Security
Insurance Lockbox understands the significance of securing your personal
information. Our company is very serious when it comes to the latest
technology and security features to secure your private data. You are
the only person given authority to access your information. You are
the only one who has access to allow an authorized user to view (but
not edit/change) your information.
Insurance Lockbox recommends
that users not enter full account numbers, usernames & passwords,
or social security numbers. If only partial account numbers are recorded
there will not be enough information for someone to commit identity
theft.
Here are some of the procedures we have implemented to make Insurance Lockbox
more secure:
Individualized Login
Each user is required to use a Username and Password each time they login.
The username and password are both required to be 8-15 characters long
and contain at least one number and one letter. Also the information
is encrypted during transmission to even further secure your personalized
login information.
Session Inactivity
If your Lockbox account is inactive for 30 minutes while your account
is open, our system automatically logs you out so that your information
is not compromised. This feature was added because many people step
away from their computers and leave the information on the screen that
can compromise their security. We apologize for any inconvience this
may cause during your usage, but the safety of information is the number
one priority.
Encryption
Insurance Lockbox uses an encrypted server for the storage of Lockbox
information. This encrypted database engine helps protect data from
unauthorized disclosure and tampering. The SQL Server Database Engine
security functionality includes highly granular authentication, authorization,
and validation mechanisms; strong encryption; security context switching
and impersonation. With built –in encryption key management and
facilities to handle encryption, decryption, and one-way hashing with
built- in T-SQL statements, SQL encryption is known to be an excellent
way for securing sensitive data. In other words this data is encrypted
in a layered approach; a hacker would have to have the SMK to decrypt
the DMK and have to have the DMK to decrypt the Certificates and the
Asymmetric keys. They would then have to have the Certificates and
Asymmetric keys to decrypt the symmetric keys, and obtain the symmetric
keys to decrypt the data.
Server Security
Insurance Lockbox’s servers are protected 24 hours a day by updated
firewalls that block unauthorized entry. The building and the room that
store the servers are also protected 24 hours a day by video surveillance
and triggered alarms. We also have a disaster recovery program which
requires us to keep backup copies of everything that is on Insurance Lockbox’s server off site. This backup site is also protected 24
hours a day by updated firewalls, surveillance, and triggered alarms.
So, as you can see, your information is being securely stored and is
not subject to disposal.
Image Verification
Insurance Lockbox has administered visual image verifications (called
security codes) for added security on our site. You will notices these
images at the time of logging in and signing up your account. You may
have seen this before on different websites, but have never known what
exactly it was used to prevent. These images help block computers from
generating usernames and passwords to try to hack into an account.
Due to the distorted view, computers cannot read the image and enter
it into the field.