|
Physio-med
::
Security
|
At Physio-Med Services LTD we take the issue of online security very seriously in order to protect our reputation as the UK's largest supplier of rehabilitation products to the NHS.
Below is information about some of the measures we take to ensure that your shopping experience with us is as safe as possible.
Compliance
We are registered in compliance with the Data Protection Act. Security Policy We utilise a secure server encryption method to securely transfer all credit or debit card details. This is provided by Protx.
Secure server
We use a secure server which encrypts your credit card information during transmission from the webpages to the database. A secure server webpage is different to a normal webpage. You will know you are on a secure webpage because the padlock will be displayed. The web address will also change to indicate a secure server, so that it now starts with
1. https: When this happens you will know that any information you type into that page will be encrypted when it is sent out.
2. You may also double click on the padlock that can be found at the end of the address bar in FIREFOX Browser and also at the lower Right of the screen. Upon double clicking this it will display an information Pane stating that our THAWTE Security status and certificate of authenticity is in date and valid
3. In Microsofts Internet Exporer the padlock can be found at the Lower Right of the screen. Upon double clicking this it will display an information Pane stating that our THAWTE Security status and certificate of authenticity is in date and valid.
Transaction security
All transaction information passed between the Physio-Med Services LTD and the Protx System is encrypted using 128-bit SSL certificates. No cardholder information is ever passed unencrypted and any messages sent to your servers from Protx are signed using MD5 hashing to prevent tampering. You can be completely secure in the knowledge that nothing you pass to the Protx servers can be examined, used or modified by any third parties attempting to gain access to sensitive information.
Encryption and Data Storage
Once on the systems, all sensitive data is secured using the same internationally recognised 256-bit encryption standards used by, among others, the US Government. The encryption keys are held on state-of-the-art, tamper proof systems in the same family as those used to secure VeriSign's Global Root certificate, making them all but impossible to extract. The data held is extremely secure and Protx is regularly audited by the banks and banking authorities to ensure it remains secure.
What about Server and Firewall security?
The database servers, where your personal details are stored, are not accessible from the internet. They are continually updated to have the latest versions of software ("patches") providing the highest levels of security and reliability available for those systems.