Security Statement

Last updated 15th of June 2026

When you send through Mobile Message, you're trusting us with your data and your customers' personal information. We don't take that lightly. This page explains, in plain language, how we keep that information safe — where it's stored, how it's protected, and who can get to it.

Stored in Australia

Your messages and contacts live on servers in Sydney, in independently certified data centres.

Encrypted at rest

Everything we store is encrypted with 256-bit AES, so the data on disk is unreadable without the keys.

Encrypted in transit

Every connection is protected with TLS — the same encryption that secures online banking.

99.9% uptime

We back the platform with a 99.9% monthly uptime commitment, in writing — see our SLA.

Two-factor login

Add a second step to your login so only you can get into your account.

Independently certified

Our data centres hold ISO 27001, SOC 2 Type II and PCI DSS certifications.

Where your data is stored

Mobile Message's platform is hosted in Equinix data centres in Sydney, Australia — so your data stays onshore. Equinix is one of the most trusted names in data-centre infrastructure, and its facilities are independently audited against a long list of international standards, including ISO 27001 (information security), SOC 1 and SOC 2 Type II, PCI DSS (payment card security), ISO 22301 (business continuity) and ISO 50001. That gives us — and you — a strong, externally verified foundation to build on.

Encryption

We protect your data with strong encryption at every stage — both while it's moving and while it's stored.

While it's stored (encryption at rest)

The database that holds your messages, contacts and account details is encrypted at rest using 256-bit AES — the same encryption standard trusted by banks and governments. In practice, this means that even if someone managed to get hold of the underlying storage, the data would be unreadable without our encryption keys. Particularly sensitive details are given an additional, separate layer of AES-256-GCM encryption on top, so they stay protected even inside our own systems.

While it's moving (encryption in transit)

Every connection between you and Mobile Message — whether you're using the web app or our API — is encrypted using TLS 1.2 or above. This is the same proven technology that secures online banking, and it protects your data from being intercepted or tampered with as it travels across the internet.

Keeping your account secure

  • Individual accounts: Everyone on your team gets their own login, so you stay in control of who has access — and can remove it the moment someone leaves.
  • Two-factor authentication: Turn on 2FA to add a second step to your login, so a password alone isn't enough for someone to get into your account.
  • Protected passwords: Passwords are stored using one-way hashing and are never kept in plain text — not even we can read them.
  • Activity logging: Account activity is logged, so important actions can be traced and reviewed if a question ever comes up.

How our staff access is controlled

Access to our production systems is limited to the small number of staff who genuinely need it. Our team uses a secure corporate directory with role-based permissions and mandatory multi-factor authentication, and we follow the principle of least privilege — people get the minimum access required to do their job, and nothing more.

Network and infrastructure protection

Our production environment is kept separate from our corporate network, protected by firewalls and private networks (VPNs), with strict network segmentation. Only the essential services are allowed to talk to each other, which keeps the number of ways the system can be reached to a minimum.

Monitoring and response

We continuously collect and monitor security logs and activity across our platform, in line with industry best practice. That means unusual behaviour can be spotted and investigated quickly, before it becomes a problem.

Reliability you can count on

  • 99.9% uptime commitment: We guarantee at least 99.9% platform availability every calendar month, backed by our Service Level Agreement.
  • Redundant carrier connections: We maintain multiple connections into the major telecommunications networks, so if one connection has trouble, your messages keep moving.
  • Built to scale: The platform scales automatically to handle everything from a handful of messages to high-volume campaigns, with high-priority messages delivered promptly even during busy periods.
  • Live status page: You can check current availability and any planned maintenance any time at our status page.

Privacy and compliance

Security and privacy go hand in hand. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth) — you can read the detail in our Privacy Policy. As an Australian messaging provider, we also operate under the Spam Act 2003 and work closely with the Australian Communications and Media Authority (ACMA); our Anti-Spam Policy explains what that means for the messages you send.

Reporting a security concern

If you believe you've found a security vulnerability, or you simply have a question about how we protect your data, we want to hear from you. Email hello@mobilemessage.com.au and mark it for our security team — we take every report seriously and will get back to you quickly.