Voice & Messaging Compliance

Abstract geometric shield representing verification and trust

Calls that are not authenticated get labeled as spam. Texts that are not registered get filtered. Compliance is no longer paperwork — it is whether your communications arrive at all.

RunCentral handles the registration and authentication work behind your voice and messaging services, so your calls are answered and your messages are delivered.


STIR/SHAKEN — caller ID authentication

STIR/SHAKEN is the industry framework for cryptographically signing calls so the receiving carrier can verify the caller ID was not spoofed. It exists because illegal spoofing made people stop answering the phone.

When your provider signs a call, it assigns an attestation level:

  • Full attestation (A) — the provider knows the customer and confirms they have the right to use that number
  • Partial attestation (B) — the provider knows the customer but cannot confirm the number
  • Gateway attestation (C) — the provider passed the call on but cannot vouch for its origin

Calls carrying low attestation are far more likely to be flagged “Spam Likely” or blocked. Because we provision your numbers on our own network, your outbound calls are signed with full attestation.


10DLC — registered business texting

10DLC (10-digit long code) is how application-to-person text messaging is legitimately sent over standard local business numbers in the US. Carriers require that both your business and your messaging use cases be registered before traffic is accepted.

Registration is not just a formality. Carriers assign a trust score that directly determines:

  • How many messages per second you are permitted to send
  • Your daily message volume ceiling
  • How aggressively carriers filter your traffic

Unregistered traffic is increasingly blocked outright, and can carry per-message carrier surcharges. Registering properly is the difference between messages landing and messages disappearing.


TCR — The Campaign Registry

TCR is the central registry the US carriers use to verify 10DLC traffic. Two things get registered:

  • Your brand — verified business identity, including legal name, EIN and contact details. Accurate details here materially improve your trust score
  • Your campaigns — each messaging use case, such as customer care, appointment reminders, account notifications or two-factor authentication, with sample message content and opt-in details

We complete brand and campaign registration on your behalf and manage it as your use cases change.


Consent and opt-out

Registration gets your messages through the carriers. Consent keeps you on the right side of the TCPA. The rules are not complicated, but they are not optional:

  • Obtain and record clear opt-in before messaging a recipient
  • State who you are and what the messages will cover
  • Honor STOP, UNSUBSCRIBE and similar opt-out keywords immediately and automatically
  • Respond to HELP with contact information
  • Keep records of consent

These behaviors are built into the messaging platform we deploy — see Omnichannel Messaging.

Talk to us

Not sure whether your current messaging is registered, or why your calls are showing as spam? We will audit what you have and tell you plainly where you stand.