We built Spine for collections and lending, where one wrong sentence has legal consequences. Conversation runs at machine speed, every consequential action stops for a policy check or a named person, and every decision lands on a tamper-evident record your auditors can check.
Before we go on, I’m an AI assistant and this call is recorded. Can I confirm your date of birth?
Sure. And my card is [redacted].
Policy documents do not stop a bad call. These controls are part of the platform, so they apply to every agent and every client by default.
Payment plans, refunds, account changes, loan offers and disputes stop for a named person or pass a policy check before they execute. Why it matters: automation grows without growing your exposure.
Every action and decision appended to an HMAC hash-chained log, so any tampering is detectable. Why it matters: you can prove what happened on any call, months later.
Card numbers and personal data removed from transcripts and logs. Why it matters: fewer places hold sensitive data, which shrinks your breach and audit scope.
Row-level security for each client in the database. Why it matters: one client’s customers can never appear in another client’s agent.
Do-not-call and consent checked before dialing, with time-of-day and contact-frequency rules enforced. Why it matters: outbound campaigns stay inside contact rules without manual list scrubbing.
The agent verifies identity before discussing an account and handles wrong parties safely. Why it matters: third-party disclosure, one of the costliest mistakes in collections, is designed out.
| Framework | Status | Owner |
|---|---|---|
| NIST AI RMF | ✓ mapped | Risk lead |
| SOC 2 | ✓ controls aligned | Security lead |
| PCI DSS | ✓ controls aligned | Payments lead |
| India DPDP | ✓ mapped | Privacy lead |
| FDCPA and Regulation F | 1 alert | Compliance lead |
The Compliance Center maps 15 frameworks to one common set of controls, including NIST AI RMF, SOC 2, PCI DSS, India DPDP, GDPR-style privacy and US debt collection rules under the FDCPA and Regulation F. Mapping shows how our controls align with each framework. It is not a claim of certification.
Trust in AI on the phone depends on honesty with the caller and discipline behind the scenes.
Our agents tell callers they are speaking with an AI and offer a person when it matters. Read how in our AI disclosure.
Every model and every agent version is tested in simulation, released behind a ramp gate and recorded per turn by the model router.
Customers can ask what we hold about them and how it is used. See privacy rights for how requests are handled.
We do not publish ROI claims. We do publish the rules the platform enforces.
In the demo we hold a payment at the write gate, approve it as a named person and verify the hash-chained entry it leaves behind.