By Jeff Hudesman, CISO
Ensuring Digital Security
In the rapidly evolving digital world, the importance of security cannot be overstated. As the Chief Information Security Officer at Pinwheel, I'm at the forefront of our battle against digital threats. Our mission is clear: to safeguard our clients' data with the most robust security measures available. This dedication is embodied in our two flagship products: Pinwheel Core and Pinwheel Prime.
Overview of Pinwheel's Products and Their Security Measures
The Foundation of Trust: Pinwheel Core
Pinwheel Core is not just a product; it's a commitment to security. We pride ourselves on adhering to some of the most stringent security standards in the industry, including ISO 27001, SOC 2 Type II, and PCI DSS Level 2 compliance. Our system enforces TLS 1.2+ and strict OAuth2 authentication/authorization, ensuring that all transactions are secure and verified.
The protection of sensitive data is a cornerstone of Pinwheel Core. We use field-level AES256 encryption and tokenization for both the temporary storage of end-user credentials and Pinwheel-collected Personally Identifiable Information (PII). Moreover, our commitment to data privacy extends to our rigorous internal access controls, including role-based access policies, hardware security keys for multifactor authentication, and comprehensive SIEM logging and monitoring.
One question I often receive from clients is “how does the security of Pinwheel Core compare to Atomic’s TrueAuth?” The answer is simple: they’re exactly the same. Both product offerings utilize encrypted device-based authentication, removing the need for users to share credentials with a third party (us or Atomic).
The Industry’s Most Advanced Solution: Pinwheel Prime
Our next generation product elevates deposit switching security to new heights. Pinwheel Prime’s significant security enhancements are tailored to meet the sophisticated requirements of the world’s largest banks. Pinwheel Prime is the first and only solution available that is completely credential-less, eliminating the requirement for a user to enter PII or payroll credentials to identify and authenticate their account. By inventing a new way of proactively matching a bank customer with their associated payroll record across our proprietary network of payroll partners, we have radically minimized the storage and transmission of sensitive data. We interface directly with official payroll APIs with secure client authentication (e.g., OAuth2 access tokens), for narrowly scoped access to payroll systems.
Our pioneering internal PII Tokenizer service ensures that customer-provided PII is instantly tokenized upon receipt, with UUID tokens used throughout our system to further secure data.
Pinwheel Prime also utilizes mTLS enforcement and payload encryption for all PII transmissions, a testament to our commitment to end-to-end security. Pinwheel’s encryption strategy is meticulous, with multi-layered encryption keys managed and automatically rotated in accordance with security best practices.
Addressing Security Challenges
At Pinwheel, we understand that the security landscape is ever-changing. Our approach to security is proactive and comprehensive, encompassing everything from supply chain risk analysis to bi-annual penetration testing and weekly vulnerability scanning. Our robust monitoring and incident response processes ensure that we are always ready to respond to security events, safeguarding our clients' data.
The Future of Security at Pinwheel
As we look to the future, our commitment to innovation and excellence in security remains unwavering. We are continuously exploring new technologies and methodologies to enhance the security and reliability of our products. Our vision is clear: to lead the industry in security excellence, ensuring that our clients can conduct their business securely and confidently.
In conclusion, the security measures that have always been embedded in Pinwheel Core and the bleeding edge security enhancements of Pinwheel Prime demonstrate our industry-leading position on security. At Pinwheel, we are dedicated to providing our clients with the highest level of security and privacy protection, today and into the future. We invite you to join us on this journey, as we continue to set new standards for digital trust and security.
For more information about our products and our approach to security, please explore our security page or contact us.