Every texting opt-in your customers collect, kept as proof you can hand over.
For platforms that register 10DLC and toll-free campaigns for many businesses. Your platform tells us each signup, YES and STOP as they happen. We keep them, unchangeable, with the exact wording the person saw. So when you are asked to prove a person agreed, by your messaging provider, a reviewer or a lawyer, you can answer for one subscriber in seconds.
The problem you already have
- Your customers' opt-in proof has to show your customer, not your platform. Twilio's error 30506 page lists, as a cause of a rejected toll-free verification, opt-in examples that “Display the ISV's branding instead of the end business”. Until the number is verified, “Messaging traffic on this Toll-Free number is blocked”, so a customer's launch waits.
- You can be asked to prove a person agreed. Twilio's messaging policy says “you must provide proof of a recipient's consent and the date and the method through which that consent was obtained.” That is a question about one person: their signup, their confirmation and the words they were shown, all timed. If that history is scattered across logs, someone has to put it together by hand, and if the logs are gone there is nothing to send. Three stories walk through being asked: your texting provider asks, one customer's texts draw complaints, and what being asked looks like, and why it happens.
- The obligation sits with you. The same policy says a platform “must require those End Users and customers to obtain prior express written consent from any downstream users”, and Twilio's acceptable use policy says “Customer is responsible for its End Users' compliance with this AUP”.
What it does today
- A consent record for every person, per customer. Signup, YES confirmation and STOP, each with its time, its source and the exact terms wording. Consent records are append-only: nobody can edit or delete an entry, including us. Erasing a person is a separate, recorded act.
- Evidence for one person, on demand. One API call or one click exports one subscriber's consent record as an evidence packet you can send to whoever asked. See a sample evidence packet.
- STOP kept beside consent, never over it. A later STOP does not erase the consent before it. Both stay on record, in order.
- An API built for engineers. REST, idempotent writes, self-serve keys and a published reference you can run as written. A web console sits on top, and it shows nothing the API cannot.
- A public page for your platform. It names your business and the sites you have verified, for anyone who asks who you are.
Coming next NOT LIVE YET
A public opt-in page per customer, in the customer's own brand. Their form or keyword flow and the exact disclosure wording, with every past version kept: served on the customer's own domain, because Twilio's error 30927 page says the website in opt-in evidence must be the “Same domain or a page clearly owned by the registered brand”. Pilot platforms get it first and help shape it.
Running your own texting program, not a platform? Your own opt-in page is live now: $49 a month.
What it can and can't do
It shows what your platform told us, and when, for signups recorded from the day you start. It can't rebuild what was never recorded, it doesn't see your sign-up form, it never sends messages, and it doesn't record an IP address. It isn't legal advice. And nobody can promise a provider will accept an answer.
Beside your provider's consent switch
Twilio's Consent Management API “lets you bulk manage user consent preferences globally across your messaging channels”, with “details about how and when consent was collected”. It is where a person's current status lives, across RCS, SMS and MMS. Its page describes a repeat entry this way: “If a consent already exists, it will be updated (via upsert) to match the requested object.”
The two work together. Beside it, Redoubt Vault keeps every entry in a person's history, not only the latest, along with the wording each person saw and a packet for one person.
A hosted opt-in form can show the form itself, which we can't. What we hold that a form alone does not: one record across every customer, append-only, through an API. Use more than one where that fits.
The pilot
Five platforms. 90 days. $1,500, credited in full against a first year. You integrate the API for your customers' signup, YES and STOP. We build the per-customer opt-in page with you. At the end, you decide whether to continue.
Want to talk first? Write to Rodney.
What this is based on
Last checked against the sources below: 6 October 2026. Redoubt Vault is not affiliated with Twilio.
- Twilio error 30506: a cause of a rejected toll-free verification is opt-in examples that “Display the ISV's branding instead of the end business”, and “Messaging traffic on this Toll-Free number is blocked until it's verified.”
- Twilio's messaging policy: “you must provide proof of a recipient's consent and the date and the method through which that consent was obtained”, and a platform “must require those End Users and customers to obtain prior express written consent from any downstream users”.
- Twilio's acceptable use policy: “Customer is responsible for its End Users' compliance with this AUP”.
- Twilio's Consent Management API: it “lets you bulk manage user consent preferences globally across your messaging channels”, “along with details about how and when consent was collected”, and “If a consent already exists, it will be updated (via upsert) to match the requested object.”
- Twilio error 30927: the website in opt-in evidence must be the “Same domain or a page clearly owned by the registered brand”.
Who's behind it
Redoubt Vault is built by Rodney Palmer, who reads and answers every message himself. Rodney on LinkedIn.