Trust and governance

The AI can talk freely. It cannot move money on its own.

We built Spine for collections and lending, where one wrong sentence has legal consequences. Conversation runs at machine speed, every consequential action stops for a policy check or a named person, and every decision lands on a tamper-evident record your auditors can check.

spine·voice · governance
redaction on · chain ok
VoiceAI · Card paymentlive
consent · dnc ✓ · contact window ✓
Agent

Before we go on, I’m an AI assistant and this call is recorded. Can I confirm your date of birth?

Customer

Sure. And my card is [redacted].

redaction · card number removed from transcript and logs
write gate · payment held for policy check
AI disclosedcard redactedwrite held
consent ✓ · dnc ✓ · identity ✓ · pan redacted · payment held · guardian ok · audit:chained ✓ ·
Card payment call, simulated · rendered by spine·voice
then a named specialist signs off →
SPINE · WRITE GATE · call #52006live
step 01Consent and DNC checkbefore the call is placedAuto · pass
step 05Take card paymentpolicy check, then specialistHeld · human
✓ approved · named reviewer · hash-chained entry
Governance in the platform 100% of consequential writes gated 0 unapproved writes 15 frameworks mapped Guardian checks 24/7
Security controls

Six controls that run on every call, not on a checklist.

Policy documents do not stop a bad call. These controls are part of the platform, so they apply to every agent and every client by default.

01

Write gate

Payment plans, refunds, account changes, loan offers and disputes stop for a named person or pass a policy check before they execute. Why it matters: automation grows without growing your exposure.

02

Audit chain

Every action and decision appended to an HMAC hash-chained log, so any tampering is detectable. Why it matters: you can prove what happened on any call, months later.

03

Redaction

Card numbers and personal data removed from transcripts and logs. Why it matters: fewer places hold sensitive data, which shrinks your breach and audit scope.

04

Tenant isolation

Row-level security for each client in the database. Why it matters: one client’s customers can never appear in another client’s agent.

05

Consent and DNC checks

Do-not-call and consent checked before dialing, with time-of-day and contact-frequency rules enforced. Why it matters: outbound campaigns stay inside contact rules without manual list scrubbing.

06

Identity before disclosure

The agent verifies identity before discussing an account and handles wrong parties safely. Why it matters: third-party disclosure, one of the costliest mistakes in collections, is designed out.

spine·voice // compliance center15 frameworks_
Compliance Center · common control setsample
FrameworkStatusOwner
NIST AI RMF✓ mappedRisk lead
SOC 2✓ controls alignedSecurity lead
PCI DSS✓ controls alignedPayments lead
India DPDP✓ mappedPrivacy lead
FDCPA and Regulation F1 alertCompliance lead
Guardian alert raised · evidence attachedOpen alert
Compliance Center, sample data · rendered by spine·voice
Compliance Center

Fifteen frameworks, one control set, one place to show your auditors.

The Compliance Center maps 15 frameworks to one common set of controls, including NIST AI RMF, SOC 2, PCI DSS, India DPDP, GDPR-style privacy and US debt collection rules under the FDCPA and Regulation F. Mapping shows how our controls align with each framework. It is not a claim of certification.

  • Guardian agent, always onAn AI agent checks the controls continuously and raises an alert when one drifts. Problems are found by us, not by your auditor.
  • Evidence, owners and waiversEach control has a named owner, attached evidence and any approved waiver on record. Audit preparation starts from evidence that is already filed.
  • Trend reportsSee control health over time for your risk committee and your clients.
Responsible AI

Customers know they are talking to AI. Your team knows which model answered.

Trust in AI on the phone depends on honesty with the caller and discipline behind the scenes.

✓AI disclosure to callers

Our agents tell callers they are speaking with an AI and offer a person when it matters. Read how in our AI disclosure.

✓Model governance

Every model and every agent version is tested in simulation, released behind a ramp gate and recorded per turn by the model router.

✓Privacy rights

Customers can ask what we hold about them and how it is used. See privacy rights for how requests are handled.

What we commit to

Numbers we are willing to be held to.

We do not publish ROI claims. We do publish the rules the platform enforces.

100%Consequential writes gated
0Unapproved writes
15Compliance frameworks mapped
24/7Guardian control checks
Book a demo

Bring your risk team. We will open the audit record.

In the demo we hold a payment at the write gate, approve it as a named person and verify the hash-chained entry it leaves behind.