Security & data protection
Your data, protected — and always yours.
Pinnacle Ai runs on SOC 2 Type II certified infrastructure and keeps your customer data safe with encrypted HTTPS/TLS connections, role-based user permissions and PCI-compliant payment processing. You own your data, you can export it whenever you want, and we don't sell it.
SOC 2 Type II certified
The infrastructure our platform runs on holds an independent SOC 2 Type II certification, covering the Security, Availability, and Confidentiality trust service criteria. A Type II report attests that controls operated effectively over a period of time.
How does Pinnacle Ai protect my data?
Seven things we can say plainly — no jargon, no badges we haven't earned.
SOC 2 Type II certified infrastructure
The infrastructure our platform runs on holds an independent SOC 2 Type II certification, covering the Security, Availability, and Confidentiality trust service criteria. A Type II report attests that those controls operated effectively over a period of time — not that a box was ticked once.
- Independent SOC 2 Type II certification
- Security, Availability and Confidentiality criteria
- Controls tested over time, not a one-off check
Encrypted connections, end to end
Every page, form and app session runs over encrypted HTTPS/TLS connections, so data moving between your team, your customers and Pinnacle Ai isn't travelling in the open.
- HTTPS/TLS on all traffic, including forms and funnels
- Encrypted connections for the web app and mobile apps
- Data stored on secure, reputable cloud infrastructure
You own your data
Your contacts, conversations and content belong to your business. You can export your contact data whenever you want, and we don't sell it to anyone.
- Export contacts and content anytime
- We do not sell your data
- No contracts — leave with what you brought and built
Role-based user permissions
Unlimited users doesn't mean everyone sees everything. Set what each person can open, so a front-desk hire and an owner don't have the same view.
- Permissions per user, by area of the account
- Limit access to billing, reporting and settings
- Remove access the moment someone leaves
Payments handled by PCI-compliant processors
Card payments run through PCI-compliant payment processors such as Stripe. Raw card numbers are handled by the processor, not stored by us.
- Card data handled by PCI-compliant processors
- We don't store raw card numbers
- Your merchant account stays in your name
Compliance tooling where you need it
Tools for privacy requests and cookie consent are available through our compliance portal, and text messaging follows carrier compliance rules — we handle A2P registration with you on your Tech Setup call.
- Privacy request and cookie consent tooling via the compliance portal
- A2P text registration set up with you, 1-on-1
- Unsubscribe and consent handling built into messaging
Reliable, managed, backed-up infrastructure
The platform runs on managed cloud infrastructure that's monitored and backed up, so you're not the one patching servers or worrying about a hard drive.
- Managed, monitored hosting
- Regular backups of platform data
- Updates and maintenance handled for you
Ownership
What happens to my data if I leave?
You take it. There are no contracts and no exit fee — export your contacts and content and cancel whenever you like. We'd rather earn the next month than lock you into it.
Legal documents live in the compliance portal
Our Terms of Service, Privacy Notice and cookie policy are published in the compliance portal, along with the tooling for privacy requests and consent.
FAQ
Security questions, answered
This page is a plain-language summary of how we handle your data — it is not a contract and it doesn't replace our legal terms. The binding Terms of Service, Privacy Notice and related policies are published in our compliance portal.
Questions about your data? Ask a human.
24/7 live chat & Zoom support on every plan