Data Security for Enterprises
Data Security
We take the privacy and security of your data seriously at SMS Gateway Center. This page describes, specifically and verifiably, how we handle encryption, credentials, data retention, regulatory compliance, and platform availability, rather than general assurances.

Encryption in Transit
All traffic to our website and platform is served over HTTPS. Sensitive form submissions, including contact and lead forms, are transmitted over this encrypted connection rather than in plain text.
Credential & Secrets Management
Database, email, and third-party API credentials used by our platform are stored outside the public web root, in files our web server never serves directly, and each credential has a single source of truth rather than being duplicated across multiple files. This reduces the chance of a credential being exposed through a misconfiguration or an old, forgotten copy.
Administrative Access
Backend and administrative systems require authentication before any account or campaign data can be accessed, and are not reachable without valid login credentials.
Data Retention
We retain different categories of data for different periods, based on operational necessity and legal requirements, and delete data once its retention period has passed:
| Data Category | Description | Retention Period | Deletion Method |
|---|---|---|---|
| Application Logs | System, security, audit, and operational logs | 7 Days | Automatically deleted by log management process |
| Message Logs | Application message history and communication logs | 1 Year | Automatically purged from production databases |
| Billing Summary | Billing records, invoices, and payment summaries | 3 Years | Secure deletion after retention period unless required by law |
DLT & TRAI Regulatory Compliance
As an SMS provider operating in India, we support and require DLT entity, header, and template registration for all commercial messaging sent through our platform, and enforce TRAI's sending-time and consent rules, including honoring the National Customer Preference Register (NCPR/DND).
Third-Party Security Testing
Our core messaging platform (unify.smsgateway.center) has undergone third-party Vulnerability Assessment and Penetration Testing (VAPT).
Platform Availability
We monitor the availability of our core messaging platform on an ongoing basis. Contact us directly if you need current availability figures for a vendor security review or SLA discussion.
Secure Transactions
Payments are processed through third-party payment gateways. We do not store full payment card details on our own systems.
If you have a specific security or compliance question that isn't answered here, for example for a vendor security questionnaire, contact us at [email protected] and we'll do our best to help directly rather than pointing you back to this page.

