Security Policy
We understand that the
security of your personal and account
information is important to you. To assist us in offering these
Web-based secure
online payment services in a secure manner, we employ a number of
measures,
which are described below. These measures allow us, among other
benefits, to
properly authenticate your identity when you access these services and
protect
your information as it traverses on the Internet.
Encryption
Whenever
you access
pages requesting or presenting sensitive financial or personal data, we
will
encrypt that data to prevent others from accessing it while in transit.
We utilize
Secure Socket Layer (SSL) encryption for this purpose. We require the
use of
128-bit SSL encryption in order to protect sensitive information.
We usually use PayPal.com company for
integrated secure online payments.
See how it works:
Plese visit website for more information:
http://www.paypal.com/cgi-bin/webscr?cmd=_security-center-outside
Payment
gateway ompany that we use for integrated secure onile
payments for pharmaceutical companies is approved by the most of UK
Banks in terms of security and have the following security policy:
Security
As a
Payment Service Provider, thousands of businesses outsource their
transaction security to us. It is our top priority to ensure that
transaction
data is kept secure at all times.
Transaction
security
All transaction information passed between merchant sites and the
Company VSP
Systems is encrypted using 128-bit SSL certificates. No cardholder
information
is ever passed unencrypted and any messages sent to your servers from
Company
are signed using MD5 hashing to prevent tampering. You can be
completely secure
in the knowledge that nothing you pass to the Company servers can be
examined,
used or modified by any third parties attempting to gain access to
sensitive
information.
Encryption
and Data Storage
Once on our systems, all sensitive data is secured using the same
internationally recognised 256-bit encryption standards used by, among
others,
the US Government. The encryption keys are held on state-of-the-art,
tamper
proof systems in the same family as those used to secure VeriSign's
Global Root
certificate, making them all but impossible to extract. The data we
hold is
extremely secure and we are regularly audited by the banks and banking
authorities to ensure it remains so.
Links to banks
Company has multiple private links into the banking network that are
completely
separate from the Internet and which do not cross any publicly
accessible
networks. Any cardholder information sent to the banks and any
authorisation
message coming back is secure and cannot be tampered with.
Employee
access
No individuals within Company are able to decrypt transaction
information or
cardholder data. Our systems only allow access to our most senior staff
and
only in extenuating circumstances (such as investigations of Card Fraud
by the
Police). Your transaction information and customer card information is
secure
even form our own employees because our systems never display the full
card
numbers, even on administration screens.
|