Built to be trusted.
Pinkk is an intelligence research tool, and trust has to hold whether you use it alone or across a team. Here is how we protect your data, your account, and your decisions.
Your data stays yours
Sensitive data is encrypted at rest. Reports are access-controlled and never exposed publicly. We do not sell your data or use it to train models.
Encrypted at rest
API keys and credentials are encrypted using application-level encryption. Decrypted only when needed.
Reports stay private
Reports are scoped per account and never served from a public URL. Access requires sign-in or a time-limited signed link.
Not sold, not shared
Your data is not sold, not used to train models, and not shared with third parties beyond what is needed to operate the service.
Export or delete anytime
Export reports as PDFs and delete your account and data at any time. No lock-in. See our Privacy Policy for details.
Account security
Accounts are protected from weak passwords, known-breached credentials, and throwaway signups.
Strong passwords
Passwords must be at least 12 characters with mixed case, numbers, and symbols. Enforced at registration, reset, and change.
Breach check on every password
New and changed passwords are checked against the Have I Been Pwned database. Compromised passwords are rejected before they can be set.
Optional 2FA
TOTP-based two-factor authentication using any standard authenticator app. Recovery codes generated at setup. Enable or disable anytime from account settings.
Disposable email blocking
Registrations using known disposable email domains are blocked, keeping accounts tied to real, reachable addresses.
Email verification required
Email verification is required before reaching the dashboard. Suspended accounts are signed out and blocked from logging back in.
Rate limiting and bot protection
Sensitive endpoints are rate limited. Forms use Cloudflare Turnstile to filter automated submissions.
Transparent when it matters
Two things are open to anyone — no account needed.
Live system status
99.94% · 30 daysUptime is monitored externally and published on our public status page, including per-component status and recent incidents.
View status pagePublic report verification
Every report carries a reference number (PKK-XXXX-XXXX). Anyone can confirm a report is genuine at /verify — without an account.
Verify a reportResponsible disclosure
Found a security issue? Report it privately through our contact page before public disclosure, and give us a reasonable window to investigate and fix. We will work with you in good faith.
Decisions you can stand behind.
Conservative, evidence-based findings, verifiable reports, and a platform built to handle your data carefully. Start free — no credit card required.