Tenant isolation in the database
Every table carries a tenant and Postgres row level security enforces it, so one customer cannot read another even if application code has a bug.
Security, residency and models
How we protect your data, where it can live and which models can run it.
Security practice
The controls that matter most to a regulated operator, and why each one matters.
Every table carries a tenant and Postgres row level security enforces it, so one customer cannot read another even if application code has a bug.
Every governed action appends to a ledger per tenant. Each entry carries the hash of the one before, so changing the past breaks the chain and verification says where.
Keys and credentials live in the secret store of the hosting platform, never in the repository. A leaked copy of the code carries no access.
People and services get only the roles their job needs. Agents may call only the tools their profile allows, and anything not marked as a read is treated as a write.
If a check cannot run, the action stops. No approval means no action, so an outage never turns into an unreviewed write.
Writes and escalations wait for a named person who can approve, modify and approve, take over or reject. The decision and the reason are recorded.
Stop one agent, a workspace or the whole estate at once. Every change needs a reason and is recorded.
Checks run after every generation step, and before a call Spine checks contact windows, do not call lists, consent, disputes and jurisdiction rules.
Data residency
Pick where Spine runs. Records, evidence and audit stay in that region.
Spine can be deployed in the cloud region you choose, so records, evidence and the audit ledger live there. Voice AI runs today on Google Cloud in Mumbai for India.
Spine ships as containers with its state in Postgres, so it is designed to run inside a cloud account you control when policy requires it.
Whichever option you pick, each tenant is isolated in the database and has its own audit chain.
Model choice
Agents talk to a model router, not to one vendor. That keeps you in control of cost, quality and where inference runs.
A per tenant policy decides which models an agent may use, with fallback chains when one is slow or down.
Run open weight models in your region when data must not leave it. Voice AI is designed for sub-second turns on open weight models.
The router records what each decision cost, so you can compare models on your own traffic before you switch.
Responsible AI
Principles only count when software holds you to them. These are built into how Spine runs.
A named person decides every write and the reason is kept. AI proposes, people decide.
If it is not on the ledger, it did not happen. Every step can be traced after the fact.
Evals and readiness checks gate a new agent version. One that fails is held back to assisted mode.
Agents hand over to a person when a conversation needs judgement, care or a decision they may not make.
Security contact
Questionnaires, architecture reviews and vulnerability reports all go to one inbox read by the team that builds Spine.
Email hello@billgosling.ai with the subject "Security question" and as much detail as you can share. Please give us time to fix an issue before you publish it.
Ask us. The Compliance Center builds evidence packs for auditors, drawn from the platform itself, and we can walk your team through one on a demo tenant.
Yes. The model router follows a policy per tenant, so you decide which models an agent may call, in which order and in which region. Open weight models can run where your data lives.
We will walk through the ledger, the approval gates and the kill switch on a demo tenant.