1. How We Protect Your Data
Pinnasys implements industry-standard technical and organizational security measures to protect data against unauthorized access, alteration, disclosure, or destruction. These include:
- Encrypted data transmission via HTTPS/TLS.
- Access controls limiting data access to authorized personnel only.
- Regular security reviews and vulnerability assessments.
- Secure cloud infrastructure with reputable providers.
While we take reasonable steps to protect data, no method of internet transmission or electronic storage is 100% secure. We design for defense in depth rather than relying on any single safeguard.
2. Infrastructure & Cloud Security
Pinnasys is an AWS Certified team, and we run client workloads on established cloud providers rather than self-hosted infrastructure, so the underlying compute, network, and storage layers inherit the provider's own certifications and physical security controls.
Within that infrastructure, we scope access by engagement: credentials, API keys, and environment access are limited to the people actually working on a given project.
3. AI Governance & Responsible AI
Because our work involves building and integrating AI systems — not just storing data — we treat model behavior, prompts, and outputs as part of the security surface, not separate from it.
- Algorithmic audit trails so decisions made by an AI workflow can be traced back to their inputs.
- Transparent policy management across the lifecycle of an agent or model integration, from design through deployment.
- Alignment with emerging AI regulation, including the EU AI Act and FTC guidance on automated decision-making.
4. Data Privacy
Security and privacy are two sides of the same commitment. This page covers how we protect data technically and operationally; our Privacy Policy covers what data we collect, why we collect it, and the rights you have over it.
5. Reporting a Security Concern
If you believe you've found a security vulnerability in our website or systems, we want to hear about it. Please report it responsibly rather than exploiting or publicly disclosing it before we've had a chance to investigate.