Global compliance data
All of this is on Compliance and owned by the compliance service. It has six tabs: Companies, Do not call, Default rules, Holidays, Reference data and Trap numbers. API paths below are relative to /api/platform/v1/compliance. Writes need the compliance_write capability (platform_owner); other roles see no buttons. A company can only make the shared rules stricter, never looser.
Do-not-call imports
Section titled “Do-not-call imports”A federal, state or litigator list is a CSV file sent as the body of one request. It is streamed, so it is never held in memory, and may be up to 2 GB.
On the Do not call tab:
- Under Import a list, choose the scope: Federal, State (also pick the state) or Known litigators.
- Give a source label and optionally an effective date.
- Choose add (default) or replace.
- Choose the file. A progress bar shows the upload; Recent imports shows each job’s state and counts, updated after every batch (
GET /dnc/imports/{id}).
Replace opens a box that says it removes numbers for every company, and you must type REPLACE.
The file is one number per line, or a CSV whose first line names the phone column. Numbers are stored only as keyed hashes. Sending the same file again adds nothing.
Add and replace
Section titled “Add and replace”- Add only ever adds. A file that fails half way keeps what it already added and removes nothing.
- Replace also removes every active number of that scope that is not in the file, but only after the whole file was read without error. A failed or cancelled replace removes nothing. A file that is mostly not phone numbers (none valid, or over half invalid) is refused, so a wrong file cannot wipe a list. Trap numbers are never replaced away.
- New numbers are live in the checks as soon as the job ends, with no restart.
Default rules
Section titled “Default rules”The Default rules tab (GET/POST /rules, PUT /rules/{id}, DELETE /rules/{id}) manages the platform’s rows: calling hours, attempt caps, consent, holidays blocked, recording consent, AI disclosure, minimum age. A new rule starts flagged needs counsel review. Mark as reviewed by counsel (reviewer, note; the server records the date, POST /rules/{id}/review) records the reviewer’s name and note and clears the flag. Changing a rule’s value sets the flag again. Delete is soft. The only US calling-hours and consent rules cannot be switched off, because the checks would then deny every call.
Holidays
Section titled “Holidays”The Holidays tab (GET/POST/DELETE /holidays) manages the days with no calls. Changes apply at once. US federal holidays for 2026 and 2027 are seeded.
Area-code and ZIP3 reference data
Section titled “Area-code and ZIP3 reference data”The Reference data tab shows each table’s row count and its source. The built-in tables are public data (NANPA, Census, US DOT); until they are uploaded with a source the tab shows a “built-in copy” notice. Upload (PUT /reference/area-codes, PUT /reference/zip3, PUT /reference/zip5) takes a CSV of code,state,timezone[,timezone2...]. You must say the source and whether it is verified. The format is strict. If any line is wrong, nothing is applied and you get the first 100 errors. Use the built-in table goes back to the built-in table.
Canary numbers
Section titled “Canary numbers”A canary is a trap number. Any company that dials it is denied with honeypot and the hit is recorded. The Trap numbers tab (GET/POST/DELETE /canaries) manages them: Add a trap number and Retire. Companies are not shown platform traps.
Across companies
Section titled “Across companies”- The Companies tab (
GET /overview) shows, per company, checks allowed and denied by reason, open complaints, trap hits, and the state of its audit chain. - Check the audit log now (
POST /tenants/{id}/audit/verify) walks one company’s whole audit chain and says whether it is intact. GET /search/phonefinds which lists and companies hold a number, by hash, with counts only.