Robot Objects Security Policy
General
When it comes to security, our first priority is to ensure that the information contained on our website or any of our IT systems is only available to authorized people within an authorized context.
Although we cannot divulge all of our methods, Robot Objects proactively takes every reasonable precaution to safeguard our data and the IT systems on which it resides.
Unfortunately, in the reality of today’s world, there is no way to be 100% assured that a system will not be compromised. With that in mind, we take further precautions to ensure that data is not needlessly exposed. A few of our precautions: We don’t keep data on servers that are exposed to the Internet unless that data is needed by our webservers; Transaction data is removed from Internet exposed servers in a timely fashion; And we never store Credit Card numbers or related information.
Encryption
Our servers utilize 256-bit RSA encryption for all sensitive activity between our site and your computer. This is the highest form of encryption available for websites. Your browser should indicate that it is in Secure Mode for these pages. MicroSoft’s Internet Explorer, for instance, displays a small padlock icon at the bottom of the browser.
Credit Card Transactions
All Credit Card transactions are conducted with 256-bit RSA encryption as described above. When you enter your Credit Card information on your browser, your browser sends the information to our server in an encrypted format. We then route that information, again using 256-bit encryption, to our real-time payment processor to obtain authorization for the purchase.
By utilizing a real-time authorization service, there is no need for us to ever even record your credit card number. Therefore credit card numbers are NEVER stored on the Robot Objects website or on any Robot Objects equipment. We store only the authorization/denial code received from our card processing service.
Account Information
Strict adherence to our Privacy Policy also ensures that all of your account information is held in the highest confidence. We don't collect data that is not needed to process an order. Within our organization, we only provide account access to employees with a need for such access.
Account passwords are stored in an encrypted format. This encryption involves a "one-way hash" developed at MIT so that the password cannot be read from the database. Not even our own database administrators could determine your password. (If you lose your password, we can't tell you what it is, but instead issue a new, temporary password). There is no known method for unencrypting the passwords.
Furthermore, and as noted above, all web pages used for accessing or editing account information are encrypted.
|