Our network, application, physical, and
administrative security technologies and procedures combine
to provide a completely secure computing environment. We are
committed to keeping your information private and secure. We
use industry-leading technologies and policies to protect the
confidentiality of your customer data and personal information,
and we will continue to update our systems to stay at the forefront
of security processes and technologies.
Encryption Between Your Browser
and Our Servers
Data in transport is secured with 128-bit SSL3 encryption using VeriSign
Class 3 certificates. This is the same industry-standard Secure Sockets
Layer (SSL) protocol that leading e-commerce and financial service providers
use to encrypt your information so that it cannot be understood by other
people. This encryption ensures the privacy of your data as it flows
between your Web browser and our servers. Our solutions can enable strong
128-bit SSL encryption with U.S. versions of Microsoft and Netscape browsers,
or 40/56-bit SSL with non-U.S. version browsers. Authentication and encryption
can be upgraded to include VPN, PKI, and classified encryption for US
DoD customers.
Login ID and User Password
To ensure that our members identify themselves in a secure and reliable
way, we employ a dual-method authentication system. We require the
use of your exact Login ID, and your User Password to log in to our
Server. Your login information is stored on our physically secure servers
in an encrypted format, which makes it completely unreadable and protected
from external harm and fraudulent activity. The Password is chosen
by the User and is encrypted so that even our employees and systems
administrators cannot access it. We also maintain access logs and other
documentation to provide accountability.
Firewalls and physical security
Our dedicated network is located in secure, limited-access facilities
and is guarded around the clock. Multiple firewalls prevent unauthorized
electronic access to the data environment. Authentication mechanisms
and discretionary access controls prevent authorized users from accessing
unauthorized data and services.
|