End-User Messaging Technologies
End-user messaging technologies are services and systems that deliver messages to individuals through channels such as SMS text, MMS, voice, push notifications, and third-party apps like WhatsApp. Businesses use them to send notifications, one-time passcodes, and other communications to customers. As delivery channels, they carry information but are not themselves security or data-protection controls.
End-user messaging technologies are managed communications platforms and APIs that enable applications to send and deliver messages across channels including SMS, MMS, voice, push, and over-the-top messaging apps (for example, WhatsApp). AWS End User Messaging is one such service, providing scalable delivery, message feedback, and monitoring capabilities (including for one-time-passcode delivery and conversion tracking). In payment security contexts, these channels are frequently used to deliver transaction alerts, one-time passcodes (OTPs), and step-up authentication prompts, but they are transport/delivery mechanisms rather than authentication or data-protection mechanisms in themselves. Their security posture depends on how they are configured, what data traverses them, and the controls applied at each hop. Under PCI DSS, sensitive authentication data (full track data, CAV2/CVC2/CVV2/CID, PINs and PIN blocks) must not be stored after authorization; PCI DSS does not categorically prohibit transmitting cardholder data or SAD where such transmission is necessary and properly protected, so any messaging channel handling such data must apply appropriate protection and would fall within PCI DSS scope. Confirm applicable requirements against the current published PCI DSS standard, as numbering and wording differ between versions.
Why it matters
End-user messaging technologies have become a common delivery layer for payment-related communications: transaction alerts, fraud notifications, one-time passcodes, and step-up authentication prompts often reach customers via SMS, voice, push, or over-the-top apps like WhatsApp. Because these channels touch the customer at moments that matter for fraud detection and authentication, teams sometimes treat them as if they were security controls in their own right. They are not. They are transport and delivery mechanisms, and their contribution to a security outcome depends entirely on what data traverses them and how each hop is configured and protected.
This distinction matters for scoping and risk assessment. A messaging channel that carries only a non-reusable OTP or a generic alert presents a different risk profile than one configured to carry cardholder data or sensitive authentication data. Under PCI DSS, sensitive authentication data (full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks) must not be stored after authorization. PCI DSS does not categorically prohibit transmitting cardholder data or SAD where such transmission is necessary and properly protected, so any messaging channel handling such data must apply appropriate protection and would fall within PCI DSS scope. Confirm applicable requirements against the current published PCI DSS standard, as numbering and wording differ between versions.
Treating messaging delivery as a self-contained safeguard can also lead teams to overestimate the assurance provided by, for example, an SMS-delivered OTP. SMS and similar channels are subject to delivery failures, interception risks, and social-engineering attacks that target the recipient rather than the channel. Message feedback and delivery monitoring can help teams observe OTP delivery and conversion, but delivery visibility is an operational metric and is not, by itself, an authentication or data-protection control.
Who it's relevant to
Inside End-User Messaging Technologies
Common questions
Answers to the questions practitioners most commonly ask about End-User Messaging Technologies.