Compliance

By the book —
in the code.

Other tools call their compliance rails “convenience only.” Spindle’s are enforced floors written into the engine — no agent, setting, or imported script can switch them off — paired with a signed, exportable record of everything.

01 · The floors

The five floors

Controls you can see — and can’t disable.

Consent & STOP

Say stop once, in any words, and you’re suppressed everywhere — instantly, across every channel.

Quiet hours

Never a message outside 8am–9pm in the recipient’s own time zone. Server-enforced, and it only ever gets stricter.

Provenance

Every lead is stamped with where it came from — and where there’s no lawful basis, it stays locked.

Disclosure

Recipients always know they’re talking to an automated assistant. The persona editor can’t remove it.

Fail-closed

When proof is missing, Spindle doesn’t send. It defaults to off, not to risk.

Evidence on demand

The receipt

Export the whole consent and opt-out trail in a click — a signed, tamper-evident record.

02 · The posture

The posture

Facilitator, not author.

You are the legal sender. You attest that you have a lawful basis for every contact, and you indemnify us by signature. In return, Spindle backs you with floors you can’t disable and a record of everything — a stronger posture than tools whose terms say their compliance is “convenience only.”

Your liability by contract, our floors you can’t disable, everything logged.

A plain disclaimer. Spindle’s compliance features are engineering controls provided for your benefit — not legal advice, and not a safe harbor, and they don’t transfer liability to Spindle or guarantee your messaging is lawful. You are the legal sender, responsible for your own compliance. SMS features go live only after a review with counsel.

03 · The rules

What it maps to

The rules, handled where they belong.

Compliance lives in the orchestration engine — not a help-center article.

TCPA

Texting consent & quiet hours

No cold or follow-up text without a real, on-file basis. Quiet hours (9pm–8am) enforced in the send layer — unbypassable.

CAN-SPAM

Marketing email

Email customers commit to identifying themselves, a real postal address, and honoring opt-outs. Email’s rules stay separate from texting’s.

DNC & STOP

Do-not-call

Every text scrubbed against DNC + your suppression list — suppression beats stale consent. STOP = suppress + one confirmation, nothing more.

State laws

Mini-TCPA + bot disclosure

One conservative floor that only ever gets stricter. Bot-disclosure wording is a fixed control, not editable brand voice.

Provenance

Where each contact came from

Every lead labeled listed · acquired · consumer-import · unproven. Proof is never invented — unproven stays locked.

Evidence

Signed & provable

Immutable e-signed terms, per-business fail-closed gates, and a one-click audit / evidence export of the whole trail.

04 · Security

Security & data

The data you don’t store can’t be breached.

You can’t offload liability by your hosting choice — what good engineering buys is defensibility. Here’s what’s true today, and what’s on the roadmap before we ever hold production data at scale.

Live today

  • Data minimization — no card, token, or secret is ever stored
  • No account until you send — far less data collected than typical SaaS
  • Device encryption — keys held in the OS secure enclave, app-lock on bulk actions
  • Tenant isolation — every query workspace-scoped, enforced in CI

On the roadmap — before production data at scale

  • Encryption at rest + column-level encryption for sensitive fields
  • Row-level isolation in the database
  • SOC 2 and a signed data-processing agreement on file
  • Encrypted, tested backups and breach-response runbooks
05 · The line

Compliance you can show your lawyer.

Join the private beta and see the rails for yourself.