Glossary · Cloud infrastructure

CPaaS (Communications Platform as a Service)

Cloud-based platform providing developer APIs for SMS, voice calls, verification codes, email, video, and messaging (WhatsApp Business, RCS). CPaaS providers hold sensitive customer communication data — phone numbers, message content, verification codes — making vendor jurisdiction structurally important.

## What CPaaS covers Communications Platform as a Service (CPaaS) is the API layer that sits between an application and telecommunications infrastructure. A developer calls a REST endpoint or SDK method; the CPaaS provider routes the resulting SMS, voice call, verification code, email, WhatsApp message, or RCS message through mobile operators, carriers, and messaging platforms. The category has consolidated around a few large vendors — **Twilio** (US, Nasdaq), **Sinch** (Sweden, Nasdaq Stockholm), **Infobip** (Croatia), **Vonage** (US, owned by Ericsson SE), **Bird / formerly MessageBird** (Netherlands, US private-equity owned), and **Amazon Connect / AWS End User Messaging** (US) — with a broader ecosystem of specialised players. ## Why CPaaS is a sovereignty question CPaaS providers hold what is arguably the most sensitive routine communications-data category: - Phone numbers of every customer receiving verification codes, receipts, notifications - Contents of messages (SMS/WhatsApp) that carry order confirmations, health-appointment reminders, KYC verification codes, banking one-time passwords - Metadata: who received what, when, from which sender ID, with what delivery status - For email: message bodies, tracking pixels, engagement telemetry - For voice: call metadata, and increasingly transcripts when conversational-AI features are enabled Under EU law, these are personal data under GDPR and — for messages themselves — additionally protected under the ePrivacy Regulation. Under US law, a US-incorporated CPaaS provider is subject to the CLOUD Act, FISA Section 702, and National Security Letters. ## The jurisdiction question in practice A European company using Twilio for SMS OTPs and Twilio SendGrid for transactional email is routing a genuinely sensitive telemetry stream through Twilio Inc. — a Delaware corporation. US authorities can compel Twilio to disclose data it holds, including data belonging to European customers hosted in Twilio's EU regions. Structurally, only a CPaaS provider with no US parent removes that exposure. In practical 2026 terms, the credible European options are: - **Sinch** — Stockholm, Sweden. Nasdaq Stockholm-listed (SINCH). 4000+ employees. Includes Mailgun and Mailjet (email) inside the same corporate group. Structurally the closest direct Twilio replacement. - **Infobip** — Vodnjan, Croatia. Private, EU-controlled. Comparable global operator coverage. Strong in enterprise messaging. Both operate EU data-residency by default; both are structurally EU-jurisdiction at the parent level. ## What CPaaS excludes CPaaS is distinct from: - **Contact-centre-as-a-service (CCaaS)** — voice-centric agent-facing platforms (Genesys, Talkdesk). CPaaS provides the APIs; CCaaS provides the agent UX. - **Meetings / video-conferencing** — Zoom, Google Meet, Teams. These are meeting-first products, not developer APIs. - **Marketing email platforms** — Mailchimp, GetResponse, Brevo. These handle broadcast newsletters; CPaaS handles per-user transactional messages. The line blurs when CPaaS providers acquire adjacent capabilities — Sinch acquired Mailgun and Mailjet, Twilio acquired SendGrid — but the developer-API-first framing remains the CPaaS category anchor. ## Regulatory pressure in 2026 Three regulatory trends make CPaaS sovereignty more material: 1. **PSD3 and the Payment Services Directive review** — SCA (Strong Customer Authentication) flows delivered via SMS OTP or silent network authentication place messaging providers directly in the payments-regulated flow. 2. **NIS2 essential entities** are now asking direct questions about the jurisdiction of critical customer-communications vendors. 3. **AI Act processing chains** — as voice, SMS, and email are increasingly processed by conversational-AI layers, the AI-Act obligations on high-risk processing propagate to the CPaaS layer. For European organisations reviewing their vendor stack under any of these regimes, CPaaS is not a background utility — it is a category worth explicit sovereignty scrutiny.
← Back to glossary