# POL-105 — The policy must describe its security safeguards at a high level

> The privacy policy must describe the safeguards protecting the information, at least at a high level.

- **Rule ID:** POL-105
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CTIA, MessageDesk
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-105/

## Why this rule exists

CTIA asks senders to describe how information is protected, and the value to the consumer is a signal that somebody thought about it at all. The trap is the opposite of omission: a generated policy that invents a certification the business does not hold turns a missing sentence into a false statement, which is a much worse position.

## How to fix it

Describe the measures you actually have in one or two sentences, and name no standard you have not been audited against. Done when everything the section claims is true of your systems today.

## Example of a compliant value

```text
We encrypt data in transit and at rest, and limit access to the numbers in the text programme to the staff who operate it.
```

## Common mistakes

- Do not name a compliance standard to fill the section. POL-242 exists because invented certifications are the specific failure this section attracts.
