Never assert a fact about the business nobody has confirmed
The requirementstatement
A generated document must assert no fact about the business — retention periods, encryption, sub-processors, certifications, jurisdictions — that has not been sourced or confirmed by the user.
- Severityseverity
- BlockingBLOCKINGBreaking this rule gets the submission rejected. There is no partial credit.
- When it bitesphase
- Gates approvalapprovalGet this wrong and the brand or campaign is refused at registration.
- What is checkedobject
- generated policy factual assertions
- Where it liveslayer
- Policy pagesPOLICY_PAGE
- How Ekas settles itdetectability
- Human checkHUMAN
- Only someone holding the document or making the call can settle it. Ekas tells you exactly what to look at.
- What the fix involvesfailureClass
- Supply evidenceTERMINAL_EVIDENCE
- Needs proof only you hold: a screenshot, a recording, a scan of the form people signed.
- Who requires itauthorities
- FTCTCR
- When it appliesapplicabilityText
- Applies to every 10DLC registration.
Why this rule existsrationale
How to fix itremediation
Confirm each factual claim with the person who would know — retention with whoever runs the database, encryption with whoever runs the infrastructure, certifications with whoever holds the audit report — and delete the ones nobody can confirm. Done when every specific in the document traces to somebody who said it.
Check this yourselfattestation
No tool can settle this one for you. Here is the check, and what wrong looks like.
Can you name a person who confirmed each specific claim in this document — retention periods, encryption, sub-processors, certifications?
- 1Read the document as a list of assertions about your own business.
- 2For each specific, ask the person who would know: retention with whoever runs the database, encryption with whoever runs the infrastructure, certifications with whoever holds the audit report.
- 3Delete every claim nobody can source. Invented SOC 2, ISO 27001 and HIPAA claims are the named ones.
What wrong looks like: A thirty-day retention period and AES-256 at rest arrive in the draft because they are plausible. The FTC treats a false privacy claim as a deceptive practice, so the consequence is an enforcement action rather than a rejection.
Notesnotes
Rules you will hit next
Other policy pages rules at the same severity. A registration is judged as a whole, not rule by rule.
POL-242 is one of 157 policy pages rules in the 915-rule 10DLC registry. Free to cite under CC BY 4.0.