Security

Operational security is part of the platform design

ISPinnacle separates browser, application, payment, RADIUS, and RouterOS responsibilities so sensitive operations can be validated and controlled at server boundaries.

Last updated: 5 August 2026

Identity and organization access

Authentication protects private organization and ISP routes. Organization membership and role-aware checks are applied to sensitive customer, device, billing, and administrative workflows.

Secrets and device credentials

Payment credentials, database access, and MikroTik connection secrets belong in server-side configuration. Device operations run through a dedicated control service rather than sending raw credentials to browser code.

Validated service boundaries

Public API inputs and gateway callbacks are validated before business logic runs. Financial and access workflows use consistent records and actionable error handling so failures can be investigated without disclosing secrets.

Responsible reporting

If you believe you have found a security issue, email mail@ispinnacle.co.ke with a clear description and steps to reproduce. Do not access, alter, or retain data that does not belong to you.

Questions?

Contact us at mail@ispinnacle.co.ke.