{
  "id": "POL-105",
  "slug": "pol-105",
  "title": "The policy must describe its security safeguards at a high level",
  "statement": "The privacy policy must describe the safeguards protecting the information, at least at a high level.",
  "rationale": "CTIA asks senders to describe how information is protected, and the value to the consumer is a signal that somebody thought about it at all. The trap is the opposite of omission: a generated policy that invents a certification the business does not hold turns a missing sentence into a false statement, which is a much worse position.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "CTIA",
    "MessageDesk"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Describe the measures you actually have in one or two sentences, and name no standard you have not been audited against. Done when everything the section claims is true of your systems today.",
  "example": "We encrypt data in transit and at rest, and limit access to the numbers in the text programme to the staff who operate it.",
  "pitfalls": [
    "Do not name a compliance standard to fill the section. POL-242 exists because invented certifications are the specific failure this section attracts."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-105/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-105.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
