related references

* [Compliance posture overview](/compliance/posture-overview) — the
  one-page concept map of every tenant-toggleable control, the
  out-of-box defaults, and what the platform does not let you toggle.
* [Configure your tenant's compliance posture before the first send](/compliance/tenant-posture-first-run)
  — the day-one runbook across the send-time gates, in
  configuration order with every default stated.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.