
The off-channel enforcement wave has not slowed down. In the first two months of 2026 alone, FINRA issued actions against multiple firms for failing to capture and preserve business-related text messages, personal emails, and encrypted messaging app communications. Fines ranged from $10,000 for individual representatives to $750,000 for a single firm. One firm’s violation was made worse by the fact that a senior executive was among those using unapproved messaging apps.
In one case, a broker was barred entirely, his termination notice citing off-channel communications violations as the triggering event. In another, a firm’s supervisors were personally copied on business-related emails sent from representatives’ personal accounts, yet no one acted on it. In a third, a firm with prior regulatory warnings, a consultant’s review, and updated written procedures still ended up fined because its senior leadership was among those sending thousands of unarchived text messages.
The Regulation Requires Capture, Not Just Prohibition
Under SEC Rule 17a-4 and FINRA Rule 4511, broker-dealers must preserve all business-related electronic communications in a tamper-protected format for a minimum of three years (six years for most records, with the first two immediately accessible).
The off-channel communications enforcement pattern has been consistent since 2022: regulators do not penalize the use of WhatsApp. They penalize the failure to capture it.
Why Most Approaches Fall Short
There are three common approaches from legacy vendors when firms start looking to solve this.
Mobile Device Management (MDM) profiles. The compliance vendor installs a profile on the employee’s phone that gives the firm visibility into device activity. This works, technically. But it requires employee cooperation with intrusive device enrollment, creates friction in BYOD environments, and raises legitimate employee privacy concerns. Adoption shortfalls are common, creating the very coverage issues regulators identify during exams.
Endpoint agents or modified apps. Some vendors require employees to use a compliance-wrapped version of WhatsApp or install a local agent that monitors messaging activity. Employees often resist, circumvent, or simply forget. The firm ends up with partial capture that looks complete on paper.
iCloud or device backup sync. Pulling from scheduled backups means there is always a window of exposure. If an employee deletes a message before the next sync, it is gone. Edited messages may not be captured with their original text. Disappearing message timers, a common feature on consumer apps, create additional lapses.
All three approaches share a structural vulnerability: they depend on something installed on, or synchronized through, the employee’s device. Any break in that chain is a compliance failure.
How Comma Captures WhatsApp
Comma’s architecture for WhatsApp capture does not rely on MDM profiles, endpoint agents, or device backups. Instead, messages are archived in real time through an off-device, account-level connection.
Here’s how it works:
Account-level connection. The employee connects their WhatsApp account to Comma through their firm’s compliance dashboard. This is account-level authorization, not device enrollment. No app is installed. No profile is pushed to the phone. The connection remains active even if the employee changes devices.
Point-of-delivery capture. When a message is sent or received, it is delivered simultaneously to the employee’s phone and to Comma’s secure capture endpoint. This happens in real time, before any local action (deletion, editing, disappearing timer) can affect the record. The compliance archive receives the message the moment it exists.
Business contact filtering. Not everything on an employee’s phone is a business communication. Comma uses smart contact filtering to archive only conversations with designated business contacts, leaving personal threads untouched. This is how firms meet their capture obligations without creating legal exposure around employee personal data.
Full fidelity. Comma preserves message text, attachments, timestamps, sender and recipient data, and edit or deletion events. If an employee edits a message or a counterparty deletes their side of a conversation, the original version and the change record are both retained.
Open-source connectors. Comma’s WhatsApp and Signal capture connectors are published on GitHub under an open-source license. Firms can review the exact code before deployment. There is no black box.
Once captured, all data routes to a WORM-compliant archive with a default seven-year retention period, exceeding the standard six-year SEC and FINRA requirement. Records are fully indexed and searchable by keyword, contact, date range, and channel.
A Note on Channel Coverage
The off-device, no-agent architecture described above applies to WhatsApp, Signal, and iMessage. These platforms capture via account-level authorization at the delivery layer.
SMS and RCS capture work differently, as these protocols are device-native and require a different integration path. If your firm needs to capture standard text messages or RCS, that is worth discussing separately, as the technical approach varies by device platform and carrier.
What This Means for Exam Readiness
FINRA examiners increasingly ask for evidence that firms have not just policies, but working capture systems. They request message-level records, want to see coverage across platforms, and identify inconsistencies between what the WSP says and what the archive actually contains.
Comma’s architecture provides complete record capture for the channels it supports. Because messages are archived independently of the employee’s device, recordkeeping does not depend on device enrollment, local software, employee behavior, or scheduled backups. Firms can produce complete, searchable records for any covered conversation on demand in an exam-ready format.
Recent FINRA enforcement actions make the consequences of incomplete recordkeeping clear. A firm fined $750,000 for text messages, a broker barred for off-channel violations, a firm whose supervisors were personally aware of the problem and did not act. In each case, the underlying issue was not a policy. It was the absence of a system that actually worked.

