Security
ReachVault holds a wallet for you that you fund with mobile money, then use to buy crypto, redeem gift cards, send money, and grow it in fixed-term plans. This page describes the structural choices we've made to keep your account and your money safe — plainly, and without claiming certifications we don't hold.
How we protect your account
- Passwords and transaction PINs are hashed — never stored in plain text, and never visible to our staff.
- Every sign-in and every money-moving action is tied to your account and logged with a timestamp.
- Your session token lives in memory in your browser, not in local storage — a safer place for it to sit.
How we protect your money
- Every transaction moves through a double-entry ledger — money never appears or disappears without a matching, auditable entry.
- Deposits, withdrawals, crypto orders, and transfers each go through the same compose-review-authorise flow, with a PIN required before anything moves.
- We never show a balance change until the server has confirmed it. No optimistic numbers, no flickering totals.
How we stay accountable
- Every action taken on your account — by you or by our staff — is logged, including what changed and when.
- Consent to our Terms, Privacy Policy, and risk disclosures is versioned, timestamped, and available to you at any time under Settings → Consents.
- If our terms change in a way that affects you, you'll be asked to review and accept the new version before you can move money again.
Found a security issue, or have a question about how we handle your data? Reach us at the support address in the footer below — we treat every report seriously.