{
  "id": "BRD-117",
  "slug": "brd-117",
  "title": "A public company must supply a business contact email",
  "statement": "A PUBLIC_PROFIT brand must carry a business contact email — it is mandatory and it triggers the Authentication+ 2FA.",
  "rationale": "For a public company this field is not a contact detail, it is the second factor: the PIN goes to it and the brand cannot reach VERIFIED without one. Omitting it does not produce a missing-field error people recognise — the brand sits in an authentication-required state, which reads as a queue rather than as a blank box.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.business_contact_email",
  "severity": "BLOCKING",
  "detectability": [
    "DETERMINISTIC"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "TCR",
    "AWS",
    "Telnyx"
  ],
  "codes": [
    {
      "provider": "TCR",
      "code": "501",
      "remediable": true
    },
    {
      "provider": "Twilio",
      "code": "30994",
      "remediable": true
    }
  ],
  "applicability": {
    "entityTypes": [
      "PUBLIC_PROFIT"
    ]
  },
  "applicabilityText": "Applies when the brand is a public company.",
  "universal": false,
  "remediation": "Supply a named individual's mailbox on the company domain, monitored by someone who will act on a verification mail within days. Done when the field is populated and that person knows a PIN is coming.",
  "example": "business_contact_email: jane.doe@acmecoffee.com — an individual mailbox on the company domain",
  "pitfalls": [
    "The PIN expires (BRD-227), so an address that is technically valid but monitored monthly fails the verification just as surely as an empty field."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/brand/brd-117/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-117.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
