Security & Compliance
This page is maintained by Pinnacle Process Solutions to answer common security and privacy questions about Pinnacle Communication Coach.
Authentication & access
- Email + password with leaked-password screening (Have I Been Pwned).
- Google sign-in via OAuth 2.0 / OpenID Connect.
- Email verification required. Anonymous sign-ins disabled.
- Role-based access control; administrator role is separated from user data.
- Row-Level Security enforced in the database for every user-owned table.
Encryption
- All traffic uses TLS 1.2+ in transit.
- Data at rest is encrypted by the managed cloud database (AES-256).
- Secrets are held in a managed secret store, never in source code.
Application security
Development follows OWASP Top 10 and OWASP ASVS Level 2+ practices: parameterized queries, server-side input validation, output sanitization, authenticated and authorized server endpoints, signed webhooks, and least-privilege service credentials.
Payments
Card data is handled exclusively by Stripe (PCI DSS Level 1). We never see, store, or transmit raw card numbers.
Privacy
We collect the minimum information required to operate the service (account, usage, and analyses you submit). You can request export or deletion of your data by contacting us.
Compliance alignment
Pinnacle Communication Coach is designed to align with SOC 2 Type II and ISO/IEC 27001:2022 security controls, and with GDPR and CCPA privacy principles. Independent certification requires successful third-party audits and is not claimed until completed. No certification logos or trust seals are displayed on this site.
Report a vulnerability
Please email a.dalal@pinnacleprocess.com with a description and reproduction steps. We respond to reports as quickly as possible.