Security

Authority is explicit, tenant-bound, and reversible.

Spillway separates source evidence, canonical product decisions, provider execution, and external confirmation so no integration can manufacture product truth.

Version security-surface-2026-08-v1. This surface describes the implemented product boundary.

Tenant isolation

Provider connections, messaging senders, installation state, billing relationships, calls, and proof evidence are bound to an exact tenant. Client-supplied tenant identifiers do not create authority, and cross-tenant provider references are rejected.

Credentials and payments

Spillway stores approved credential references rather than raw provider secrets in product artifacts. Stripe-hosted Checkout and Billing Portal surfaces handle payment information; Spillway does not store card numbers or security codes.

Provider evidence

Signed webhooks, replay protection, deterministic idempotency, provider-resource binding, capability probes, immutable evidence, and explicit live gates prevent documentation or a successful connection from silently becoming tenant authority.

Bounded control

Tenant pause, provider disable, messaging suppression, scheduling reality checks, billing kill switches, and explicit offboarding stop new consequential activity without erasing historical evidence.

Claims

This page does not claim SOC 2, HIPAA, PCI, penetration-test, or carrier certification. It describes controls implemented in Spillway's application architecture; external verification remains separately evidenced.