Security

Built like a bank.

Reach is designed with the security posture of a fintech, from encryption to compliance-ready architecture.

Encryption at every layer

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Sensitive fields are additionally envelope-encrypted per user.

Biometric login

Face ID and Touch ID on iOS. Biometric unlock on Android. Password + 2FA fallback for the web.

2FA and passkeys

Time-based one-time passwords and WebAuthn passkeys supported for every account.

Role-based permissions

Wallet owners, contributors, and viewers each see exactly what they should — nothing more.

Full audit logs

Every contribution, vote, release, and admin action is logged and available on request.

Ready for KYC/AML

The platform is architected for compliance with US and EU banking regulations as we roll out payments with partner institutions.

Reach is not a bank. Banking, custody, and money movement services will be provided by regulated partner institutions. This page describes Reach's product and platform practices; it is not a legal or regulatory disclosure.