{
  "id": "BRD-277",
  "slug": "brd-277",
  "title": "High-risk financial services brands are not carried",
  "statement": "A brand whose business is high-risk financial services — payday and short-term lending, indirect loan marketing, stock alerts or crypto must not be registered for A2P messaging.",
  "rationale": "This category is where SMS fraud concentrates, so carriers exclude the business model rather than reading each campaign — the same message from a first-party lender and from a lead-selling loan site is indistinguishable in a text and very different in consequence. The cost of the blanket rule is that legitimate, licensed, first-party lenders get caught by it unless the carve-out is applied deliberately.",
  "layer": "BRAND",
  "layerSlug": "brand",
  "object": "brand.vertical + brand fields + website content",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM",
    "CRAWL"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "AWS",
    "Bandwidth",
    "Bird",
    "Infobip",
    "Sinch",
    "Plivo",
    "Vonage"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "709",
      "remediable": false
    },
    {
      "provider": "Sinch",
      "code": "CR2014",
      "remediable": false
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Where the business is a licensed first-party lender servicing its own loans, say so explicitly in the brand description and the campaign — the carve-out is real and it turns on first-party servicing. Where the business markets credit it does not originate, or promotes securities or crypto, it cannot be registered.",
  "notes": "The first-party carve-out is load-bearing and is the same one MSG-HIGH-RISK-FINANCIAL carries at the campaign layer; fixture 5 of the golden corpus exists to keep it from being dropped. Sinch permits 2FA-only traffic for stocks, investing and crypto businesses, which is why that carve-out is stated separately.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/brand/brd-277/",
  "markdown": "https://ekas.io/rules/10dlc/brand/brd-277.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
