Skip to content

Security, residency and models

Trust Center

How we protect your data, where it can live and which models can run it.

Illustration. Sample events. Each row stores the hash of the row before it.

Security practice

Security in plain words.

The controls that matter most to a regulated operator, and why each one matters.

  • Tenant isolation in the database

    Every table carries a tenant and Postgres row level security enforces it, so one customer cannot read another even if application code has a bug.

  • Hash-chained audit

    Every governed action appends to a ledger per tenant. Each entry carries the hash of the one before, so changing the past breaks the chain and verification says where.

  • Secrets never in code

    Keys and credentials live in the secret store of the hosting platform, never in the repository. A leaked copy of the code carries no access.

  • Least privilege roles

    People and services get only the roles their job needs. Agents may call only the tools their profile allows, and anything not marked as a read is treated as a write.

  • Gates that fail closed

    If a check cannot run, the action stops. No approval means no action, so an outage never turns into an unreviewed write.

  • Human approval for writes

    Writes and escalations wait for a named person who can approve, modify and approve, take over or reject. The decision and the reason are recorded.

  • Kill switch

    Stop one agent, a workspace or the whole estate at once. Every change needs a reason and is recorded.

  • Guardrails on every step

    Checks run after every generation step, and before a call Spine checks contact windows, do not call lists, consent, disputes and jurisdiction rules.

Data residency

Your data stays where your regulator expects it.

Pick where Spine runs. Records, evidence and audit stay in that region.

  • In the region you choose

    Spine can be deployed in the cloud region you choose, so records, evidence and the audit ledger live there. Voice AI runs today on Google Cloud in Mumbai for India.

  • In your own cloud account

    Spine ships as containers with its state in Postgres, so it is designed to run inside a cloud account you control when policy requires it.

  • Separated per tenant

    Whichever option you pick, each tenant is isolated in the database and has its own audit chain.

USCanadaIndiaUK and EU

Model choice

Swap models without rewriting agents.

Agents talk to a model router, not to one vendor. That keeps you in control of cost, quality and where inference runs.

  • Your models, your policy

    A per tenant policy decides which models an agent may use, with fallback chains when one is slow or down.

  • Open weights supported

    Run open weight models in your region when data must not leave it. Voice AI is designed for sub-second turns on open weight models.

  • Cost per decision

    The router records what each decision cost, so you can compare models on your own traffic before you switch.

Responsible AI

The principles the platform enforces.

Principles only count when software holds you to them. These are built into how Spine runs.

  • People stay accountable

    A named person decides every write and the reason is kept. AI proposes, people decide.

  • Everything is provable

    If it is not on the ledger, it did not happen. Every step can be traced after the fact.

  • Tested before it goes live

    Evals and readiness checks gate a new agent version. One that fails is held back to assisted mode.

  • Hand over when it should

    Agents hand over to a person when a conversation needs judgement, care or a decision they may not make.

Security contact

Talk to us about security.

Questionnaires, architecture reviews and vulnerability reports all go to one inbox read by the team that builds Spine.

Bring your security team to the demo.

We will walk through the ledger, the approval gates and the kill switch on a demo tenant.