Security, consent and reliability

Careful with customer messages, at every step.

ConnectSMS runs inside your Salesforce org and talks only to your Twilio account. Here is how it protects that connection, respects opt-outs, and avoids losing or duplicating customer messages.

  • No credit card required
  • Listed on Salesforce AgentExchange
  • Then $120 per user per year
  • Runs on your own Twilio account

Is ConnectSMS secure? ConnectSMS checks Twilio's signature on every webhook call, verifies your Twilio credentials before saving them and never shows the Auth Token again. Messages are private and shared only through access to each business number, opt-outs are always enforced, and a message with an unclear outcome is checked with Twilio rather than sent twice.

Security

Your Twilio connection, locked down.

ConnectSMS is built on the Salesforce Platform, and Salesforce connects directly to your Twilio account with no ConnectSMS servers in between. These controls protect that connection and the messages that travel over it.

  • Twilio signature verification

    Every webhook call is checked against Twilio's signature for the exact address and parameters. In Enforce mode, the default, unsigned or forged requests are rejected, and sending can't be turned on without it.

  • Twilio account validation

    Credentials are verified with Twilio before they're saved, and webhook requests must match the Account SID of your saved connection.

  • Auth Token never shown or logged

    The Auth Token lives in a protected setting only ConnectSMS can read. Your Twilio Auth Token is never shown in the browser or written to logs.

  • Restricted guest-user access

    The Site guest user gets ConnectSMS Webhook Guest, which grants the webhook Apex class and nothing else. It gives no access to your records.

  • Private messages and conversations

    Messages and conversations are private. People read them only through View or Send access to the business number.

  • Audit log

    Configuration, access and consent changes are recorded in an audit log, with who made each change and when.

  • Sandbox sending guard

    In a sandbox copied from an org where sending is on, sending turns off automatically until an admin turns it on in that sandbox.

  • Only Twilio endpoints

    The only outside service ConnectSMS calls is Twilio's API. No ConnectSMS server stores or relays your messages.

  • One switch for sending

    Admins can turn off sending for the whole org at once. A reason is required and recorded in the audit log.

Signature check: three modes, one safe default

Default

Enforce (recommended)

ConnectSMS rejects every request that does not carry a valid Twilio signature. Sending can only be turned on in this mode.

Short-term

Monitor (troubleshooting only)

Requests with a missing or wrong signature are accepted but recorded. Use it briefly while fixing a signature problem, then switch back.

Never in production

Off (development orgs only)

No signature check at all. Never use Off in production or in a sandbox that holds real customer data.

Good practice for your Twilio account

  • Use a dedicated Twilio subaccount for each Salesforce production org, and a test account or separate subaccount in sandboxes
  • Turn on Messaging Geographic Permissions for only the countries you serve, and SMS Pumping Protection, in Twilio
  • Protect the Twilio Console with two-factor authentication, and rotate the Auth Token if it may have been exposed
  • Keep signature checking on Enforce, and give the Site guest user only ConnectSMS Webhook Guest
  • Don't give integration or agent users ConnectSMS Campaign Manager or ConnectSMS Admin
  • Set a daily safeguard that matches your real sending volume

Reliability

Built to avoid guessing with customer messages.

Every message is written to Salesforce before ConnectSMS calls Twilio. If Twilio's answer is lost, the message is marked Unknown and checked with Twilio, never blindly sent again.

Sending means Twilio accepted the message. Sent means it was handed to the carrier, and Delivered means the carrier confirmed it.

Normal path

  1. Queued
  2. Sending
  3. Sent
  4. Delivered

If Twilio's answer is lost

  1. Timeout or server error
  2. Unknown
  3. ConnectSMS checks with Twilio
  4. Matching status, or Failed if Twilio never got it
  • Recorded before calling Twilio

    Each message is saved in Salesforce first, so a lost connection can't lose the message or its history.

  • Unknown, then checked with Twilio

    A timeout, connection error or Twilio server error marks the message Unknown. ConnectSMS asks Twilio what happened and records the matching status, or Failed if Twilio never got it.

  • Queued dispatch

    Messages sent now go to a background job right away. Scheduled messages, outreach and anything still waiting are picked up by the dispatcher every 15 minutes.

  • Duplicate-send protection

    Idempotency keys let Flow, Apex and API callers repeat a request without sending the message twice, and the composer ignores double clicks.

  • Rate-limit back-off

    If Twilio answers 429 Too Many Requests, the message goes back to Queued and is tried again after a pause.

  • Stuck-message detection

    A message still waiting on Twilio's answer after 10 minutes is marked Unknown and checked with Twilio.

  • Retry linked to the original

    Failed and Undelivered messages can be retried deliberately as a new message linked to the first, so the history shows both.

  • Failures in plain language

    Each failure says what went wrong and what to do next, with the Twilio error code.

  • Checked again at send time

    Before a queued or scheduled message goes out, ConnectSMS re-checks the sending switch, permissions, number access and opt-outs.

Every message status, and what it means
StatusWhat it means
ScheduledWaiting for its scheduled time; permissions and consent are checked again before sending
QueuedSaved and waiting to be handed to Twilio
SendingTwilio accepted it and is sending it to the carrier
SentHanded to the carrier; delivery not yet confirmed
DeliveredThe carrier confirmed delivery; this does not mean it was read
ReadReported read by the recipient's app
UndeliveredThe carrier couldn't deliver it
FailedIt couldn't be sent
BlockedA ConnectSMS rule blocked it
CanceledCanceled before it was sent
UnknownConnectSMS couldn't confirm whether Twilio accepted it; it is being checked and won't be resent automatically
ReceivedReceived from the customer

Permissions

Access by role, and by business number.

Two things decide what someone can do: a ConnectSMS permission set, and access to specific business numbers.

ConnectSMS User

Everyday texting, the inbox and templates, on the business numbers an admin has granted.

ConnectSMS Campaign Manager

Creates, reviews, launches, pauses and cancels outreach, and manages shared templates. Combine with ConnectSMS User to text one-to-one.

ConnectSMS Admin

Twilio connection, business numbers, access, policies, opt-outs and operations.

ConnectSMS Automation

For integration users, agent users and people who run Flow or API messaging from numbers made available to automation.

What each permission set includes

Permission setCustom permissions
ConnectSMS UserConnectSMS: Send Messages
ConnectSMS Campaign ManagerConnectSMS: Manage Outreach
ConnectSMS: Manage Templates
ConnectSMS: Send from Automation Numbers
ConnectSMS AutomationConnectSMS: Send from Automation Numbers
ConnectSMS AdminAll five, including ConnectSMS: Administer

How number access works

  • Admins grant Send or View access per business number, to people or public groups. Send includes View
  • Replies always come from the number the customer texted; people without Send access to it can read but not reply
  • Admins see every conversation, including texts to Twilio numbers not set up in ConnectSMS
  • Permissions and number access are checked again at send time, so removed access blocks queued messages too
  • ConnectSMS Webhook Guest is only for the Site guest user. It isn't a role for people

FAQ

Security and consent: common questions

How are SMS opt-outs handled?

When a customer replies with one of Twilio's standard opt-out keywords, such as STOP, UNSUBSCRIBE or CANCEL, ConnectSMS records the opt-out and stops texting that number; START, YES or UNSTOP opts them back in. Opt-outs are always enforced, checked when a message is requested and again when it is sent, and shown to users in the composer and inbox.

Does ConnectSMS make my text messaging compliant?

No software can do that on its own. ConnectSMS gives you controls that help your team apply the policies you choose, including opt-out enforcement, quiet hours for outreach and automation, number-level access and an audit log. You remain responsible for consent and for the rules that apply to your messages.

How does ConnectSMS know a webhook call really came from Twilio?

Twilio signs every request it sends. ConnectSMS checks that signature against the exact webhook address and parameters using your Auth Token, and checks that the request names your Twilio account. In Enforce mode, which is required before sending can be turned on, any request that fails is rejected.

What happens if Twilio doesn't answer when a message is sent?

The message is marked Unknown instead of being sent again. ConnectSMS asks Twilio whether it received the message: if it did, the real status is recorded; if not, the message becomes Failed and someone can retry it deliberately. Admins can also choose Check with Twilio in Operations.

Can a Salesforce sandbox send real text messages by accident?

When a sandbox is copied from an org where sending is on, ConnectSMS turns sending off in the sandbox automatically. An admin has to review the Twilio settings and turn sending on there. We recommend a Twilio test account or a separate subaccount for sandboxes.

Keep exploring

Try it now: every feature, free for 14 days

Put every customer text where your team already works.

Install ConnectSMS from AgentExchange, connect your Twilio account and give your team the numbers they should text from.

  • No credit card required
  • Listed on Salesforce AgentExchange
  • Then $120 per user per year
  • Runs on your own Twilio account

ConnectSMS is published by WorkBridge Solutions. Twilio bills your Twilio account directly for messaging, including during the trial.