July 13th, 2011

Data Security in Lavante Application

by

There has been much press recently about websites being hacked, raising the security stakes for businesses that rely on the internet and SaaS-based systems.  At Lavante we take data security very seriously, and continuously improve our processes and technologies to protect our customer’s and supplier’s data.

Here are several concrete steps we have taken to address such security issues:

  1. SAS 70 Certification: Lavante has recently undergone SAS 70 Type II certification.  Statement on Auditing Standards (SAS) No. 70 is a widely-recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA).  It represents that a service organization has been through an in-depth audit of their control objectives and control activities, including controls over information technology and related processes. Lavante further underscored its commitment to data security and protection by migrating its hosting to a leading U.S. SAS 70 data center that provides state-of-the art, secure, SAS 70 data center IT infrastructure.  Lavante has always maintained the highest security and control of data, but the new Type II certification along with the move to this new facility provides additional guarantees that customer data is secure.  You can find additional details at http://www.lavante.com/sas-70-certification.
  2. McAfee SECURE certification: Websites displaying McAfee SECURE symbol are tested and certified daily to pass McAfee security scan which help protect you from identity theft, viruses, spyware, and other online dangers.  More details at https://www.mcafeesecure.com/RatingVerify?ref=connect.lavante.com.  You will find a McAfee SECURE seal in our application login page.
  3. DigiCert certification: DigiCert® (http://www.digicert.com/) provides security to Lavante by enabling the encryption of data transmitted between Lavante and your browser during an encrypted SSL/TLS session (look for the padlock). DigiCert® has verified that Lavante controls its site/domain. Records reviewed by DigiCert® confirm Lavante to be an existing Entity/Organization at the time of the review.  You will also find a DigiCert seal in our login page.
  4. Encryption of sensitive data: In addition to above security measure all sensitive data such as password, tax identification and banking information are also encrypted in Lavante Supplier Information Management application.

This is a rapidly evolving area.  I welcome your comments about any of these security measures and the related trends.

Tags: , ,

Leave a Reply