Four Records Decide Whether You Can Defend a Lead Buy Under the TCPA

Four Records Decide Whether You Can Defend a Lead Buy Under the TCPA — Elevarus

Share This Post

Four Records Decide Whether You Can Defend a Lead Buy Under the TCPA

A complaint lands. Someone you called says they never agreed to hear from you, and their lawyer wants $1,500 for that one call. Now the question is simple and it is yours to answer: what can you actually show? Not what the seller promised in the contract. What you can pull up, today, that proves the person on that lead asked to be contacted.

That is the whole job of consent compliance for a lead buyer. You are not the marketer who generated the lead. You are the one who dialed it, and under the Telephone Consumer Protection Act the burden of proving consent sits with the caller. A TrustedForm certificate is part of the answer. It is not the whole answer, and treating it as a magic shield is how buyers get surprised. A defensible buy comes down to four records you can produce on demand, plus a habit of checking them before the dial, not after the complaint.

TL;DR

  • Under the TCPA the burden of proving consent is on you, the caller, not the seller, and each bad call carries statutory damages of $500, or up to $1,500 if it was willful, with no cap on the total.
  • A TrustedForm certificate proves how a form was submitted. It does not, on its own, make a call compliant. ActiveProspect calls it the first step, not the finish line.
  • Four records defend a buy: the disclosure the consumer saw, the certificate that timestamps the moment, an independent behavioral token, and your own pre-dial verification log.
  • The FCC one-to-one consent rule was vacated in January 2025. Do not build your 2026 stack around a rule that no longer exists.
  • Verify the certificate matches the lead before you pay, especially in ping-post, where the cert URL rides along in the post.

Infographic listing the four records that defend a lead buy under the TCPA: the consent disclosure the consumer saw, the TrustedForm certificate timestamp, an independent behavioral token, and the buyer's pre-dial verification log

Quick answers:

What “defensible” actually means when you buy leads

Defensible does not mean the seller said the lead was clean. It means that if a plaintiff’s lawyer asks you to prove consent, you can hand over a record that holds up. The TCPA lets a consumer sue without showing any real harm. The damages are fixed by statute and counted one call at a time: $500 for a basic violation, up to $1,500 if it was knowing or willful, and no ceiling on the total. At $500 a call with no ceiling, a few hundred bad calls is real money fast.

Here is the part buyers miss. The seller generated the lead, but you placed the call. Courts look at who made the contact. So the seller’s word is worth exactly as much as the documentation behind it, and a contract that says “all leads are TCPA compliant” is not documentation. It is a promise you cannot show a judge.

So the test for everything below is the same. Does this record let you reconstruct what the consumer saw and agreed to, on the date it happened? If yes, it counts. If it only describes the lead in the abstract, it does not.

Record one: the disclosure the consumer actually saw

The first record is the consent language itself, exactly as it appeared on the page, with the consumer’s action attached to it. Prior express written consent under the TCPA is not a checkbox theory. The FCC defines it as a signed written agreement, made after a clear and conspicuous disclosure, that authorizes a specific seller to send autodialed or prerecorded marketing calls to a specific number (FCC). In plain terms: the person agreed, in writing, with a date and time, knowing what they were agreeing to.

What makes this record strong is specificity. The disclosure should name the seller or sellers the consumer agreed to hear from. It should sit next to the submit action, not buried in a footer. And it should be captured as the consumer saw it, not retyped later from a template. A disclosure you can only describe is weak. A disclosure you can replay is strong.

Operator Note: Read the actual disclosure on a sample lead before you sign a buying agreement, not after the first dispute. If the seller cannot show you the real page a consumer submitted, you are buying a description of consent, not consent.

Record two: the certificate that timestamps the moment

This is where TrustedForm earns its place. A TrustedForm certificate records the conversion event as it happens: the page source code, an event log of clicks and keystrokes and mouse movement, metadata like IP address and browser and geolocation, a session replay, and the timestamp and URL where the lead was generated (ActiveProspect). It is an independent, immutable record of how that form was filled out. That is genuinely useful in a dispute, because a court can see what the consumer clicked rather than take your word for it.

Two limits matter, and both bite buyers who relax. First, a certificate is not automatic protection. ActiveProspect itself calls the free certificate “the first step toward compliance,” not the finish line. It proves the mechanics of a submission. It does not prove the disclosure language was adequate or that the consent content was valid. Second, retention. A standard TrustedForm certificate is stored for 90 days and then deleted. TrustedForm Retain extends that to five years (ActiveProspect). TCPA claims do not arrive in 90 days. They arrive in years. If you are only holding 90-day certificates, your evidence is gone before the lawsuit shows up.

Key Stat: A buyer pays roughly $0.15 to $0.50 per certificate, and a typical TrustedForm bill of 1,000 leads a month at $0.25 each runs about $3,000 a year (Claim.supply). Set against TCPA defense costs that run from $40,000 into the high six figures, verification is the cheapest line item in the operation.

Record three: the behavioral token that catches what a certificate cannot

The second signal source is behavioral. Jornaya, now LeadiD under Verisk, takes a different cut at the same problem. Instead of replaying one form, it tracks the consumer’s journey across sites and sessions using a token, and it flags patterns: a form filled in under two seconds, the same lead submitted across multiple networks, bot-like behavior (Claim.supply). TrustedForm shows you what happened on the page. Jornaya tells you whether the lead is what it claims to be.

For a buyer, the practical split is clean. TrustedForm is your litigation defense, because it shows the consent moment. Jornaya is your fraud filter, because it catches the resold, recycled, and fabricated. They are not competitors so much as two halves of one check. ActiveProspect acquired Jornaya’s parent in 2024, so increasingly you can run both under one roof.

One warning that applies to both. A token is not proof by existence. Some sellers attach a token that looks like a Jornaya or TrustedForm reference but does not correspond to that lead, or is fabricated outright. The presence of a certificate string is not the same as a certificate that resolves to the exact phone number you are about to call. Which is the entire point of the fourth record.

Record four: the verification you run before you dial

The first three records live on the seller’s side. The fourth is yours, and it is the one most buyers skip. Before you call a lead, pull its consent record, confirm the certificate actually resolves and matches the lead’s contact details, check that the disclosure elements are present, and log that you did it. Then dial. If an element is missing or the certificate does not match, that lead does not get called.

The single check that earns its keep is the cheapest one: does the phone number captured inside the certificate match the number on the lead you were posted? When the two do not line up, you are usually looking at a recycled or resold record, the exact failure a behavioral token is built to flag, and that lead drops out of the dial set before it ever rings. Run it on a sample of any new seller’s leads before you scale the buy, not after the first complaint.

This is the difference between holding evidence and using it. A folder full of certificate URLs you never opened is not a compliance program. A short, timestamped log that says “checked, matched, scrubbed, dialed” is. It also shifts your posture from negligent to diligent, which is the exact line between a $500 violation and a $1,500 willful one.

Two more checks belong in the same pass. Scrub against the Do Not Call list close to the call, not at intake, because a number can land on the list between purchase and dial. And keep the whole bundle for five years, the practical outer edge of how long a TCPA claim can come back at you, the same horizon TrustedForm Retain is built around.

Quick Win: Write the pre-dial check as a hard gate in your routing, not a human habit. No matched certificate, no dial. A gate you cannot forget beats a checklist you can.

Where ping-post timing decides defensibility

If you buy through ping-post, the timing of that fourth record is the whole game. In a ping-post auction the seller pings buyers with a thin version of the lead, buyers bid in well under a second, and the winning bidder gets the full record posted to their endpoint (ClickPoint). That post carries the contact data and the compliance documentation, including the consent timestamp or the TrustedForm certificate URL. The certificate rides along in the post. That is convenient, and it is also a trap if you treat arrival as verification.

The defensible move is to verify on receipt of the post, before you accept and pay, and certainly before you dial. Confirm the certificate resolves and matches the posted phone number in that moment. A buy where you checked the consent record at the instant of purchase is far easier to defend than one where you trusted the field and validated nothing. Speed is the selling point of ping-post. It is not an excuse to skip the check, because the check is automated and runs in the same sub-second window as the auction.

For the deeper mechanics of how the auction and the post actually move a lead, our ping-post lead distribution guide walks the full flow.

The rule you do not have to build around in 2026

Here is where a lot of consent content is quietly out of date, and where buyers waste effort. In December 2023 the FCC adopted a one-to-one consent rule. It would have required consent to name a single seller and be logically and topically tied to the interaction that produced it, which in practice meant a consumer had to consent to each buyer individually. The lead industry spent most of 2024 rebuilding around it.

It never took effect. On January 24, 2025, in Insurance Marketing Coalition v. FCC, the Eleventh Circuit vacated the rule, three days before its January 27 start date, holding the FCC had reached past what the TCPA actually says (Wiley). The FCC then removed the vacated language. So in 2026 there is no federal one-to-one consent mandate. Plenty of guides written in 2024 still say each buyer must be individually named or that blanket “marketing partners” language no longer passes. As a matter of current federal law, that specific rule is not in force.

That does not mean consent got loose. Prior express written consent still applies in full: a clear and conspicuous written disclosure, the consumer’s clear and unmistakable agreement, a signature, a record. Naming the seller in the disclosure is still a sound practice and makes a stronger record. What changed is that you are not legally bound to a one-seller-per-consent structure, and you should not be paying for stack changes sold as compliance with a vacated rule. If you want the buyer-side detail, we keep a current read in the TCPA one-to-one consent checklist.

Operator Note: State law has not stood still even though the federal rule fell. A handful of states run their own mini-TCPA statutes with their own consent and timing rules. Build to the strong record described here and you are positioned for both, without chasing a federal rule that was struck down.

Before the first buy, the vetting is mostly a set of direct questions and a sample. Treat any vague answer as a finding.

What to ask the seller What a good answer looks like
Show me the disclosure a consumer actually saw The real timestamped page, with the consent language and submit action, not a template
What certification rides with each lead TrustedForm or Jornaya, with certificates that resolve and match the lead
How long do you retain consent records Five years, not 90 days
When was this list scrubbed against Do Not Call Within 31 days of contact, ideally fresher
Will you sign audit rights and indemnification Yes to both, in writing

The two non-negotiables are the matching certificate and the audit clause. The certificate is your evidence. The audit right and the indemnification are what let you verify the seller’s claims over time and recover if a warranty turns out to be empty. A seller who balks at either is telling you something. For a closer look at choosing between the two main certificate vendors, our TrustedForm versus Jornaya decision guide lays out the tradeoffs.

How to buy defensible leads from Elevarus

Most lead-buying compliance problems are not legal mysteries. They are operational gaps: certificates that expire before the lawsuit, tokens nobody resolved, a pre-dial check that lives in someone’s head instead of the routing. We build lead programs where the consent record travels with the lead, the certificate is verified to match before the dial, retention runs the full window, and the whole thing is logged so you can answer a TCPA complaint with a file instead of a shrug.

If you are buying leads and you are not sure you could defend a single one of them today, that is the conversation to have. Book a free consultation and we will walk your current stack, find the gaps, and tell you straight what is defensible and what is exposure. For the wider picture of how this fits a full acquisition program, start with our lead generation hub.

Frequently Asked Questions

Does a TrustedForm certificate make my lead buys TCPA compliant?

No. A TrustedForm certificate is strong evidence of how a form was submitted, including the page, the consumer’s actions, and the timestamp. ActiveProspect describes it as the first step toward compliance, not automatic protection. It does not by itself prove the disclosure language was adequate or that you verified and retained the record. Compliance is the full stack: the disclosure the consumer saw, the certificate, an independent fraud signal, and your own pre-dial verification, kept for years.

No. The FCC’s one-to-one consent rule was vacated by the Eleventh Circuit in Insurance Marketing Coalition v. FCC on January 24, 2025, three days before it would have taken effect, and the FCC removed the language. There is no federal one-to-one consent mandate in 2026. Standard prior express written consent still applies, so you still need a clear written disclosure, the consumer’s agreement, and a record. You are simply not bound to a one-seller-per-consent structure under federal law.

What is the difference between TrustedForm and Jornaya?

TrustedForm documents the consent moment with a session replay and page snapshot, which makes it your litigation defense because it shows what the consumer saw and clicked. Jornaya, now LeadiD under Verisk, tracks behavior across sites and sessions and flags fraud signals like sub-two-second form fills and leads resold across networks. One proves the moment, the other tests whether the lead is real. Many buyers run TrustedForm as the baseline and add Jornaya at higher volume or in high-fraud verticals.

When should I verify the consent certificate in a ping-post buy?

On receipt of the post, before you accept and pay, and before you dial. In ping-post the certificate URL is delivered in the winning post alongside the contact data. The convenience tempts buyers to trust the field without checking it. Confirm the certificate resolves and matches the posted phone number in that same sub-second window. A buy verified at the moment of purchase is far easier to defend than one validated never.

Plan for five years, not 90 days. A standard TrustedForm certificate is stored for 90 days and then deleted, while TrustedForm Retain extends storage to five years. TCPA claims often arrive long after the call, so 90-day retention usually means your evidence is gone before any dispute lands. Keep the full bundle, the disclosure, the certificate, and your verification log, for the practical outer edge of the limitations window.

What should I ask a lead seller before the first buy?

Ask to see the actual disclosure a consumer submitted, what certification rides with each lead, how long they retain records, when the list was last scrubbed against Do Not Call, and whether they will sign audit rights and indemnification. Good answers are concrete: a real timestamped page, certificates that resolve and match, five-year retention, a scrub within 31 days, and yes to audit and indemnity in writing. Vague answers on any of these are a finding, not a detail.



Work with Elevarus

Are You Ready to Grow With a Proven Lead Generation & Performance Marketing Agency?

Get a free, no-pressure strategy call with our lead-generation team. We'll map the fastest path to more qualified leads for your business.

Book a free call →

Ready to put this into action?

Picture of SHANE MCINTYRE

SHANE MCINTYRE

Founder & Executive with a Background in Marketing and Technology | Director of Growth Marketing.