Compliance
By the book —
in the code.
Other tools call their compliance rails “convenience only.” Spindle’s are enforced floors written into the engine — no agent, setting, or imported script can switch them off — paired with a signed, exportable record of everything.
The five floors
Controls you can see — and can’t disable.
Consent & STOP
Say stop once, in any words, and you’re suppressed everywhere — instantly, across every channel.
Quiet hours
Never a message outside 8am–9pm in the recipient’s own time zone. Server-enforced, and it only ever gets stricter.
Provenance
Every lead is stamped with where it came from — and where there’s no lawful basis, it stays locked.
Disclosure
Recipients always know they’re talking to an automated assistant. The persona editor can’t remove it.
Fail-closed
When proof is missing, Spindle doesn’t send. It defaults to off, not to risk.
Evidence on demand
The receiptExport the whole consent and opt-out trail in a click — a signed, tamper-evident record.
The posture
Facilitator, not author.
You are the legal sender. You attest that you have a lawful basis for every contact, and you indemnify us by signature. In return, Spindle backs you with floors you can’t disable and a record of everything — a stronger posture than tools whose terms say their compliance is “convenience only.”
Your liability by contract, our floors you can’t disable, everything logged.
A plain disclaimer. Spindle’s compliance features are engineering controls provided for your benefit — not legal advice, and not a safe harbor, and they don’t transfer liability to Spindle or guarantee your messaging is lawful. You are the legal sender, responsible for your own compliance. SMS features go live only after a review with counsel.
What it maps to
The rules, handled where they belong.
Compliance lives in the orchestration engine — not a help-center article.
Texting consent & quiet hours
No cold or follow-up text without a real, on-file basis. Quiet hours (9pm–8am) enforced in the send layer — unbypassable.
Marketing email
Email customers commit to identifying themselves, a real postal address, and honoring opt-outs. Email’s rules stay separate from texting’s.
Do-not-call
Every text scrubbed against DNC + your suppression list — suppression beats stale consent. STOP = suppress + one confirmation, nothing more.
Mini-TCPA + bot disclosure
One conservative floor that only ever gets stricter. Bot-disclosure wording is a fixed control, not editable brand voice.
Where each contact came from
Every lead labeled listed · acquired · consumer-import · unproven. Proof is never invented — unproven stays locked.
Signed & provable
Immutable e-signed terms, per-business fail-closed gates, and a one-click audit / evidence export of the whole trail.
Security & data
The data you don’t store can’t be breached.
You can’t offload liability by your hosting choice — what good engineering buys is defensibility. Here’s what’s true today, and what’s on the roadmap before we ever hold production data at scale.
Live today
- Data minimization — no card, token, or secret is ever stored
- No account until you send — far less data collected than typical SaaS
- Device encryption — keys held in the OS secure enclave, app-lock on bulk actions
- Tenant isolation — every query workspace-scoped, enforced in CI
On the roadmap — before production data at scale
- Encryption at rest + column-level encryption for sensitive fields
- Row-level isolation in the database
- SOC 2 and a signed data-processing agreement on file
- Encrypted, tested backups and breach-response runbooks
Compliance you can show your lawyer.
Join the private beta and see the rails for yourself.