Security That's Built Into the Platform, Not Bolted On

An enterprise security review usually asks the same questions regardless of channel: who can connect, how are credentials protected, and what happens to bad or malicious input. Here is exactly what SMPPCenter's SMS, WhatsApp, RCS, and AI agent messaging platform does on each of those fronts, grounded in the actual controls built into the product, not a generic security checklist.

Access Controls at Every Entry Point

Entry Point Control
Bulk file exchange IP allowlist on Bulk SMS & RCS via SFTP, only authorized systems can connect
Website widget Domain allowlist on the Website Chat Widget, it simply won't load on an unlisted domain
AI model credentials BYOK API keys for OpenAI, Anthropic, Azure OpenAI, or Gemini encrypted at rest, not stored as plain text
Underlying infrastructure Governed by your own security policy when deployed on-premise or in a private cloud account you control

Protection Against Bad and Malicious Input

Bot & Scam Detection

  • Bot-traffic detection and scam-content pattern blocking on the Website Chat Widget.
  • Per-minute rate limiting to control abuse.

PII Controls on AI

  • AI Agent Builder supports PII redaction and topic guardrails per bot.
  • Limit what personal data an AI agent processes or retains during a conversation.

Validated Before It's Acted On

  • Bulk files validated for recipient format, DLT template match, credits, and structure.
  • Anything that fails is rejected and reported back, not partially processed.

Infrastructure You Control

Running a security review?

Tell us what your review needs to cover, and we will walk through the specific controls in detail.

Talk to a Specialist

FAQ

Frequently Asked Questions

Bulk file exchange through Bulk SMS & RCS via SFTP is locked to an allowlist of IP addresses, so only systems you authorize can connect. The Website Chat Widget is similarly locked to a domain allowlist, and simply won't load anywhere else.

If you bring your own API key for OpenAI, Anthropic, Azure OpenAI, or Gemini in AI Agent Builder, that credential is encrypted at rest, not stored as plain text.

Yes. The Website Chat Widget includes bot-traffic detection and scam-content pattern blocking, alongside per-minute rate limiting to control abuse.

AI Agent Builder supports PII redaction and topic guardrails per bot, so you can limit what personal data an AI agent processes or retains during a conversation.

Every file dropped for bulk messaging is validated for recipient number format, DLT template match, sufficient credits, and overall file structure before anything is queued. Anything that fails is rejected and reported back rather than processed.

Yes. Running the platform fully on-premise or in a private cloud account you control means access to the underlying infrastructure is governed by your own security policy, not a shared vendor environment. See On-Premise Messaging Software and Private Cloud Deployment.

Ready to talk through your security requirements?

Talk to a Specialist

LET US WALK THROUGH OUR SECURITY CONTROLS

Tell us about your security review requirements, and we will walk through the access controls, encryption, and validation built into the platform.

TALK TO A SPECIALIST
Contact us