1.The datacenter has the following in place for our network of servers:
1. Firewall
2. Physical facility security
3. Hardware replacement and software upgrades to patch security related issues.
2. Security related to server hardware and software is handled by the datacenter.
3. SSL Certificates are provided by us through Let's Encrypt, at our sole discretion. We do not allow our clients to provide an SSL certificate. SSL Certificates are not customizable.
4. We are SAQ-A PCI Compliant due to not storing or processing credit card information on our websites. Any payment processing is handled by third parties and on their website.
5. We do not allow sensitive information to be stored on the website such as banking information and social security numbers.
6. Each website user must use their own username and password to log into the website. Multiple people are not allowed to share a login to the website. A Website Administrator determines which users have access to log into the website.
7. User passwords are stored as hashed values.
8. Any technology related details not explained in this section are confidential. Therefore, we do not answer questions regarding security. Revealing any additional details regarding security would create a risk to our clients because an attacker could use that information to launch a better planned attack.