Security

How we protect your account and your money

Being signed in is not enough to move money on Pinnora. Here is what stands between your account and anyone else — and what you can do to help.

Signing in

Your password is never stored as you typed it. Pinnora keeps only a salted scrypt hash of it — a deliberately slow, memory-hard function designed to make guessing passwords from a stolen copy impractical — and checks what you type against that.

You can also sign in with a passkey: Face ID, Touch ID or your device’s passcode. A passkey is a key pair made on your device, and the private half never leaves it. Each sign-in signs a fresh, single-use challenge, and Pinnora checks the signature, that the request came from Pinnora’s own site and that you were actually present. There is no password to type, and because a passkey only works on Pinnora’s own site, a look-alike site cannot use it.

Repeated wrong passwords are slowed down and then stopped, and attempts on one account from many different networks are recognised as an attack — without locking you out from the network you normally use.

Two steps before money leaves

A signed-in session on its own can look at your account, but it cannot move money out of it. Sending money, withdrawing it and adding a new passkey all ask you to confirm it is you — with your password or a passkey — unless you already did so in the last ten minutes.

  • Identity first. Your identity has to be verified before you can withdraw, send money to anyone or apply for business capital.
  • Press and hold. Buying or selling from an asset’s page, deposits, withdrawals and sends are confirmed by holding the button for a second, so a stray tap does nothing.
  • Checked before it goes. Every withdrawal, and every send to an address outside Pinnora, is reviewed by our team before it is paid out, and shows as in progress until then.
  • A daily limit. Withdrawals and sends to outside addresses count towards a daily limit set by Pinnora and shown in the app.

Sessions tied to your device

When you sign in, your browser is given a session cookie that page scripts cannot read and that other websites cannot send. Every change you make also carries a separate request token, so another site cannot act for you while you are signed in.

A session belongs to the browser and the network it was opened on. If the same cookie turns up from a different browser or a different network, the session ends there and then, and the attempt is recorded. Sessions also end after a week without use, and after thirty days at most.

The Security centre in the app lists every device signed in to your account, so you can sign out any one of them, or all of them at once. Changing your password signs out every other device and removes every passkey except the one you are using, so somebody who had your old password cannot stay in.

Alerts you cannot miss

Every new sign-in to your account — with a password or with a passkey — sends you a security notification naming the device. So do repeated failed attempts to sign in, a passkey added or removed, a password change, and support opening your account to help you. These security alerts are kept even when you clear your notifications, because they are the warning that matters most if someone else is ever in your account.

Encrypted in transit

Pinnora is served over HTTPS only, and tells browsers to use nothing else for the site and its subdomains, so your connection cannot be quietly downgraded. Push notifications are encrypted to your device before they are sent, so the delivery service in between cannot read them.

In the browser, the app runs under a strict content security policy: it loads its scripts only from Pinnora and refuses to be shown inside another site’s page, which blocks whole families of attacks before they start.

Behind the scenes

  • Staff tools run separately from the customer app, behind access controls of their own, and every staff account must use two-factor authentication.
  • When support opens your account to help you, you are told, and that view is read-only: it cannot move money or change anything.
  • Every staff action is written to an audit log in which each entry is chained to the one before it, so an entry altered after the fact can be detected.

What you can do

  • Add a passkey on the phone you use most, and use a password you use nowhere else.
  • Read every sign-in alert. If one was not you, change your password and sign out every other device from the Security centre.
  • Never share your password, or approve a passkey prompt you did not start.
  • Open the app at mypinnora.com/app/ or from your Home Screen, never from a link in a message you did not expect.
Think someone else has used your account? Change your password, sign out all other devices, and open a support ticket so we can look at the activity with you. More answers are in the help centre.

Open Pinnora in your browser

Your account, your investments and your savings in one place, on any phone or computer.

Open the App