Last Updated: August 2026
1. Our Approach to Data Security
Pinnacle applies practical safeguards based on the nature of the information, the systems being used, and the requirements of each engagement.
Our approach is built around several principles:
- Collect and access only the information required.
- Limit access to people who legitimately need it.
- Use established and reputable technology platforms.
- Protect accounts and systems with appropriate security controls.
- Avoid unnecessary duplication or storage of sensitive information.
- Maintain confidentiality throughout and after an engagement.
- Address security concerns promptly when identified.
No technology environment can eliminate every risk. Our objective is to reduce unnecessary exposure and handle client information responsibly throughout its lifecycle.
2. Access Control
Access to client information and systems is provided only where required to perform authorized work.
Where appropriate, we use measures such as:
- Individual user accounts.
- Role-based permissions.
- Strong passwords.
- Multi-factor authentication.
- Controlled administrative access.
- Regular review of user access.
- Removal of access when it is no longer required.
When implementing systems for clients, we also encourage access structures that reflect actual roles and responsibilities rather than providing unnecessary organization-wide access.
3. Cloud Platforms and Third-Party Systems
4. Digital Transformation and Client Systems
Our role in digital transformation frequently requires us to configure systems that contain important business and customer information. Security therefore forms part of the implementation process.
Depending on the project, this may include defining:
- User roles and permissions.
- Data access levels.
- Administrative privileges.
- Authentication requirements.
- Data sharing rules.
- Workflow permissions.
- Integration access.
- Document access.
- User onboarding and offboarding procedures.
The objective is not simply to make a system functional. It is to help ensure that people have access to the information they need without unnecessarily exposing information they do not.
5. Client Credentials
Where access credentials are required to perform an engagement, they should be handled carefully and shared only through appropriate methods.
Whenever possible, we prefer clients to create individual authorized user accounts rather than share primary administrator credentials.
Passwords and other authentication information should not be distributed unnecessarily or retained longer than required.
6. Data Minimization
7. Confidential Information
Information received through our work is treated as confidential where its nature, the circumstances, or contractual arrangements reasonably require confidentiality.
This may include:
- Business strategies and plans.
- Customer and prospect information.
- CRM and sales data.
- Financial and commercial information.
- Internal reports and documents.
- Employee information.
- Contracts and proposals.
- Proprietary processes and methodologies.
- Attendee and registration information.
- Sponsor and partner information.
Confidential information is not used for purposes unrelated to the engagement without appropriate authorization.


