{
  "id": "CON-KEYWORD-CONFIRM",
  "slug": "con-keyword-confirm",
  "title": "Keyword opt-in requires a compliant confirmation reply",
  "statement": "The auto-reply sent after a keyword opt-in must carry the brand, frequency, rates, STOP and HELP.",
  "rationale": "The confirmation message is the consumer’s receipt: it is where they learn what they just joined and how to leave. CTIA treats it as a required disclosure surface in its own right, and it is the one element of a keyword program you control completely.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "campaign.optin_message",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "CTIA",
    "TCR",
    "Bandwidth",
    "AWS"
  ],
  "applicability": {
    "consentMethods": [
      "keyword"
    ]
  },
  "applicabilityText": "Applies when consent was collected by text-to-join keyword.",
  "universal": false,
  "remediation": "Write the opt-in confirmation to include all five elements within the 320-character limit.",
  "example": "Acme Coffee: you're subscribed to offers. Msg frequency varies. Msg & data rates may apply. Reply HELP for help, STOP to cancel.",
  "catalogIds": [
    "CMP-181"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-keyword-confirm/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-keyword-confirm.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
