Authorized phone-system evidence
Spillway may process recordings or transcripts made available through an authorized connected phone system.


Trust & Data · Controls
Spillway connects to real business systems and can communicate with real homeowners. This page separates legal requirements, carrier requirements, payment-security controls, privacy controls, and Spillway product safeguards.
Implemented controls do not replace account-specific provider evidence.
Pipedream Connect authorization, tenant binding, server-side credential custody, and revocation.
Selected sender, outbound send, inbound reply, delivery, registration, and opt-out capability.
Carrier and provider registration for the contractor’s selected messaging route.
Stripe-owned payment surface, no raw card storage, signed webhook authority, and idempotent billing.
Authorized provider artifact, source-lawfulness responsibility, access controls, and redacted logs.
Outbound messaging, backlog delivery, new-call recovery, and monthly billing.
Genuine provider reads, sends, replies, delivery, and reconciliation.
Business messaging
U.S. business messaging can require provider or carrier registration and account-specific readiness. Spillway verifies the connected account before sending and does not treat provider support as proof that a specific sender is ready.
A call must satisfy the bounded recovery criteria before continuation.
No homeowner message is sent before the $299 activation payment is verified server-side.
The exact tenant, provider, and selected business number are bound before dispatch.
STOP and equivalent requests suppress further automated recovery messages.
Quiet-hours and frequency controls remain enforced.
Retries reuse the same message and idempotency key.
Production message effects require explicit tenant/provider release authority.
Carrier registration, provider plan, sender ownership, and permitted use remain specific to the connected contractor account. They are checked before sending.
How homeowner messaging works →Payment security
Stripe handles secure payment processing. $299 activates Spillway today and retains the contractor-authorized payment method. The first authoritative qualifying confirmed recovered inspection creates no additional charge and anchors the next $299 exactly 30 days later, then every 30 days. If the first recovery takes longer than 10 days, Spillway keeps working at no additional charge until it happens. No elapsed-time, browser, provider, or unconfirmed-appointment event can manufacture billing truth.
How billing works →Communication data
Spillway may process recordings or transcripts made available through an authorized connected phone system.
The contractor must have the lawful authority and required notice or consent for the source recording.
Artifacts are account-bound, access-controlled, and excluded from general analytics and routine logs.
Spillway does not assume recording or transcription is available or lawful merely because a provider offers it.
Production controls
Provider references and recovery state are server-bound to the contractor account.
Stripe and provider events use the available signature, replay, and deduplication controls.
Secrets remain in managed server configuration and are excluded from browser state, analytics, and logs.
Activation, authorization, probe, messaging, confirmation, billing, and failure events use redacted structured records.
Missing configuration, capabilities, external evidence, or release authority cannot create a green or consequential state.
A tenant can be paused, connections revoked, contacts suppressed, retries stopped, and billing authority disabled.
Last reviewed: August 24, 2026
Incident response
No internet-connected product can honestly promise that an incident will never happen. Spillway’s operating path must support containment, credential and connection revocation, evidence preservation, impact assessment, required notifications, remediation, and post-incident review.
Review stop controls →Truthful claims