Compliance

The record you would want if someone asked.

Outreach and lead resale are the two places this kind of module creates real exposure. The design assumption is that every touch may one day have to be defended, one message at a time.

Consent ledger

Everything captured at the moment of consent.

Not a boolean on a lead record. A complete, immutable, versioned account of exactly what the consumer was shown and what they agreed to.

  • Exact disclosure text shown
  • Disclosure version identifier
  • Date and time, to the second
  • IP address and user agent
  • Page URL and form position
  • Checkbox state as submitted
  • Named seller / brand identified
  • Authorized communication channels
  • Specific phone number and email authorized
  • Source URL and campaign attribution
  • Third-party proof certificate token
  • Every withdrawal or opt-out event

Enforcement

Rules the engine applies, every time.

One-to-one consent

The disclosure names your brand as the specific sender. Onward sale to third parties is a separate, itemized consent — never bundled into a generic 'insurance partners may contact you' line.

Quiet hours by consumer, not by you

Permitted contact windows are computed from the consumer's ZIP and time zone, with state overrides where the state is narrower than the federal 8:00 a.m. to 9:00 p.m. window. It is a rule engine evaluated at dispatch, not a setting someone forgets.

Suppression before every action

DNC and internal suppression are checked before every outbound touch and before every post to a partner. Suppression is permanent and applies across channels, sequences and auctions simultaneously.

Only what consent allows is shared

What leaves the module to any third party is limited to what the stored consent record actually authorizes. Unredacted contact data is released only after a buyer accepts.

State-specific referral compensation

Licensing requirements and restrictions on compensation contingent on an insurance sale differ by state. Those rules are configuration the engine reads, because a single national revenue-share model is not lawful everywhere.

Revocation is an event

Every withdrawal is stored as its own timestamped record, processed promptly, and never overwritten. The ledger is append-only, so the audit trail survives every later change.

Where responsibility sits

The platform records and enforces. It does not certify.

Sovereign's role is to make the compliant path the default path and the evidence automatic: consent captured properly, quiet hours computed correctly, suppression honored everywhere, and every action reconstructable from an append-only record. You remain the party communicating with the consumer, and you set the rules that govern their own book.

Federal telemarketing and robotext rules, state-level restrictions, commercial email requirements and state insurance-licensing law all bear on how this module is turned on for a given company.

Consent language, disclosure placement, onward-sale disclosures and referral-compensation configuration must be reviewed by insurance and TCPA counsel before production use. Nothing on this page is legal advice, and no part of the platform is offered as a compliance guarantee.