Security

ReachVault holds a wallet for you that you fund with mobile money, then use to buy crypto, redeem gift cards, send money, and grow it in fixed-term plans. This page describes the structural choices we've made to keep your account and your money safe — plainly, and without claiming certifications we don't hold.

How we protect your account

  • Passwords and transaction PINs are hashed — never stored in plain text, and never visible to our staff.
  • Every sign-in and every money-moving action is tied to your account and logged with a timestamp.
  • Your session token lives in memory in your browser, not in local storage — a safer place for it to sit.

How we protect your money

  • Every transaction moves through a double-entry ledger — money never appears or disappears without a matching, auditable entry.
  • Deposits, withdrawals, crypto orders, and transfers each go through the same compose-review-authorise flow, with a PIN required before anything moves.
  • We never show a balance change until the server has confirmed it. No optimistic numbers, no flickering totals.

How we stay accountable

  • Every action taken on your account — by you or by our staff — is logged, including what changed and when.
  • Consent to our Terms, Privacy Policy, and risk disclosures is versioned, timestamped, and available to you at any time under Settings → Consents.
  • If our terms change in a way that affects you, you'll be asked to review and accept the new version before you can move money again.

Found a security issue, or have a question about how we handle your data? Reach us at the support address in the footer below — we treat every report seriously.