Regulatory Guides
Rules Your Firm Needs to Know
SEC Rule 17a-4
Retention periods, WORM storage, and what the rule actually requires in practice. The foundation of books-and-records compliance.
SEC · Books & Records
Read guide →
SEC Rule 17a-3
17a-3 is where the capture obligation comes from. Most firms focus on storage and skip this rule. Here's what broker-dealers need to know.
SEC · Books & Records
Read guide →
FINRA Rule 4511: Books and Records
What broker-dealers must create and preserve, and how FINRA examines for recordkeeping failures.
FINRA · Books & Records
Read guide →
FINRA Rule 3110: Supervision
Supervisory obligations for communications review, WSP requirements, off-channel messaging, and 2026 updates.
FINRA · Supervision
Read guide →
FINRA Off-Channel Enforcement
Over $2 billion in penalties since 2021. What FINRA examiners look for and what firms that got fined had in common.
FINRA · Enforcement
Read guide →
Exam-Ready Checklist
A practical checklist for RIAs and broker-dealers preparing for SEC or FINRA examination — archive readiness, WSPs, supervision documentation.
Exam Prep · SEC · FINRA
View checklist →
Compliance Guides
Practical Guides for Your Team
Off-Channel Communications Compliance
What off-channel means, why regulators care, and how to build a defensible program — personal devices, WhatsApp, Signal, and iMessage.
Off-Channel · Policy
Read guide →
BYOD Messaging Compliance
How to handle personal device use in regulated environments — policies, capture strategies, and what firms get wrong.
BYOD · Policy
Read guide →
Off-Channel Compliance for RIAs
Investment advisers face the same off-channel obligations as broker-dealers. What RIAs must capture, retain, and produce under SEC Rule 204-2.
RIA · SEC Rule 204-2
Read guide →
AI
When AI Use Becomes a Business Record
Are LLM tool calls business records?
What a tool call is, why it is the strongest signal of regulated activity in an AI session, and what an examiner is likely to ask for.
AI · Books & Records
Read guide →
Are ChatGPT conversations business records?
When a ChatGPT session is a business record, what current vendor capture covers, and what is missing.
AI · Books & Records
Read guide →
How Comma Works
Technical & Architecture Resources
WORM Storage & SEC Rule 17a-4
What WORM actually means, why it matters, and how Comma's archive satisfies the immutable storage requirements of SEC Rule 17a-4.
Architecture · Compliance
Read deep-dive →
Open-Source Capture Architecture
Why Comma published its WhatsApp and Signal connectors on GitHub — and what that means for trust, auditability, and compliance.
Open Source · Architecture
Read deep-dive →
Insights
Recent Analysis & Enforcement Coverage
FINRA May 2025 Enforcement Actions
A breakdown of FINRA's May 2025 disciplinary actions — false attestations, social media violations, and what they signal for exam priorities.
FINRA · Enforcement · 2025
Read post →
SEC 2026 Examination Priorities
What the SEC's 2026 exam priorities mean for your firm's communications compliance program.
SEC · Exam Priorities
Read post →
The TeleMessage Breach Timeline
What happened when TeleMessage was breached — and what it reveals about the risks of modified-app capture architecture.
Security · Architecture
Read post →
Off-Channel Compliance Crisis
How the SEC and FINRA off-channel enforcement wave changed what firms must do to stay compliant.
Off-Channel · Enforcement
Read post →
FINRA Regulatory Notice 25-07
FINRA's latest regulatory notice and what it means for your supervision and recordkeeping obligations.
FINRA · Regulatory Notice
Read post →
Why We Open-Sourced Our Capture Code
The case for transparency in compliance infrastructure — and why auditability matters more than promises.
Open Source · Architecture
Read post →
Vendor Comparisons
How Comma Stacks Up
Smarsh Alternative
Per-connector pricing adds up fast, and iMessage isn't captured off-device. Comma covers 35+ channels at a flat fee.
Enterprise · Legacy
See comparison →
Global Relay Alternative
Built for email-first firms. WhatsApp, Signal, and iMessage rely on third-party connectors. Comma captures all three at the point of delivery.
Enterprise · Legacy
See comparison →
Microsoft Purview Alternative
No iMessage connector. WhatsApp and Signal sync once per day. Comma captures all three in real time.
M365-native · Enterprise
See comparison →
View All Comparisons
TeleMessage, LeapXpert, Theta Lake, Proofpoint, SteelEye, and more — the full vendor comparison library.
All Vendors
View all →
Documentation
Help Docs & Setup Guides
Getting Started
Connect WhatsApp, Signal, iMessage, Microsoft Teams, and other channels. Step-by-step setup guides for admins and individual users.
Setup · Integrations
View docs →
API Reference
REST API documentation for integrating Comma Compliance into your existing systems — authentication, endpoints, and request examples.
API · Developer
View docs →
See Comma in action.
A 20-minute walkthrough — real capture, real-time flagging, real transparency.