Third Party Index

Snapshot 58482

Document
Security page
URL
https://workbridgesolutions.com/connectsms/security/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
65669 bytes
SHA-256 (raw)
22207451f52f5f499c9cc9c17cf6f06af17eeaa0bf4c4943775c7dd4be167290
SHA-256 (normalized text)
236ceab1e02af963f6aa11c23ff4894db54bbc176ec51ce2c58cdf8da9b07c18

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security, consent and reliability
Careful with customer messages, at every step.
ConnectSMS runs inside your Salesforce org and talks only to your Twilio account. Here is how it protects that connection, respects opt-outs, and avoids losing or duplicating customer messages.
Start your 14-day free trial on AgentExchange (opens in a new tab) Talk to us
No credit card required
Listed on Salesforce AgentExchange
Then $120 per user per year
Runs on your own Twilio account
Is ConnectSMS secure? ConnectSMS checks Twilio's signature on every webhook call, verifies your Twilio credentials before saving them and never shows the Auth Token again. Messages are private and shared only through access to each business number, opt-outs are always enforced, and a message with an unclear outcome is checked with Twilio rather than sent twice.
Security
Your Twilio connection, locked down.
ConnectSMS is built on the Salesforce Platform, and Salesforce connects directly to your Twilio account with no ConnectSMS servers in between. These controls protect that connection and the messages that travel over it.
Twilio signature verification
Every webhook call is checked against Twilio's signature for the exact address and parameters. In Enforce mode, the default, unsigned or forged requests are rejected, and sending can't be turned on without it.
Twilio account validation
Credentials are verified with Twilio before they're saved, and webhook requests must match the Account SID of your saved connection.
Auth Token never shown or logged
The Auth Token lives in a protected setting only ConnectSMS can read. Your Twilio Auth Token is never shown in the browser or written to logs.
Restricted guest-user access
The Site guest user gets ConnectSMS Webhook Guest, which grants the webhook Apex class and nothing else. It gives no access to your records.
Private messages and conversations
Messages and conversations are private. People read them only through View or Send access to the business number.
Audit log
Configuration, access and consent changes are recorded in an audit log, with who made each change and when.
Sandbox sending guard
In a sandbox copied from an org where sending is on, sending turns off automatically until an admin turns it on in that sandbox.
Only Twilio endpoints
The only outside service ConnectSMS calls is Twilio's API. No ConnectSMS server stores or relays your messages.
One switch for sending
Admins can turn off sending for the whole org at once. A reason is required and recorded in the audit log.
Signature check: three modes, one safe default
Default
Enforce (recommended)
ConnectSMS rejects every request that does not carry a valid Twilio signature. Sending can only be turned on in this mode.
Short-term
Monitor (troubleshooting only)
Requests with a missing or wrong signature are accepted but recorded. Use it briefly while fixing a signature problem, then switch back.
Never in production
Off (development orgs only)
No signature check at all. Never use Off in production or in a sandbox that holds real customer data.
Good practice for your Twilio account
Use a dedicated Twilio subaccount for each Salesforce production org, and a test account or separate subaccount in sandboxes
Turn on Messaging Geographic Permissions for only the countries you serve, and SMS Pumping Protection, in Twilio
Protect the Twilio Console with two-factor authentication, and rotate the Auth Token if it may have been exposed
Keep signature checking on Enforce, and give the Site guest user only ConnectSMS Webhook Guest
Don't give integration or agent users ConnectSMS Campaign Manager or ConnectSMS Admin
Set a daily safeguard that matches your real sending volume
Consent
Messaging controls designed to help teams enforce their configured communication policies.
Opt-outs are recorded from the customer's own reply, enforced on every path and checked again at the moment of sending.
Opt-outs that always apply
A reply that is exactly one of Twilio's standard opt-out keywords records an opt-out
START, YES or UNSTOP opts the customer back in on the number they texted
Opt-outs reported by Twilio are honored too, including Twilio error 21610
Opt-outs are always enforced. There is no switch to turn them off
Checked when a message is requested and again when it's sent, for texts, replies, outreach and automation
Users see it: the composer won't send and the inbox shows Opted out
Admins choose the scope: block every business number from that phone, or only the number that got the STOP
Quiet hours can delay outreach and automation messages overnight
Guide to SMS opt-outs in Salesforce
Opt-out keywords
STOP
STOPALL
UNSUBSCRIBE
CANCEL
END
QUIT
REVOKE
OPTOUT
Opt back in
START
YES
UNSTOP
Recognized when the whole reply is the keyword, in any letter case. HELP and INFO are answered by Twilio, not ConnectSMS.
Manual opt-outs, with a documented reason.
When someone asks to stop by phone, email or in person, an admin adds the opt-out in ConnectSMS Setup and it applies at once, including to queued and scheduled messages.
Removing an opt-out needs a note on how and when the person agreed to receive messages again
The admin must also confirm that the consent is documented
Every change, with its note, is recorded in the audit log
Search opt-outs by phone number, and filter by status, business number, source and date
Remove the opt-out for +1 (212) 555-0147?
Only remove an opt-out when this person has asked to receive messages again, for example by texting START, and you can show that consent. Other opt-outs for the same phone number still apply.
*How and when did they agree to receive messages again? Called the service desk on Oct 12 and asked for appointment reminders again. Confirmed by email the same day.
I confirm this person's consent to receive messages again is documented.
CancelRemove opt-out
Recreated from the ConnectSMS interface with sample data.
What ConnectSMS doesn't do
It doesn't make your messaging legally compliant or give legal advice. The rules depend on your business, your messages and where your customers are.
It doesn't collect or decide consent for you. You own consent: who agreed to receive texts, for what, and how you show it.
It doesn't interpret free-text requests such as please stop texting me. Only a reply that is exactly a keyword is recognized, so add a manual opt-out when someone asks another way.
It doesn't cap spending by default. The daily safeguard is optional and off until an admin sets it.
Reliability
Built to avoid guessing with customer messages.
Every message is written to Salesforce before ConnectSMS calls Twilio. If Twilio's answer is lost, the message is marked Unknown and checked with Twilio, never blindly sent again.
Sending means Twilio accepted the message. Sent means it was handed to the carrier, and Delivered means the carrier confirmed it.
Normal path
Queued
Sending
Sent
Delivered
If Twilio's answer is lost
Timeout or server error
Unknown
ConnectSMS checks with Twilio
Matching status, or Failed if Twilio never got it
Recorded before calling Twilio
Each message is saved in Salesforce first, so a lost connection can't lose the message or its history.
Unknown, then checked with Twilio
A timeout, connection error or Twilio server error marks the message Unknown. ConnectSMS asks Twilio what happened and records the matching status, or Failed if Twilio never got it.
Queued dispatch
Messages sent now go to a background job right away. Scheduled messages, outreach and anything still waiting are picked up by the dispatcher every 15 minutes.
Duplicate-send protection
Idempotency keys let Flow, Apex and API callers repeat a request without sending the message twice, and the composer ignores double clicks.
Rate-limit back-off
If Twilio answers 429 Too Many Requests, the message goes back to Queued and is tried again after a pause.
Stuck-message detection
A message still waiting on Twilio's answer after 10 minutes is marked Unknown and checked with Twilio.
Retry linked to the original
Failed and Undelivered messages can be retried deliberately as a new message linked to the first, so the history shows both.
Failures in plain language
Each failure says what went wrong and what to do next, with the Twilio error code.
Checked again at send time
Before a queued or scheduled message goes out, ConnectSMS re-checks the sending switch, permissions, number access and opt-outs.
Every message status, and what it means
Status	What it means
Scheduled	Waiting for its scheduled time; permissions and consent are checked again before sending
Queued	Saved and waiting to be handed to Twilio
Sending	Twilio accepted it and is sending it to the carrier
Sent	Handed to the carrier; delivery not yet confirmed
Delivered	The carrier confirmed delivery; this does not mean it was read
Read	Reported read by the recipient's app
Undelivered	The carrier couldn't deliver it
Failed	It couldn't be sent
Blocked	A ConnectSMS rule blocked it
Canceled	Canceled before it was sent
Unknown	ConnectSMS couldn't confirm whether Twilio accepted it; it is being checked and won't be resent automatically
Received	Received from the customer
Permissions
Access by role, and by business number.
Two things decide what someone can do: a ConnectSMS permission set, and access to specific business numbers.
ConnectSMS User
Everyday texting, the inbox and templates, on the business numbers an admin has granted.
ConnectSMS Campaign Manager
Creates, reviews, launches, pauses and cancels outreach, and manages shared templates. Combine with ConnectSMS User to text one-to-one.
ConnectSMS Admin
Twilio connection, business numbers, access, policies, opt-outs and operations.
ConnectSMS Automation
For integration users, agent users and people who run Flow or API messaging from numbers made available to automation.
What each permission set includes
Permission set	Custom permissions
ConnectSMS User	ConnectSMS: Send Messages
ConnectSMS Campaign Manager	ConnectSMS: Manage Outreach
ConnectSMS: Manage Templates
ConnectSMS: Send from Automation Numbers
ConnectSMS Automation	ConnectSMS: Send from Automation Numbers
ConnectSMS Admin	All five, including ConnectSMS: Administer
How number access works
Admins grant Send or View access per business number, to people or public groups. Send includes View
Replies always come from the number the customer texted; people without Send access to it can read but not reply
Admins see every conversation, including texts to Twilio numbers not set up in ConnectSMS
Permissions and number access are checked again at send time, so removed access blocks queued messages too
ConnectSMS Webhook Guest is only for the Site guest user. It isn't a role for people
Manage access in ConnectSMS Setup
FAQ
Security and consent: common questions
How are SMS opt-outs handled?
When a customer replies with one of Twilio's standard opt-out keywords, such as STOP, UNSUBSCRIBE or CANCEL, ConnectSMS records the opt-out and stops texting that number; START, YES or UNSTOP opts them back in. Opt-outs are always enforced, checked when a message is requested and again when it is sent, and shown to users in the composer and inbox.
Consent and opt-outs
Does ConnectSMS make my text messaging compliant?
No software can do that on its own. ConnectSMS gives you controls that help your team apply the policies you choose, including opt-out enforcement, quiet hours for outreach and automation, number-level access and an audit log. You remain responsible for consent and for the rules that apply to your messages.
How does ConnectSMS know a webhook call really came from Twilio?
Twilio signs every request it sends. ConnectSMS checks that signature against the exact webhook address and parameters using your Auth Token, and checks that the request names your Twilio account. In Enforce mode, which is required before sending can be turned on, any request that fails is rejected.
What happens if Twilio doesn't answer when a message is sent?
The message is marked Unknown instead of being sent again. ConnectSMS asks Twilio whether it received the message: if it did, the real status is recorded; if not, the message becomes Failed and someone can retry it deliberately. Admins can also choose Check with Twilio in Operations.
Can a Salesforce sandbox send real text messages by accident?
When a sandbox is copied from an org where sending is on, ConnectSMS turns sending off in the sandbox automatically. An admin has to review the Twilio settings and turn sending on there. We recommend a Twilio test account or a separate subaccount for sandboxes.
Keep exploring
Administration
Policies, opt-outs, the sending switch and the audit log in ConnectSMS Setup.
Twilio integration
How the connection, numbers and signed webhook fit together.
SMS opt-outs guide
How STOP and START work with Twilio and Salesforce.
Try it now: every feature, free for 14 days
Put every customer text where your team already works.
Install ConnectSMS from AgentExchange, connect your Twilio account and give your team the numbers they should text from.
Start your 14-day free trial on AgentExchange (opens in a new tab) Talk to us
No credit card required
Listed on Salesforce AgentExchange
Then $120 per user per year
Runs on your own Twilio account
ConnectSMS is published by WorkBridge Solutions. Twilio bills your Twilio account directly for messaging, including during the trial.