Security
Operational security is part of the platform design
ISPinnacle separates browser, application, payment, RADIUS, and RouterOS responsibilities so sensitive operations can be validated and controlled at server boundaries.
Last updated: 5 August 2026
Identity and organization access
Authentication protects private organization and ISP routes. Organization membership and role-aware checks are applied to sensitive customer, device, billing, and administrative workflows.
Secrets and device credentials
Payment credentials, database access, and MikroTik connection secrets belong in server-side configuration. Device operations run through a dedicated control service rather than sending raw credentials to browser code.
Validated service boundaries
Public API inputs and gateway callbacks are validated before business logic runs. Financial and access workflows use consistent records and actionable error handling so failures can be investigated without disclosing secrets.
Responsible reporting
If you believe you have found a security issue, email mail@ispinnacle.co.ke with a clear description and steps to reproduce. Do not access, alter, or retain data that does not belong to you.
Questions?
Contact us at mail@ispinnacle.co.ke.