Anvex is a neutral registry for A2P messaging in France. A brand proves who it is, Anvex issues a cryptographic sender credential, and the operator checks it in real time as each message arrives.
The registry confirms who is sending, not what is being sent
Operators check it in real time, inside the delivery path
Recipients see a verified indicator on messages that pass
For mobile operators, brands that message customers, and public bodies.
Registry monitorIllustrative
BrandRegistryOperatorRecipient
Sender IDBANQUE-EXEMPL
CredentialValid issued 2027-03-14
Registry queryMatch 8 ms
VerdictVerified sender
Last check — 16:42:07Stage 1 · Trust indicators
0Cyber incident assistance requests, France, 2024, all categories
0Growth in requests year over year
0Phishing assistance requests alone
0A2P messages a year across French operators
Sources: Cybermalveillance.gouv.fr, Rapport d'activité 2024, March 2025; Anvex estimate from the combined A2P traffic of the French national operators.
The gap
Sender identity in business messaging is self-declared.
SMS and RCS carry no cryptographic proof of who sent a message. Any party with network access can present itself as a bank, an operator or a public body. Existing defences analyse content once delivery has begun. None of them verifies the sender before it.
In 2024 the French national platform cybermalveillance.gouv.fr handled more than 420,000 assistance requests across all categories of cyber incident, up 49.9% year over year. Phishing remained the dominant threat, accounting for 33.7% of consumer assistance requests and 64,000 assistance requests on its own.
SMS
The sender ID is a text string the sender configures. Nothing in the protocol requires proof of identity.
Any party with network access can present itself as a bank, an operator or a public body.
RCS
Richer messages, same question at delivery: no neutral registry that the operator queries before the message lands.
A brand's verified identity does not follow it from one channel to the other.
Existing defences
SMS firewalls analyse content and traffic patterns and act once a pattern is known.
None of them verifies the sender before delivery. Sender ID blindness is the gap.
How it works
Four steps. One credential.
An SSL certificate for SMS and RCS: a neutral registry, a cryptographic credential and a visible sign of authenticity. Operators become the browsers, the registry becomes the certificate authority, and verified sender status becomes the padlock.
1
A brand registers its legal entity, domain ownership and sender IDs
Verification covers legal status through official registry records, control of the domains tied to the brand, and the right to use each requested sender ID, with trademark validation where applicable.
2
Anvex verifies that identity and issues a cryptographic sender credential
The verification team checks submissions against public records and third-party data sources. The credential attests the identity in the registry and links it to the brand's messaging traffic. Annual re-verification and continuous monitoring keep it valid.
3
The operator queries the registry in real time as each message arrives
The query carries the claimed sender ID and returns one of three answers: verified with the organisation identity, unverified, or unknown. Sub-second responses keep the check inside the delivery path.
4
The consumer receives the message with a trust indicator confirming authenticity
Verified senders appear with a trust indicator. How it is displayed varies by operator and device. Anvex supplies the verification data; the operator decides the presentation and the enforcement stage.
Delivery path
BrandRegistryOperatorRecipient
The brand submits evidence through the portal.
Enforcement
Enforcement grows with registry coverage.
Operators move through four stages at their own pace. Early stages change what recipients see. Later stages change what gets delivered. Nothing is blocked until coverage justifies it.
Verified and unverified status shown to recipients, no traffic blocked
Initial deployments display verification status without touching delivery. Verified senders appear with a trust indicator, unverified senders without. Brands gain a reason to verify, and legitimate messaging continues as before.
Warnings on unverified senders claiming high-risk brand names
As coverage expands, operators can warn recipients when an unverified sender uses a high-risk brand name, such as a bank or a government agency. The message still arrives. The recipient sees that the identity behind it is not verified.
Messages claiming verified brand identities without valid credentials are blocked
With sufficient coverage, operators block messages that claim a verified brand identity without a valid credential. The legitimate sender holds the credential. The impersonator does not.
Verification required for all A2P traffic
Mature deployment moves toward verification for all A2P traffic, with unverified messages blocked or quarantined. This stage depends on industry coordination and regulatory support.
Registry coverage each stage builds onIllustrative
InitialExpandingSufficientComprehensive
Check a sender ID
What the registry answers.
Type a sender ID or pick a sample, choose the operator's enforcement stage, and read the registry's answer alongside what the recipient would see.
Sender checkSample data
Demonstration only, sample data. Every sender ID and organisation shown here is fictional.
Ten billion messages a year. One query per message.
The registry is sized for the whole French A2P channel, inside the delivery path, within the latency budget of message delivery.
Who it is for
One registry, three ways in.
Real-time verification for operators, verified identity for brands, and audit and compliance services that start before the registry does.
Operators
Verification inside the delivery path
Grey-route exposure, NIS2 readiness and impersonation complaints handled with one registry answer per message.
A2P revenue. Grey routes carry traffic around official channels. Verification exposes the senders behind it and gives the operator grounds to act.
NIS2 readiness. A sender verification mechanism is evidence of proactive measures in the A2P channel, which NIS2 asks essential entities to demonstrate.
Support load. Impersonation complaints stop being investigations. The registry answer states whether the sender was who it claimed to be.
Grey-route exposure, illustrative
million messages
percent
Messages outside verified control
0a month
0a day
0a year
Arithmetic on your two inputs, not a forecast or a revenue estimate. Industry estimates place grey-route share between 25% and nearly 50% of A2P traffic globally.
For brands
Customer protection. A verified identity separates the brand's messages from every attempt to imitate them, before the customer has to judge. Trust indicator. Every message from a registered sender ID carries a visible sign of authenticity on participating operators. Compliance. Verified status documents who is authorised to use each sender ID.
Tier
Message volume
Sender IDs
Who it suits
Pricing
Starter
Up to 100K messages a year
Up to 3 sender IDs
For organisations that send transactional messages from one or two sender IDs and want a verified identity from the first message.
Tiers by annual message volume and number of sender IDs. Pricing on request.
Audit and compliance
Two services that produce value before the registry does. Engagements range from EUR 15,000 to EUR 75,000, depending on scope and operator size.
A2P route auditing
EUR 25,000 to EUR 75,000 per engagement, 4 to 12 weeks
An audit shows how messaging traffic flows through the operator's network: grey routes that bypass official channels, the brands most often impersonated, and the split between legitimate and unauthorised pathways. Deliverables are a traffic analysis report, grey-route identification, fraud pattern documentation and recommendations.
NIS2 compliance assessments
EUR 15,000 to EUR 35,000 per assessment, 3 to 6 weeks
A gap assessment of the A2P channel against NIS2 requirements and the ANSSI Référentiel Cyber France, with a remediation roadmap, policy documentation and audit preparation support. Implementation support is scoped and priced separately.
NIS2 in France · where transposition stands
January 2023
NIS2 Directive enters into force across the EU
October 2024
Deadline for Member States to transpose NIS2 into national law
12 March 2025
Loi Résilience adopted by the Sénat at first reading
September 2025
Text amended by the Assemblée nationale special commission
March 2026
ANSSI publishes the Référentiel Cyber France as the working technical baseline
July 2026
European Commission refers France to the Court of Justice of the EU over the delay
Pending
Floor vote in the Assemblée nationale, not yet scheduled
Sources: Directive (EU) 2022/2555; Sénat, first reading of the Loi Résilience, 12 March 2025; ANSSI, Référentiel Cyber France, working document v2.5, March 2026; European Commission, referral of France to the Court of Justice of the EU, July 2026.
Why France
The launch market was ready before the registry.
Operator readiness
France was the first country where all four mobile operators deployed external API infrastructure through GSMA Open Gateway, in December 2024.
Regulatory timing
France has not completed NIS2 transposition; the European Commission referred the case to the Court of Justice of the EU in July 2026. ANSSI published the Référentiel Cyber France in March 2026 as the working technical baseline.
Market growth
French A2P grows 6.7% a year, the fastest of the five largest European markets.
Consolidation
In June 2026 Bouygues Telecom, Orange and Free-iliad signed a memorandum of understanding to acquire the assets of SFR. The transaction requires regulatory approval and could close in the second half of 2027. The registry's operator model runs on query volume, not operator count.
Sources: GSMA, December 2024; European Commission, July 2026; ANSSI, March 2026; Grand View Research and Market Research Future, 2025; Orange press release, June 2026.
GSMA Open Gateway network APIs deployed by all four national operators, December 2024.
Founders
Built by people who ran the networks.
45 years of combined experience in telecommunications operations, fraud prevention and regulatory compliance.
Yusufzada Nariman
Chief Executive Officer
25 years in telecommunications, including 21 years inside mobile operators at Bakcell and Azerconnect, leading roaming and carrier services and integrating more than 250 international operators. Since 2021 in A2P route auditing and fraud detection; Chief Executive Officer of TelcoGuard AG.
20 years in telecommunications law, data protection and cybersecurity compliance across Russian and Turkish markets, with advisory work on European regulatory frameworks. Legal counsel at VolgaTelecom, Pepeliaev Group, MegaFon and Turkcell; independent compliance practice since 2021.
Public milestones. Anvex is in its pre-launch phase; incorporation follows La French Tech Visa approval.
2026
Pre-launch. La French Tech Visa application, French Tech ecosystem partnerships, first conversations with French operators, and technical architecture design for the registry.
2027
Incorporation in France in Q1 2027. First audit engagements. Platform beta. First operator API pilot.
2028
Commercial registry launch. First operator integration in production.
2029
Two operators live, network effects compounding.
2030
National operator coverage.
Questions
What operators and brands ask first.
Firewalls inspect message content and traffic patterns and act once a pattern is known. Anvex answers a different question before delivery: is this sender who it claims to be. The two work side by side. The registry supplies the identity signal that content analysis cannot produce.
That depends on the operator's enforcement stage. At the first stage nothing is blocked; unverified senders appear without a trust indicator. Warnings follow for unverified senders that use high-risk brand names. Selective blocking applies to messages that claim a verified brand identity without a valid credential. Comprehensive enforcement, verification for all A2P traffic, depends on industry coordination and regulatory support.
In France, on SecNumCloud-eligible infrastructure, under GDPR. Verification data is not replicated to systems outside the EU.
It depends on the completeness of the evidence. Anvex checks the legal entity against official registry records, confirms domain ownership and confirms the right to use each sender ID. Brands receive a checklist upfront, and most delays come from missing documents. Verified status is renewed annually, with continuous monitoring in between.
Anvex is designed to be compatible with the GSMA Open Gateway APIs that all four French operators deployed in December 2024. The operator integration follows the same patterns, so operators use the technical architecture and commercial frameworks they already have for external APIs.
The registry covers both SMS and RCS. RCS includes native sender verification features, which confirms the direction of the market. Anvex extends a single verified identity across both channels, so a brand's trust indicator follows its messages whichever channel delivers them.
In June 2026 Bouygues Telecom, Orange and Free-iliad signed a memorandum of understanding to acquire the assets of SFR. The transaction requires regulatory approval and could close in the second half of 2027. The registry's operator model is driven by query volume, not operator count: the same traffic is served through fewer integrations, which shortens the path to full national coverage.
The commercial registry launch is planned for 2028, with the first operator integration in production. 2027 covers incorporation, the first audit engagements, the platform beta and the first operator API pilot.
Contact
Start the conversation.
For operators, brands, public bodies, press and partners. Say who you are and what you want to check.
Anvex is raising a pre-seed round and the round is open. Request the investor materials through the form with the subject Investor enquiry, and the founders will follow up directly.