Layered, decoupled and API-first. Configured, not coded.
A composable, low-code, API-first platform delivered as software-as-a-service. Every layer can change on its own, every layer is tailored through configuration, not code, and every layer is reached through secure, governed services.
Select a layer to explore it
Composable layers, one API-first nervous system integrating it all seamlessly.
Select a layer to see what it does and which APIs it publishes or consumes.
Onboard, configure, release.
The traditional route reaches production capability at 18 to 24 months. On Spindle you onboard onto a platform that is already integrated and operating.
Traditional: production capability at 18 to 24 months
Spindle: start building products on day one
Tailored to you at every layer. Every layer can be shaped to your exact needs through low code, and accelerated with pre-built products, processes and APIs.
One subscription
Licences acquired in bulk and bundled, not bought one capability at a time.
Pre-integrated
Every component connected, with proven patterns for products, processes and integration.
Pre-built
Products, processes and APIs to start from, adapted rather than built from scratch.
Low code at every layer
Change what you need, when you need it. Why low code matters →
Skills on demand
Curated skills when you need them, and low code for your own teams.
Evergreen
Upgrades arrive through release cycles, not programmes.
Low code puts change back in your hands.
Low code is faster and more efficient to build with, but that isn't the main point. Because every layer is configured rather than coded, your own teams make the changes the business needs, at each layer. You don't wait for vendor enhancements, patches or development queues.
Screens, portals and customer journeys.
Processes, rules, approvals and AI steps.
APIs, mappings and partner connections.
Products, rules, rates and transactions.
Documents, statements and retention rules.
A code-bound core
Every change waits in someone else's queue.
Spindle
Your teams change the layer that needs to change.
Platform components, integrated, each one working today.
Engineering choices that deliver real business outcomes.
Composable and loosely coupled
Separable services with clear contracts; components replaceable without breaking the architecture.
Adopt what you need now; add or swap parts later, with no rip-and-replace and no lock-in.
Headless PAS
A stable transaction engine and system of record; no business process is managed inside it.
Change how you work without touching the system of record.
Process- and rules-driven
Workflows, eligibility and decisions modelled in BPM and embedded rule engines.
Journeys, rules and products change in configuration, in days, not release cycles.
Single source of truth
Person, member, policy, claim and employer mastered once, with no duplication.
One view of every customer and contract; reporting and regulation reconcile first time.
Integration-first, AI-enabled
Open APIs and event streams for distributors, banks and partners; no point-to-point links.
A new bank, broker or partner channel in weeks, with AI wherever it adds value.
Secure by design
Role-based access, MFA, encryption, audit trails and privacy controls from day one.
Regulator- and audit-ready from the first policy.
Automation with human oversight
Routine validation automated; complex adjudication and appeals stay with people where you choose.
Lower cost to serve, with people focused where judgement matters.
Technology evergreen
Spindle carries continuous upgrade and advancement of every component.
No disruptive upgrade programmes; new capability arrives inside the subscription.
Certified components. Controls applied in every implementation.
The platform's components hold ISO/IEC 27001 certification, and its digital, process and integration components hold SOC 2 Type 2 attestations. Spindle applies ISO/IEC 27001 and SOC 2 controls in every implementation, and the platform is designed to support controls aligned to GDPR, POPIA and HIPAA.
Encrypted end to end
TLS 1.2+ in transit; AES-256 at rest with per-client keys; personal data masked outside production.
Immutable audit
Access, changes, process steps, API calls and document access logged and exportable to your SIEM.
Independently tested
Penetration and vulnerability testing before go-live and twice a year.
Wherever your regulator requires. Ring-fenced in every model.
Public cloud
The standard: Spindle-managed, ring-fenced tenancy in a localised data centre.
Private cloud
Your preferred cloud, where residency or group policy requires it.
Hybrid
Cloud platform with on-premise components such as a data vault.
On-premise
Full deployment into your own infrastructure.
See it working on your products.
A working demonstration within weeks; a defined first product in production within three to six months.
