Skip to content

Site search

Type to search Pages

Security & compliance

Disclosure, provenance and human control — built in from the start.

Dialnode treats dependence on regulated telecom carriers and consumer-protection obligations as a core design constraint, not a later addition. This page describes the boundaries and controls we operate today.

Controls

What the product enforces.

Each control below reflects a design constraint the product is built around. We describe them plainly and do not overstate them.

Disclosure by jurisdiction

Dialnode applies the disclosure a counterparty is owed in the relevant jurisdiction — that they are dealing with an AI agent. Disclosure is enforced against TCPA and FCC expectations in the US and against the EU AI Act's Article 50 duty in the EU, which commences on 2 August 2026.

Attributable, tamper-evident records

Every conversation is captured as an attributable, tamper-evident transcript and written into the operator's audit trail, so a record can be produced for a regulator, a counterparty or an internal review with attribution and integrity already in place.

Registered channels only

Outbound SMS runs only through registered brands and campaigns, so unregistered A2P 10DLC traffic is not blocked. Registration and deliverability are handled as first-class concerns rather than assumed.

Authenticated caller identity

Caller-ID authentication integrates with STIR/SHAKEN. Channels are bound to a verified agent identity, consuming agent identity and access management rather than a generic human account holder.

How human control works.

Dialnode is an AI-born venture. AI colleagues carry the operational volume; accountable humans govern, approve decisions and hold fiduciary and compliance responsibility. We do not blur that line.

What AI colleagues do

Number and channel allocation.

Continuous deliverability and sender-reputation monitoring.

Per-jurisdiction disclosure-rule application.

Transcript capture and provenance tagging.

First-line escalation routing to the right human.

AI colleagues operate against policies set by accountable humans and cannot cross defined boundaries autonomously; anything outside those boundaries is escalated to a named human.

What passes through a human approval gate

New outbound campaign launches.

Entry into a new regulated jurisdiction.

Carrier contract changes.

Accountable humans set and approve outbound campaign policies, authorise carrier onboarding, sign off on jurisdictional disclosure configurations, and handle all regulator-facing matters.

Questions

Security and compliance questions.

Do you hold security certifications or completed independent audits?

No. As an early-stage venture we do not claim any security certifications or completed independent security audits at this time. We are building towards recognised, industry-standard compliance frameworks, and we will describe our posture accurately as it matures rather than in advance of it.

What is recorded, and where does it go?

Conversations are captured as attributable, tamper-evident transcripts and written into the operator's audit trail. The provenance ledger is designed to support recording, consent and retention obligations in regulated industries.

Which disclosure rules are enforced?

Disclosure that a counterparty is dealing with an AI agent is enforced against TCPA and FCC expectations in the US and against the EU AI Act's Article 50 duty in the EU. Where a jurisdiction's rules differ, the applicable configuration is signed off by an accountable human before it is applied.

Can retention rules anchor an agent-provenance requirement in law?

We do not yet know. Whether a specific retention rule can anchor an agent-provenance requirement in law remains unverified, and we treat it as a discovery hypothesis rather than a settled claim.

Who is accountable when something goes wrong?

A named human. AI colleagues carry operational volume within defined boundaries and escalate anything outside them; accountable humans retain fiduciary and compliance responsibility and own all regulator-facing matters.

Have a security or compliance question?

Reach us through the contact form and an accountable human will respond.