Effective Date: September 10, 2026 | Last Updated: September 10, 2026
COMEXCEL Acceptable Use Policy and Network Integrity Standards define the mandatory operational rules, carrier compliance requirements, and prohibited practices governing access to and use of our Business VoIP Phone Service & Hosted Cloud PBX Infrastructure, SIP trunking, business phone numbers, 2-way SMS/MMS, mobile and desktop softphone applications, APIs, CRM integrations, and artificial intelligence communications tools. This policy applies to all small businesses, multi-location companies, enterprise organizations, remote/hybrid workforces, PBX administrators, IT teams, and individual VoIP users subscribing to or accessing our network. These standards safeguard telecommunications infrastructure, preserve carrier interconnect relationships, ensure message deliverability, and protect call and message recipients against unlawful, deceptive, or abusive communications.
Acceptable Use at a Glance
- Core Permitted Use: Legitimate, lawful, and authorized business-to-business (B2B) and business-to-consumer (B2C) communications with verified recipient consent.
- Strict Robocall & Voice Rules: Complete ban on unlawful autodialing, ringless voicemails, traffic pumping, and synthetic/AI voice impersonation.
- 10DLC & Messaging Standards: Mandatory registration with The Campaign Registry (TCR), strict opt-in recordkeeping, and automated handling of opt-out keywords (STOP, CANCEL, QUIT, UNSUBSCRIBE).
- Prohibited Content: Zero tolerance for spam, phishing, smishing, debt relief, unverified financial leads, cannabis/CBD promotions, and purchased marketing lists.
- Enforcement & Liability: COMEXCEL reserves the right to immediately throttle, suspend, or terminate accounts and pass through carrier-imposed non-compliance fines ($500–$10,000 per violation) resulting from prohibited activity.
Purpose, Scope & Services Covered
This Acceptable Use Policy is administered as part of the centralized COMEXCEL Legal & Compliance Hub and applies to all subscribers, account administrators, authorized end users, developers, resellers, and third-party systems accessing COMEXCEL products. Covered services include:
- Voice Infrastructure: Business VoIP Phone Service, Cloud PBX, SIP trunking, auto-attendants (IVR), call queues, call forwarding, ring groups, and voicemail.
- Number Inventory: Local Direct Inward Dialing (DID) numbers, toll-free numbers, vanity numbers, and number porting services.
- Digital Messaging: 2-way business SMS, multimedia messaging (MMS), and 10DLC application-to-person (A2P) traffic.
- Endpoints & Tools: Desktop softphones (Windows, macOS), mobile applications (iOS, Android), REST APIs, webhooks, CRM integration connectors, and AI speech intelligence engines.
Lawful & Authorized Business Use Standard
COMEXCEL services are provisioned strictly for legitimate commercial, professional, non-profit, or enterprise business operations. Customers are independently responsible for understanding and complying with all applicable federal, state, local, and international telecommunications statutes, consumer protection laws, industry trade standards, and carrier regulations. COMEXCEL provides communications infrastructure and software tools; we do not provide legal counsel, compliance guarantees, or regulatory immunity.
Prohibited Voice Calling & Robocalling Violations
Customers may not utilize COMEXCEL voice channels, SIP trunks, or softphone endpoints to conduct unauthorized, abusive, or unlawful calling campaigns:
| Prohibited Voice Activity | Technical & Operational Characteristics | Statutory Baseline | Platform Enforcement Action |
|---|---|---|---|
| Unlawful Robocalling | Prerecorded or synthetic audio blasts without prior express written consent. | TCPA / TRACED Act | Immediate trunk suspension; Industry Traceback referral. |
| Predictive & Broadcast Autodialing | High-velocity sequential dialers causing high unanswered/abandonment spikes. | FCC Part 64 Rules | Account rate-limiting; transition to metered trunking rates. |
| Ringless Voicemail Drops | Injecting voicemail payloads directly without a live alerting connection. | TCPA / FTC TSR | Permanent deprovisioning of associated phone numbers. |
| Traffic Pumping & Stimulation | Generating artificial high-cost traffic or inflating termination minutes. | Communications Act § 201 | Immediate account termination and financial liability assessment. |
Consent, Telemarketing & Do-Not-Call Compliance
Customers conducting outbound sales, notifications, or telemarketing outreach must adhere to the Telephone Consumer Protection Act (TCPA) and Telemarketing Sales Rule (TSR):
- Documented Opt-In Records: Maintain verifiable, timestamped records of recipient consent (including IP address, web form submission, or signed authorization).
- National & State DNC Scrubbing: Regularly scrub contact lists against the National Do Not Call Registry and applicable state registry databases prior to placing outbound calls.
- Internal Suppression Lists: Maintain an internal do-not-call list and immediately suppress any consumer who requests not to be contacted.
- Calling Time Windows: Strictly observe permissible local calling hours (typically between 8:00 AM and 9:00 PM in the call recipient’s local time zone).
AI Voice Intelligence, Cloned Audio & Synthetic Media
In compliance with Federal Communications Commission (FCC) rulings governing artificial and synthetic voices under the TCPA:
- Voice Cloning Prohibition: Generating or transmitting cloned human voices, audio deepfakes, or synthetic voice representations of real individuals without their explicit written authorization is strictly prohibited.
- Deceptive AI Calling: AI conversational agents or automated voice systems may not impersonate live human representatives or deceive call recipients regarding their automated nature.
- Consent Equivalence: All outbound calls utilizing AI-generated or synthesized voices are classified as prerecorded voice communications and require prior express written consent.
Caller ID Integrity, Spoofing & STIR/SHAKEN
Under the Truth in Caller ID Act and FCC STIR/SHAKEN caller authentication standards, COMEXCEL signs outbound calls with cryptographic certificates through our Security & Trust Center infrastructure:
- Prohibited Caller ID Spoofing: Transmitting misleading, inaccurate, or falsified caller ID numbers with the intent to defraud, deceive, cause harm, or conceal originating business identity is strictly prohibited.
- Neighbor Spoofing & Number Cycling: Matching local area codes and prefixes to deceive recipients into answering, or dynamically cycling through dozens of temporary numbers to evade carrier reputation flags, is a severe violation.
- Traceback Cooperation: Customers must cooperate promptly and fully with COMEXCEL and the Industry Traceback Group (ITG) in investigating any suspicious, illegal, or flagged calling patterns.

Zero Tolerance for Spam & Purchased Contact Lists
COMEXCEL operates a strict zero-tolerance policy for unsolicited communications (spam) across all voice and messaging channels:
- Third-Party Lead Lists: The purchase, rental, harvesting, or web-scraping of telephone numbers does not satisfy lawful consent requirements. Sending messages or calls to third-party lists is strictly forbidden.
- Cold Message Blasts: Transmitting unsolicited bulk text messages or marketing announcements to unverified prospects without an established business relationship or prior opt-in is prohibited.
Business SMS, MMS & 10DLC Messaging Rules
To protect carrier deliverability and comply with CTIA guidelines and The Campaign Registry (TCR) standards, all messaging must adhere to our 10DLC & Messaging Policy:
- Mandatory 10DLC Registration: Customers must complete Brand and Campaign registration with accurate business identity and sample message disclosures before sending business texts.
- Sender Transparency: Outbound text messages must clearly identify the business sender within the body of the message (e.g., “[Business Name]: Your appointment is confirmed…”).
- Automated Keyword Handling: Every messaging workflow must support and immediately execute automated carrier opt-out keywords (STOP, END, CANCEL, QUIT, UNSUBSCRIBE) and informational help prompts (HELP).
- Opt-In Strict Alignment: Message content must match the specific use case disclosed during opt-in. A customer consenting to service alerts cannot receive unrelated marketing promotions.

Prohibited SMS/MMS Content & High-Risk Niches
The transmission of messages containing the following restricted, prohibited, or high-risk content categories is strictly banned across the COMEXCEL network:
| Prohibited Category | High-Risk Industry Examples | Applicable Carrier Standard | Minimum Carrier Pass-Through Fine |
|---|---|---|---|
| CTIA SHAFT | Sex, Hate speech, Alcohol, Firearms, Tobacco/Vape promotions. | CTIA Short Code / 10DLC Rules | $1,000 – $5,000 per violation |
| Cannabis & CBD | Dispensaries, Delta-8, kratom, or federally controlled substances. | Federal Controlled Substances Act | $2,500 – $10,000 per violation |
| High-Risk Financial | Payday loans, cash advances, credit repair, debt consolidation. | Tier-1 Carrier Content Policies | $1,000 – $5,000 per violation |
| Deceptive Schemes | Work-from-home, crypto investment schemes, sweepstakes, lead generation. | FTC Deceptive Advertising Rules | Immediate Account Termination |
| Third-Party Affiliate | Cross-brand promotional alerts and unconsented affiliate lead lists. | TCR Non-Transferable Consent Rules | $1,000 per reported campaign |
CRM Integrations, APIs & Workflow Automation Abuse
Customers integrating COMEXCEL with third-party CRMs (Salesforce, HubSpot, Zoho), webhooks, or custom REST APIs must configure their automation responsibly:
- No Automated Spam Triggers: Automated CRM workflows may not trigger mass unverified SMS or cold dialing sequences upon importing external lead databases.
- API Quota & Rate Limit Protection: Flooding COMEXCEL API endpoints, attempting to bypass rate limits, or overwhelming SIP gateways with concurrent connection bursts is prohibited.
- Credential Protection: Developer API tokens, secret keys, and webhook endpoints must be secured. Sharing API credentials with unvetted third parties is a breach of policy.
Fraud, Toll Fraud & Account Compromise Schemes
- PBX Hacking & Toll Fraud: Exploiting PBX routing rules, brute-forcing SIP extension passwords, or routing unauthorized international calls across the COMEXCEL network is prohibited. Customers are financially liable for all toll fraud originating from their credentials.
- Social Engineering & Phishing: Engaging in phishing, smishing (SMS phishing), vishing (voice phishing), account takeover schemes, or posing as financial institutions, government agencies, or tech support entities is subject to immediate legal referral.
Network, Platform & Infrastructure Cybersecurity Abuse
Customers and users may not engage in any activity that compromises platform security, integrity, or availability:
- Denial of Service (DoS): Launching SIP INVITE floods, registration flooding, TCP/UDP packet storms, or DDoS attacks against COMEXCEL nodes or carrier interconnects.
- System Exploitation: Port scanning, penetration testing without prior written consent, vulnerability harvesting, reverse engineering, or injecting malicious payloads into platform interfaces.
Emergency Services (E911) Misuse & Interference
- False Emergency Reporting: Placing fraudulent, non-emergency, or automated test calls to 911 or emergency response operators is strictly illegal.
- Address Falsification: Intentionally inputting false, invalid, or misleading physical street addresses into the E911 Registered Location portal violates FCC regulations and our E911 & Emergency Services Disclosure.
Call Recording Consent & Audible Notification Rules
When configuring automated call recording on extensions, queues, or softphone endpoints, customers must verify consent laws in their jurisdictions. In clinical and healthcare settings, recording configurations must strictly comply with our HIPAA Compliance Statement:
- Consent Law Compliance: Customers must determine whether their calling operations fall under one-party or all-party (two-party) consent jurisdictions before recording audio.
- Audible Warnings: Customers must configure automated IVR audio prompts (e.g., “This call may be recorded for quality and training purposes”) or periodic audible beeps to inform all participants when recording is active.
Phone Number Inventory, Resale & Porting Abuse
- Number Warehousing: Purchasing and hoarding excessive unassigned telephone numbers to manipulate carrier reputation scores or evade spam filters is prohibited.
- Fraudulent Porting: Submitting forged Letters of Authorization (LOAs), porting numbers without verified customer authorization, or attempting port-out fraud is strictly forbidden.
Resellers, Agents & Downstream Client Responsibility
Reseller partners, master accounts, and enterprise administrators remain fully legally and financially responsible for all communications traffic generated by their sub-accounts, remote workers, and downstream clients. Violations originating from a sub-tenant will result in restrictions or immediate suspension of the parent account.
Automated Traffic Monitoring & Anomaly Detection
To protect network health and downstream deliverability, COMEXCEL coordinates automated traffic monitoring alongside Failover & Disaster Recovery systems to track:
- Spikes in ultra-short duration voice calls (<6 seconds).
- Unusually high ratios of unanswered, busy, or rejected call attempts.
- Carrier error return codes (e.g., 10DLC delivery rejections, carrier spam tags).
- Rapidly accelerating recipient opt-out (STOP) requests or consumer abuse complaints.
Carrier-Level Filtering & Downstream Blocking
Customers acknowledge that mobile network operators (such as AT&T, Verizon, T-Mobile) and terminating PSTN carriers employ proprietary spam analytics, call-blocking algorithms, and message-filtering firewalls. COMEXCEL cannot override downstream carrier filtering resulting from non-compliant messaging formats, high spam complaint rates, or unregistered campaign traffic.
Enforcement, Penalties & Immediate Account Suspension
COMEXCEL applies a graduated enforcement protocol, but reserves the right to immediately suspend or terminate access without notice for severe violations:
- Immediate Kill-Switch Suspension: Accounts engaged in active phishing, robocalling, toll fraud, network attacks, carrier-directed blocking, or illegal activity will be terminated immediately.
- Pass-Through Fines: Customers agree to pay all carrier-imposed fines and non-compliance penalties ($500 to $10,000 per confirmed violation) assessed by upstream carriers or The Campaign Registry resulting from Customer’s prohibited activity.
Abuse Reporting & Law Enforcement Contact
If you suspect that a COMEXCEL phone number or service is being used for spam, illegal robocalls, fraud, or harassment, submit an incident report immediately:
COMEXCEL Trust & Safety Department
- Abuse Intake Email: [email protected]
- Carrier Traceback Desk: [email protected]
- Legal Department: [email protected]
- Mailing Address: COMEXCEL Legal Department, 2800 Marina Mile Blvd, Suite 119, Fort Lauderdale, FL 33312
Please include the originating telephone number, destination number, timestamp, call recording/SMS screenshot, and a brief description of the suspected violation.
Frequently Asked Questions (FAQ)
Can COMEXCEL services be used with high-volume autodialers or predictive dialers?
No. COMEXCEL prohibits unlawful robocalling, continuous predictive autodialing, telemarketing broadcasts without prior consent, and artificial traffic pumping that disrupts carrier networks or violates TCPA guidelines.
Can businesses send SMS/MMS messages to purchased or scraped contact lists?
No. Sending messages to purchased, rented, or web-scraped lists is strictly prohibited; all commercial SMS/MMS campaigns require documented, express written opt-in consent directly from the recipient.
How does COMEXCEL enforce STIR/SHAKEN caller ID standards?
COMEXCEL cryptographically validates and signs originating caller IDs in accordance with FCC STIR/SHAKEN standards, prohibiting neighbor spoofing, unlawful number cycling, or falsified calling identities.
What happens if an account incurs carrier-imposed non-compliance fines?
Any carrier non-compliance fines, TCR registration violation penalties ($500 to $10,000 per confirmed offense), or spam mitigation surcharges caused by prohibited customer activity are passed through directly to the offending account.
Are AI voice agents and synthetic voice calls permitted on COMEXCEL?
AI and synthetic voice calls are permitted only when explicit prior written consent has been obtained from the recipient; unannounced AI bots, voice cloning without authorization, and deceptive synthetic impersonation are strictly forbidden.
What content categories are completely banned from SMS/MMS messaging?
Prohibited categories include CTIA SHAFT topics (Sex, Hate, Alcohol, Firearms, Tobacco/Vape), cannabis/CBD products, payday loans, debt relief programs, cryptocurrency promotions, and third-party affiliate marketing schemes.
Who is responsible for toll fraud charges resulting from hacked SIP extensions?
The customer maintains sole financial and operational responsibility for securing PBX credentials and SIP passwords; all call charges resulting from compromised credentials will be billed directly to the customer.
How does COMEXCEL respond to Industry Traceback Group (ITG) inquiries?
COMEXCEL cooperates fully with the Industry Traceback Group and regulatory authorities to investigate suspicious traffic, identify originating sources, and immediately suspend offending numbers or accounts.
How do I configure call recording to ensure compliance in all-party consent states?
Administrators must enable the automated IVR disclosure announcement within the PBX call flow builder (e.g., “This call is recorded for quality assurance”) or program a recurring audible beep tone to alert external participants before audio recording commences.
How long does 10DLC Brand and Campaign registration take before I can send SMS?
Standard Brand and Campaign approval typically takes between 2 to 5 business days through The Campaign Registry (TCR) and downstream carrier verification gateways. Sending unverified traffic during this window will result in carrier rejection.
Report Suspected Spam, Robocalls, or Network Abuse
COMEXCEL maintains zero tolerance for unlawful robocalls, caller-ID spoofing, smishing, and abusive traffic patterns. Submit incident reports, evidence payloads, or carrier traceback requests directly to our Trust & Safety operations team.
