TSGGLOBAL Talk to an expert

Security at TSG Global.

How we protect our services, manage security risks, and help you understand the practices behind your communications provider.

Program overview updated September 15, 2026

Our audit status

Management-provided overview

We continue to follow our documented security policies, developed using ISO/IEC 27001 and the Trust Services Criteria used in SOC 2. We no longer commission external assurance or certification audits and do not maintain current SOC 2 reporting or ISO 27001 certification.

The practices described here are reported by TSG management. They have not been validated through a current independent audit. Past reports apply only to the systems and periods they examined.

The policies we work by.

Our security program covers the people, processes, and systems supporting TSG’s core messaging and voice services. These summaries describe our policy requirements and operating approach.

Access and authentication

Access follows job responsibilities and the principle of least privilege. Our policies require individual accounts, approval for production access, and multi-factor authentication wherever a system supports it.

Policy detail

Access is reviewed and adjusted when responsibilities change, and removed when people leave. Passwords and other credentials are managed as confidential information.

Policies: System Access Control Policy; Password Policy.

Data protection

Our policies require encrypted storage for production data and encrypted connections for sensitive information. Customer data is logically separated, with access restricted to the authorized account.

Policy detail

Classification rules determine how data is handled. Retention and deletion depend on the type of record and applicable service, contractual, and legal requirements. Ask us about the data flows and retention terms for your service.

Policies: Data Protection Policy; Encryption Policy; Data Classification Policy; Data Deletion Policy.

Secure development

Our development process calls for code review, testing, and approval before production releases. Production and development environments are separated, and use of customer data in testing is restricted.

Policy detail

Security findings are tracked with the responsible team. High- and critical-severity findings require resolution or an approved exception with compensating safeguards before release.

Policies: Software Development Life Cycle Policy; Vulnerability Management Policy.

Monitoring and vulnerabilities

Production logging and security monitoring support the investigation of suspicious activity. Vulnerability findings are assessed by severity, assigned to an owner, and tracked through remediation.

Policy detail

Our policies cover vulnerability scanning, patching, and documented exceptions. Ask our security team for the scope and date of available testing evidence for the service you use.

Policies: Data Protection Policy; Vulnerability Management Policy.

Incident response

We maintain a documented response process for identifying, containing, investigating, and recovering from security incidents, with assigned responsibilities and escalation paths.

Policy detail

The plan includes evidence handling and communication with affected customers and other stakeholders. Notification obligations depend on the incident, the services affected, and applicable contractual and legal requirements.

Policies: Incident Response Plan; Responsible Disclosure Policy.

Backups and recovery

Our backup and recovery policies cover production data, encrypted backups, recovery responsibilities, and continuity planning for service disruptions.

Policy detail

Recovery priorities depend on the affected service. Contact us for service-specific backup and recovery information; this overview does not create an uptime or recovery-time guarantee.

Policies: Backup Policy; Business Continuity Plan; Disaster Recovery Plan.

People and governance

Security is overseen by our CTO/CISO. Written policies define responsibilities, acceptable use, risk management, and how exceptions are approved.

Policy detail

Our program calls for security awareness training during onboarding and annually, along with periodic policy and access reviews. Security risks are assessed and assigned for treatment.

Policies: Information Security Policy; ISMS Plan; Risk Assessment Policy; Acceptable Use Policy.

Supplier oversight

Our vendor-management process considers the information a supplier can access and the impact its services have on TSG and our customers.

Policy detail

Supplier reviews address security responsibilities, data handling, and relevant contractual safeguards. Service-specific infrastructure and supplier information can be discussed during your review.

Policies: Vendor Management Policy; Asset Management Policy.

Information for your review.

Start with the overview here. For more detail, request the documents relevant to the services you use.

Security policies and service questions

Available by request

Ask about access control, data protection, development, vulnerability management, incident response, continuity, or supplier oversight.

Request policy information

SOC 2 Type 2 report

Historical evidence

Our most recent completed report covers the Security category for April 1, 2024 through March 31, 2025. It describes that examination period and does not provide assurance about our current controls.

Issued August 25, 2025 by MJD Advisors.

Request historical report

We review document requests individually. Confidential materials may require an NDA and remain subject to their stated use restrictions. Customer agreements are provided only to authorized account contacts.

Common review questions.

Clear answers about the scope and limits of this information.

Do you have a current SOC 2 report or ISO 27001 certificate?

No. TSG no longer commissions external assurance or certification audits and does not maintain current SOC 2 reporting or ISO 27001 certification. We continue to operate under our documented security policies. Historical documents describe their stated scope and period only.

What does following a framework mean here?

Our security policies were developed using ISO/IEC 27001 and the Trust Services Criteria used in SOC 2. These frameworks help organize responsibilities and security practices. This page is a management-provided overview; it is not an independent assessment or a certification.

Can you help with a vendor security review?

Yes. Send your company name, the TSG services you use, your questionnaire or document list, and your deadline to security@tsgglobal.com. We will review the request and identify the information available for your account. If your procurement process requires a current external audit, tell us at the outset.

Does this cover every part of message or call delivery?

This page concerns TSG’s core messaging and voice services and the systems we operate to support them. Carrier networks and recipients’ devices have separate security properties. Transport encryption on a TSG connection does not provide end-to-end encryption for ordinary SMS or MMS. Ask us to confirm the boundaries for your integration.

Contact our security team.

security@tsgglobal.com

For a review, include your company name, TSG services, requested documents, and deadline. We can also help identify the agreement on file for your account.

Program owner: Alex Eastwood, CTO / CISO
TSG Global, Inc.

Report a security concern

Email security@tsgglobal.com with the affected service, what you observed, steps to reproduce it, and the potential impact. Keep reports limited to the information needed to investigate; contact us to arrange secure sharing of sensitive evidence.

For unwanted calls or messages, use Report abuse. For service availability, see our status page.