Trust is earned through demonstrable protection. Every control on this page is an operational practice, not a marketing claim — and we are happy to discuss the detail with verified clients.
Handling other people's money is a privilege that demands the highest standards of security. At Pinnacle Asset Management, we approach security as a layered discipline: no single control is sufficient, so we combine encryption, account segregation, identity verification, custody architecture, audit trails, insurance, and incident response into a defence-in-depth model. The result is a platform engineered to remain safe even when individual components fail — because in security, the assumption must always be that something will.
The eight pillars of our security model
256-bit AES encryption
All data — at rest and in transit — is encrypted to bank-grade standards. Your password is hashed with bcrypt and never stored in plain text.
Segregated client accounts
Client funds are held separately from Pinnacle Asset Management's operating capital and cannot be used to fund our own activities, even in insolvency.
KYC / AML compliance
Every account completes identity verification before any investment is made, and transactions are screened against anti-money-laundering requirements.
Two-factor authentication
2FA is available and strongly recommended on every account, with support for authenticator apps and backup codes for recovery.
Cold storage for crypto
The overwhelming majority of client crypto assets are held in air-gapped, multi-signature cold storage, with only operational balances in hot wallets.
Immutable audit trails
Every account action — login, deposit, trade, withdrawal — is recorded in a tamper-evident log that supports investigation and dispute resolution.
Insurance coverage
We maintain insurance coverage against specified operational risks, including custody and cyber events, as a layer of protection beyond our own controls.
Incident response
A documented incident-response plan governs how we detect, contain, investigate and communicate any security event — with client notification where required.
Encryption & data protection
All sensitive data — personal information, account details, wallet addresses, transaction records — is encrypted at rest using 256-bit AES, the same standard used by banks and governments for classified material. Data in transit between your device and our servers is protected by TLS with strong cipher suites and forward secrecy. Passwords are never stored in plain text; instead, they are hashed using bcrypt with a per-password salt, which means that even in the hypothetical event of a database compromise, your password could not be recovered from the stored hash.
Payment card details are never stored on our infrastructure. Card payments are processed by Stripe, which tokenises card data on its own PCI-DSS-compliant systems and returns only a non-reversible token to us. We hold the minimum data necessary to operate your account and no more.
What we recommend you do
- Enable two-factor authentication the moment your account is verified.
- Use a unique, strong password — not one you reuse across other sites.
- Treat any email claiming to be from Pinnacle Asset Management that asks for your password or 2FA code as fraudulent. We will never ask for these.
- Contact us immediately if you notice any unrecognised activity on your account.
Segregated client accounts
Client funds are held in segregated accounts that are legally and operationally separate from Pinnacle Asset Management's operating capital. This means your money is not available to cover our operating expenses, and in the unlikely event of platform closure, all active investments continue to maturity and all balances are returned to investors. We never reuse client assets to fund proprietary trading or any other activity of the firm.
KYC & AML compliance
Know-your-customer (KYC) verification is mandatory before any investment can be made. The process typically completes within 24 hours and involves verifying your identity using government-issued documentation and a real-time check. Anti-money-laundering (AML) screening applies to every transaction, and we are required to report suspicious activity to the relevant authorities. These procedures protect the integrity of the platform and the broader financial system — and they protect you, by making it harder for fraudulent actors to operate alongside legitimate clients.
Cold storage for crypto assets
For digital assets, custody is the single most important security decision. The overwhelming majority of client crypto is held in air-gapped, institutional-grade cold storage with multi-signature controls — meaning that no single individual can authorise a movement of client crypto, and the keys are never exposed to internet-connected systems. Only a small operational balance is held in hot wallets to facilitate withdrawals, and that balance is itself subject to strict limits and monitoring.
Audit trails & monitoring
Every meaningful action on the platform — every login, every deposit, every trade, every withdrawal, every change to account settings — is recorded in an immutable, tamper-evident audit trail. This supports investigation of any disputed transaction, enables us to detect anomalous behaviour quickly, and provides a clear record for regulators and auditors. Our monitoring systems run continuously and escalate anomalies to human reviewers for assessment.
Insurance & incident response
We maintain insurance coverage against specified operational risks, including custody and cyber events, as a layer of protection that sits behind our own controls. No control is infallible, and insurance is one of the ways we ensure that a failure does not become a client loss.
Our incident response plan governs how we handle any security event, from detection through containment, investigation, remediation, and communication. We commit to notifying affected clients promptly where an incident has a material impact on their account, in accordance with applicable regulatory requirements.
Security is a shared responsibility. We build the controls, but you play a part too — by enabling 2FA, using a strong password, and reporting anything suspicious. Read more in our Privacy Policy and Licensing & Compliance pages.