EnergySteward.com provides a comprehensive security model to
protect contract information AND to secure the interactions with that
contract information. These levels of security include:
- Strong SSL encryption (web browser, ala. the padlock notice) for all interactions
between your web browser and our production application server environment.
Please note, this is the same level of security that most online
banking institutions employ for their financial transactions.
- Datacenter layer 7 firewall rules are in force for all
transmissions to and from web browsers to the application server
environment.
- Application level login authentication (requiring login,
password and company for proper identification).
- Login authentication rules can be setup to require changes in
passwords on periodic frequencies (ie.. every 90 days, etc.).
- Login password changes can be set to restrict the 'reuse' of
passwords.
- Any optional business-2-business web service access against the application data restricted to
data center to data center (IP-to-IP) rules. Both firewall AND application IP checks done
within the web application server environment.
- Any optional business-2-business web service access against the application data also requires
login authentication credentials (just like access thru the web
application front end).
- Any optional business-2-business web service access against the
application data also requires strong SSL encrypted data
transmissions.
- All database and transaction logs backed up on a daily basis.
- Offsite disaster recovery backups of all data done on a weekly
basis.
At EnergySteward.com, we understand that contract information is a
vital asset to a company. We treat this data with the same level
of protection that typical banking institutions, etc. would have with
their customers data.
Click on the thumbnail images
(below left) to see a few sample screen shots. |