Skip to content

Security & data protection

Your data, protected — and always yours.

Pinnacle Ai runs on SOC 2 Type II certified infrastructure and keeps your customer data safe with encrypted HTTPS/TLS connections, role-based user permissions and PCI-compliant payment processing. You own your data, you can export it whenever you want, and we don't sell it.

SOC 2 Type II certified

The infrastructure our platform runs on holds an independent SOC 2 Type II certification, covering the Security, Availability, and Confidentiality trust service criteria. A Type II report attests that controls operated effectively over a period of time.

How does Pinnacle Ai protect my data?

Seven things we can say plainly — no jargon, no badges we haven't earned.

  • SOC 2 Type II certified infrastructure

    The infrastructure our platform runs on holds an independent SOC 2 Type II certification, covering the Security, Availability, and Confidentiality trust service criteria. A Type II report attests that those controls operated effectively over a period of time — not that a box was ticked once.

    • Independent SOC 2 Type II certification
    • Security, Availability and Confidentiality criteria
    • Controls tested over time, not a one-off check
  • Encrypted connections, end to end

    Every page, form and app session runs over encrypted HTTPS/TLS connections, so data moving between your team, your customers and Pinnacle Ai isn't travelling in the open.

    • HTTPS/TLS on all traffic, including forms and funnels
    • Encrypted connections for the web app and mobile apps
    • Data stored on secure, reputable cloud infrastructure
  • You own your data

    Your contacts, conversations and content belong to your business. You can export your contact data whenever you want, and we don't sell it to anyone.

    • Export contacts and content anytime
    • We do not sell your data
    • No contracts — leave with what you brought and built
  • Role-based user permissions

    Unlimited users doesn't mean everyone sees everything. Set what each person can open, so a front-desk hire and an owner don't have the same view.

    • Permissions per user, by area of the account
    • Limit access to billing, reporting and settings
    • Remove access the moment someone leaves
  • Payments handled by PCI-compliant processors

    Card payments run through PCI-compliant payment processors such as Stripe. Raw card numbers are handled by the processor, not stored by us.

    • Card data handled by PCI-compliant processors
    • We don't store raw card numbers
    • Your merchant account stays in your name
  • Compliance tooling where you need it

    Tools for privacy requests and cookie consent are available through our compliance portal, and text messaging follows carrier compliance rules — we handle A2P registration with you on your Tech Setup call.

    • Privacy request and cookie consent tooling via the compliance portal
    • A2P text registration set up with you, 1-on-1
    • Unsubscribe and consent handling built into messaging
  • Reliable, managed, backed-up infrastructure

    The platform runs on managed cloud infrastructure that's monitored and backed up, so you're not the one patching servers or worrying about a hard drive.

    • Managed, monitored hosting
    • Regular backups of platform data
    • Updates and maintenance handled for you

Ownership

What happens to my data if I leave?

You take it. There are no contracts and no exit fee — export your contacts and content and cancel whenever you like. We'd rather earn the next month than lock you into it.

Legal documents live in the compliance portal

Our Terms of Service, Privacy Notice and cookie policy are published in the compliance portal, along with the tooling for privacy requests and consent.

FAQ

Security questions, answered

Yes. The infrastructure our platform runs on is independently SOC 2 Type II certified across the Security, Availability, and Confidentiality trust service criteria — meaning its security controls were tested and shown to operate effectively over time, not just checked once.

Yes. All traffic to and from Pinnacle Ai runs over encrypted HTTPS/TLS connections, and your data is stored on secure, reputable managed cloud infrastructure.

No. We do not sell your data. Your contacts, conversations and content belong to your business and are used to run your account, not to be sold on.

Yes. You can export your contacts and content at any time. There are no contracts, so if you ever leave you take your data with you.

Card payments are processed by PCI-compliant payment processors such as Stripe. The processor handles the card details — Pinnacle Ai does not store raw card numbers.

Only the users you invite, and only the areas you allow. Role-based permissions let you limit each staff member to what they need, and you can remove access immediately when someone leaves.

In our compliance portal at compliance.getpinnacle.ai, which hosts the Terms of Service, Privacy Notice and related policies. This page is a plain-language summary, not a contract.

This page is a plain-language summary of how we handle your data — it is not a contract and it doesn't replace our legal terms. The binding Terms of Service, Privacy Notice and related policies are published in our compliance portal.

Questions about your data? Ask a human.

24/7 live chat & Zoom support on every plan

Watch the Demo