AuditConfirmations Security

Who independently certifies AuditConfirmations site security/privacy?

McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams    This site protected by Trustwave's Trusted Commerce program   

What sensitive information is stored or transmitted by AuditConfirmations?

AuditConfirmations does not store data highly susceptible to fraud. No data entered into our system as part of the confirmation process is data that would not be fully disclosed on the standard confirmation form sent through the Postal Service mail… a far less secure means of communication. Furthermore, AuditConfirmations does not ever store online banking login credentials or credit card information on our servers.

We do not ever see or store your client’s online banking information. Banking credentials are immediately destroyed upon authentication with the bank.

How does AuditConfirmations’ manage infrastructure security?

We use the most up to date technology available to make sure your data, and your client’s data, are secure.

  • All communications with the site is encrypted with full 128-256 bit SSL security. No connections are accepted from web browsers that do not offer this level of security.
  • Our servers are housed in outsourced secure SAS 70 Type II qualified datacenters.
  • System installations are built using hardened operating systems and web/application server stacks with ongoing protection from vulnerabilities.
  • System access and suspicious activity is logged and tracked for auditing purposes.
  • System infrastructure security is certified by Trustwave and McAfee.

How does AuditConfirmations’ manage application security?

  • Security is a key part of our application development lifecycle. Our code is designed to be secure from the start.
  • All aspects of the AuditConfirmations application are closely logged and monitored for suspicious activity.
  • Only technological platforms and development environments recognized industry-wide for security are in use.
  • Your account and all your confirmation data are password protected, and no one will be able to access the data unless you, your client, or their bank grants such permission.
  • All passwords are fully encrypted.
  • We perform internal application security testing on a regular basis.