Skip to content
Anthony Oliva
Create account

Security

How we protect message data

Message content and recipient phone numbers are among the most sensitive data a business hands to a vendor. These are the controls we apply, stated plainly enough that you can check them against your own questionnaire.

Data in transit

  • TLS 1.2 or higher on every API request, plain HTTP is refused rather than redirected
  • Webhook deliveries signed with HMAC-SHA256 and a per-endpoint secret
  • HSTS on all web properties

Data at rest

  • Encryption at rest for production databases and backups
  • Message content retained 30 days by default, configurable down to zero retention
  • Backups encrypted and lifecycle-expired on a fixed schedule

Access control

  • Role-based access with least privilege, reviewed quarterly
  • Mandatory multi-factor authentication for all administrative and production access
  • Production access limited to named personnel and logged
  • Scoped API keys that can be rotated or revoked in under five seconds

Monitoring

  • Centralized logging with twelve months of audit retention
  • Alerting on authentication anomalies and abnormal traffic patterns
  • Automated content screening for prohibited categories and fraud signals

Operational

  • Documented incident response procedure, tested annually
  • Backup restoration tested annually
  • Vulnerability management with regular dependency and infrastructure patching
  • Written security due diligence and a data processing agreement with every sub-processor

Security questionnaires

Send yours to legal@anthonyoliva.com. We complete standard questionnaires and can execute a data processing addendum, an NDA, or a security addendum as part of onboarding.

Reporting a vulnerability

If you believe you have found a security issue, email legal@anthonyoliva.com with the subject line "Security". Include the steps to reproduce, the impact you believe it has, and anything we need to verify it.

We acknowledge reports within one business day and will keep you updated while we investigate. We will not pursue legal action against anyone who reports in good faith, tests only against their own account, avoids privacy violations and service degradation, and gives us reasonable time to fix the issue before disclosing it.

Please do not run automated scanners against production, attempt denial of service, or access data belonging to another customer.

Breach notification

If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 48 hours, with the nature of the breach, the categories and approximate volume affected, the likely consequences, and the steps we are taking. Where full detail is not immediately available we provide it in stages rather than delaying the first notice.

The full commitment is in our Data Processing Addendum, and the sub-processors that touch customer data are listed on ourSub-Processors page.

Talk to someone who has read the carrier rules

Tell us what you are sending, to whom, and how they consented. We will tell you honestly whether it will get approved, and what to change if it will not.

+1 (332) 231-6423·sales@anthonyoliva.com

ANTHONY OLIVA, INC. — 6724 Thompson Road, Syracuse, NY 13211, United States