Pin Trust Center

Welcome to Pin's Trust Center, where our commitment to data privacy and security is core to our business.  This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data. Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Pin Trust Center

Pin Trust Center

Welcome to Pin's Trust Center, where our commitment to data privacy and security is core to our business. 

This Trust Center offers detailed insights into our security practices, including the specific controls and policies implemented by our teams. You can explore our compliance standards, request access to comprehensive security documentation, and gain a clear understanding of how we safeguard your data.

Additionally, we invite you to subscribe for updates to stay informed about the latest advancements in our security and compliance initiatives.

support@pin.com

Access control

Layered authentication and authorization safeguards restrict system access to only approved users and keep customer data protected.

Multi-factor authentication for privileged access

Administrators must present a valid second authentication factor before they can reach production infrastructure, reducing the risk of account takeover and unauthorized system changes.

Role-based access control

Privileges to networks, applications, operating systems and data stores are granted strictly on the principle of least privilege, ensuring users receive only the access required for their job responsibilities.

Unique credentials and strong password policy

Every user authenticates with an individual account that follows enforced complexity, length and rotation requirements, strengthening defenses against brute-force and credential-stuffing attacks.

Formal access provisioning and deprovisioning

All new access requests require documented manager approval and access is removed within 24 hours of termination, limiting exposure from orphaned or excessive accounts.

Quarterly access reviews and recertification

Management conducts documented quarterly reviews of all high-risk systems to verify that permissions remain appropriate and to promptly revoke or adjust any unnecessary rights.

Data security

Comprehensive safeguards protect customer information throughout its lifecycle, from classification to encryption and secure disposal.

Encryption at rest

All databases and storage services containing customer information are configured for server-side encryption, preventing unauthorized reading of stored data.

Encryption in transit

Secure transport protocols are enforced to encrypt customer data whenever it traverses public or untrusted networks, mitigating eavesdropping and tampering risks.

Data classification policy

A documented framework assigns sensitivity levels to information assets and prescribes handling requirements, ensuring appropriate protection measures are applied.

Data retention and secure disposal

Formal procedures govern how long customer data is retained and define secure purge methods, including the ability to delete data upon customer request.

Production-only customer data handling

Policies strictly prohibit storing or using customer information in non-production environments, reducing exposure during development and testing activities.

Security monitoring and logging

Automated tools continuously watch for suspicious activity, generate real-time alerts and provide visibility into system performance and threats.

Centralized log management with alerting

A dedicated log analytics platform aggregates security events across the environment and instantly notifies responders of anomalies that could impact confidentiality, integrity or availability.

Network intrusion detection system

An IDS continuously analyzes network traffic and triggers alerts when indicators of compromise or malicious behavior are detected, enabling rapid response.

System performance and availability monitoring

Automated monitoring tracks key health and capacity metrics, sending notifications when predefined thresholds are exceeded to prevent service disruption.

Anti-malware protection

Up-to-date endpoint security is deployed on production servers to detect and block malware, with routine signature updates and logging for auditing purposes.

Targeted security alert routing

Critical security events are automatically correlated and delivered to personnel with the authority and context to investigate or escalate, shortening response times.

Vulnerability management

Structured identification, assessment and remediation processes keep systems resilient against emerging threats.

Documented vulnerability management policy

Formal guidelines define how vulnerabilities are discovered, ranked by severity and remediated within set timelines, aligning practices with industry expectations.

Quarterly web application scanning

Automated scans run every quarter to detect and prioritize web application weaknesses, ensuring issues are found before adversaries exploit them.

Annual penetration testing

Independent security experts conduct comprehensive penetration tests each year to uncover exploitable weaknesses in the production environment.

Timely remediation of critical findings

Management mandates and tracks corrective actions for all high and critical vulnerabilities identified through scanning and testing until verified closure.

Routine infrastructure patch management

Operating systems and other platform components are regularly patched as part of scheduled maintenance, reducing exposure to known exploits.

Incident response

Prepared and tested processes ensure swift detection, containment and recovery from security events to protect customer operations.

Formal incident response policy

A documented framework outlines roles, communication channels and step-by-step procedures for identifying, analyzing and remediating security incidents.

Incident tracking and communication

All security events are logged, evaluated and communicated to affected stakeholders until full resolution, providing transparency and accountability.

Annual incident response testing

The incident response plan is exercised each year to validate team readiness and refine processes based on test outcomes.

Post-incident reviews

After significant events, cross-functional teams conduct documented retrospectives to capture root causes and implement preventative improvements.

Defined recovery procedures for incidents

The response program includes activities focused on restoring normal operations and safeguarding data integrity following an incident.

Business continuity and disaster recovery

Robust continuity planning and redundant infrastructure safeguard service availability even during unexpected disruptions.

Documented BC/DR plan

A comprehensive business continuity and disaster recovery strategy defines responsibilities, recovery steps and communication protocols for critical services.

Annual BC/DR testing

Regular exercises validate that recovery objectives can be met and that personnel understand their roles during disruptive events.

Daily incremental backups

Customer data is backed up every day, ensuring minimal data loss in the event restoration is required.

Backup restoration verification

Periodic restoration tests confirm that backups can be successfully recovered and data integrity is maintained.

Multi-zone data replication

Production databases are replicated across multiple availability zones, providing automatic failover capability if a primary site becomes unavailable.

Change management

Structured development and deployment practices ensure that system changes are controlled, tested and traceable.

Documented change management policy

Policies require that all system modifications follow defined processes for request, testing, review and scheduling before production release.

Segregated development and production environments

Code is developed and tested in isolated environments separate from production, preventing unintended impact on live services.

Peer code reviews

Every change undergoes peer or authorized review to validate technical correctness and alignment with security standards prior to deployment.

Branch protection rules

Enforced restrictions within the code repository prevent unauthorized or unreviewed commits from being merged into critical production branches.

Automated configuration management

A configuration management tool applies standardized system settings across environments, reducing human error and drift.

Employee security

Rigorous personnel practices foster a culture of security and ensure trusted handling of customer data.

Pre-employment background checks

All new hires undergo background screening before start date to verify trustworthiness and reduce insider risk.

Security awareness training on hire

New employees complete mandatory training that covers cybersecurity threats, data protection obligations and acceptable use expectations.

Annual security awareness training

Recurring education reinforces security best practices and keeps personnel informed about evolving threats and policies.

Code of conduct acknowledgment

Employees formally attest to understanding and adhering to the organization’s code of ethical behavior and information handling standards.

Employee confidentiality agreements

Staff sign legally binding agreements prohibiting unauthorized disclosure of proprietary or customer information, strengthening accountability.

Vendor and third-party management

Structured oversight of service providers mitigates supply-chain risk and assures alignment with security requirements.

Vendor management policy and risk assessments

Documented procedures require classification and periodic evaluation of third-party vendors based on the sensitivity of services provided.

Security clauses in vendor contracts

Formal agreements with critical vendors embed commitments and obligations that protect customer information and define incident notification duties.

Annual review of vendor SOC reports

Security and compliance attestations from critical providers are examined each year, and any exceptions are assessed for impact on the platform.

Comprehensive third-party inventory

An up-to-date register of all external partners enables effective tracking, monitoring and timely removal of obsolete relationships.

Ongoing subservice provider monitoring

Management regularly communicates with the hosting provider and reviews its controls to ensure continued alignment with contractual expectations.

Risk management and governance

Executive oversight and structured assessments guide control selection and ensure risks are addressed proactively.

Executive risk committee oversight

A cross-functional committee meets quarterly to review risk posture and oversee the effectiveness of internal controls.

Documented risk management policy

Formal guidelines outline how threats are identified, ranked and mitigated, aligning security priorities with business objectives.

Annual enterprise risk assessment

Management conducts a comprehensive evaluation each year that includes fraud considerations and drives updates to the control environment.

Defined risk mitigation controls

Risks identified during assessments lead to targeted manual and technical controls designed to reduce likelihood and impact.

Fraud risk evaluation

Risk analysis explicitly considers potential fraudulent activities to ensure safeguards address both internal and external threats.

Infrastructure and network security

Architectural safeguards and cloud controls protect the production environment against unauthorized access and service disruption.

Network segmentation

Production networks are logically separated to restrict lateral movement and limit exposure of sensitive customer data.

Managed security groups

Firewall-like rules at the cloud perimeter enforce least-privilege ingress and egress, blocking unauthorized traffic to production resources.

Hosting facility physical security

The cloud provider restricts data-center entry to authorized personnel and maintains 24/7 surveillance, preventing unauthorized physical access.

Secure asset decommissioning

The hosting provider securely destroys retired hardware to ensure residual customer data cannot be recovered.

Auto-scaling capacity management

Dynamic scaling automatically provisions additional resources during demand spikes, maintaining performance and availability.

Compliance and privacy

Independent audits and documented policies demonstrate alignment with recognized standards and customer privacy commitments.

SOC 2 Type II certification

An accredited third-party annually attests to the design and operating effectiveness of controls across security, confidentiality and availability.

Published privacy policy

Customers are informed of data handling practices and commitments, supporting transparency and regulatory compliance.

Alignment with trust services criteria

Control framework maps directly to AICPA trust services criteria, giving customers confidence in recognized best practices.

Customer-initiated data deletion

Processes exist to purge customer data from the platform upon request, supporting regulatory obligations such as GDPR rights to erasure.