Trust Centre
Last updated 24th of July 2026
This page answers the questions we're most often asked in vendor security, privacy and
technology assessments. It's written so your IT, security or procurement team can complete
their review directly from this page, alongside our
Security Statement, Privacy Policy
and Service Level Agreement. If your assessment needs something that
isn't covered here, contact us at
hello@mobilemessage.com.au.
Company and contact
- Legal entity: Mobile Message Pty Ltd, ABN 56 669 495 916, an Australian company, 100% Australian owned.
- Security and assessment contact: hello@mobilemessage.com.au. We provide support by email and live chat.
- Service: bulk and transactional SMS to Australian mobile numbers, via web application and REST API.
Certifications and compliance
- Mobile Message does not currently hold ISO 27001 certification. Our platform is hosted in Equinix data centres in Sydney which are independently certified against ISO 27001, SOC 1 and SOC 2 Type II, PCI DSS, ISO 22301 and ISO 50001.
- We are a certified participant in the ACMA SMS Sender ID Register, the Australian Government scheme that protects registered sender IDs from impersonation.
- We are a member of the Telecommunications Industry Ombudsman (TIO) scheme.
- We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). As an Australian company serving Australian businesses, the Privacy Act is our governing privacy framework.
- Card payments are processed by Stripe, a PCI DSS Level 1 certified payment provider. Card details are captured and stored by Stripe; we never store card numbers on our systems.
Data sovereignty
- Customer data is stored, processed and backed up in Sydney, Australia.
- There is no offshore storage or offshore processing of customer data.
- Messages are delivered directly to Australian carriers, with no offshore routing.
- Personnel with administrative access to production systems are Australian citizens, based in Australia.
- Customer data is never sold or shared for marketing purposes.
Encryption
- In transit: all connections to the web application and API are encrypted with TLS 1.2 or above. The API is HTTPS only.
- At rest: the database holding messages, contacts and account details is encrypted with 256-bit AES.
- Particularly sensitive fields carry an additional application-level layer of AES-256-GCM encryption.
- Passwords and API credentials are stored as one-way hashes, never in plain text.
- Backups are encrypted before they leave the database server.
Backups and disaster recovery
- Full database backups run nightly, with incremental backups every hour supporting point-in-time recovery.
- Backups are encrypted and stored in a separate storage facility in Sydney, Australia.
- Backups are retained on a rolling schedule of 7 daily, 4 weekly and 6 monthly copies, and backup integrity is verified automatically every week.
- We commit to 99.9% platform availability each calendar month under a formal, published Service Level Agreement with a claimable service credit.
- We maintain multiple connections into the Australian carrier networks, so a single connection failure doesn't stop message delivery.
- Live platform status and incident history are published at status.mobilemessage.com.au, and anyone can subscribe for automatic outage notifications.
Access management and identity
- Each person on your team gets their own login under your account. Team logins have role-based access with admin and standard user roles, and access can be revoked at any time.
- Two-factor authentication is available for account sign-in, adding a one-time verification code on top of the password.
- Single Sign-On (SAML/OIDC) is not currently offered.
- API access uses per-key credentials that can be individually labelled and revoked. API credentials are stored SHA-256 hashed.
- Account activity is logged so important actions can be traced and reviewed.
How our staff access is controlled
- Production access is limited to the small number of staff who genuinely need it, following the principle of least privilege.
- Staff access requires multi-factor authentication through a secure corporate directory with role-based permissions.
- The production environment is separated from our corporate network, protected by firewalls and private networks with strict segmentation.
Third parties and subprocessors
The following categories of third parties are involved in delivering the service:
- Australian telecommunications carriers, which deliver your messages to recipient handsets.
- Stripe, which processes card payments.
- Cloudflare, which provides DNS and network edge security in front of the platform.
- Google Workspace, which hosts our support mailbox.
- Amazon Web Services, whose Amazon SES service in the Sydney region (ap-southeast-2) delivers account emails such as receipts and notifications.
Two disclosures to Australian Government systems are required by law for SMS providers.
Sender IDs are registered in the ACMA SMS Sender ID Register, and holders of dedicated
virtual numbers have number data lodged in the Integrated Public Number Database (IPND)
as required under the Telecommunications Act. Beyond these, customer information is only
disclosed to government agencies where Australian law requires it.
Email security
Our sending domain enforces all three standard email authentication controls, which you can
validate independently with any DNS assessment tool:
- SPF with a strict hard-fail policy (
-all).
- DKIM signing on outbound mail.
- DMARC with an enforcing
p=reject policy.
Operational security and patching
- Servers run current long-term-support operating systems with regular security patching, and critical vulnerabilities are prioritised for prompt remediation.
- We run an internal security review program covering the application and infrastructure, and remediate findings on a severity-first basis.
- Security logs and platform activity are collected and monitored continuously, and delivery and services are monitored 24/7 with internal alerting.
- Our controls map to the intent of the ASD Essential Eight, including multi-factor authentication, regular patching, daily backups, application hardening and restriction of administrative privileges.
Integrations, documentation and support
- Available integrations are listed at mobilemessage.com.au/integrations, including HubSpot, Zapier, Shopify, Salesforce and more.
- Full technical documentation is published for the REST API, alongside our help centre for ongoing use and maintenance.
- Support is provided by email and live chat, mainly during business hours. Delivery and services are monitored around the clock.
Reporting a security concern
If you believe you've found a security vulnerability, or your assessment needs information
that isn't covered on this page, email
hello@mobilemessage.com.au and mark it for
our security team. We take every report seriously and will get back to you quickly.