Twilio
Messaging is the sub-processor question people forget: a number in one country, a carrier in another, and message bodies crossing both. Urengi reads the account's numbers and regions so the routing shows up in the review.
- Category
- Cloud & security
- Auth method
- API key and secret
- Direction
- Read-only
- Sync frequency
- Daily
- Scopes requested
- 3
- Available on
- Growth and Enterprise
- Maintained by
- Urengi
What the Twilio integration does
Three reads about where your messages actually go.
Numbers and their regions
Each number is recorded with its country and the region handling it, which is what a data-residency clause is actually about.
Sub-accounts are separate vendors
A sub-account used by another team is its own processing relationship, and it is reviewed as one rather than folded into the parent.
Retention settings as evidence
Whether message bodies are retained, and for how long, lands on the review as a recorded control.
Exactly what Urengi can see
Three read-only scopes on the account you connect. Message bodies are never read.
Urengi reads
- Phone numbers, countries and regions
- Sub-account names and status
- Message retention settings
Urengi writes
- Nothing — this connection is read-only
Urengi never touches
- Message bodies or recipient numbers
- Call recordings or transcripts
- Billing details or payment methods
- Anything after you revoke the key
Connect it in four steps
One authorisation, one field mapping, and a test sync you run yourself.
01
Authorise the connection
Open Twilio from this page and approve the scopes listed above — OAuth in a browser tab, or a scoped API key you paste. An admin approves them once.
02
Choose what syncs
Pick the projects, spaces or accounts Urengi should watch. Narrow is fine to start with; widening it later does not re-authorise anything.
03
Map your fields
Match owners, cost centres and tiers to what Urengi already tracks. Defaults arrive pre-filled from the first sync, so most teams change nothing.
04
Run a test sync
Pull one record and check it landed on the right review. The audit entry confirms the mapping before a real vendor is touched.
Your token, your rules.
Urengi stores the Twilio token encrypted at rest under a per-tenant key and never replays it outside the scopes you approved. Revoke the app in Twilio and every Urengi write stops within seconds — the audit log keeps the history, the connection simply ends.
Read the security statement- SOC 2 Type II
- audited annually
- Per-tenant keys
- no shared secrets
- Revocable in Twilio
- one click, no ticket
- EU or US residency
- chosen at signup