| secure, premium email & web services |
Call: 800-441-6612 International: +1 814-870-9250 sales@luxsci.com support@luxsci.com |
|
|
LuxSci Security Overview
Most service providers offer little or no security or protection. Most of those that claim to protect you provide only a veneer ... a basic level of security and privacy that falls far short of the needs of a modern organization. However, the security of your communications is at the very heart of LuxSci's founding principles, and has been a focus since our inception. Whether you are communicating with your internal users or with friends and associates at the other end of the Internet, LuxSci can keep your communications safe. We enable you to secure your exchanges and guarantee that they get to where they need to without being privy to prying eyes. And with our Premium Email Fltering services, you can keep the unwanted denizens of the Internet realm out of sight and out of mind. Why is Security Essential?
Infrastructure SecurityLuxSci's shared email services and premium dedicated servers reside in very high performance, high security, SAS70 Type II certified data centers &mdash see LuxSci's State-of-the-Art Data Center. Additionally, LuxSci's DNS services are resilient to denial of service attacks — see DNS at LuxSci -- Not your "Daddy's" DNS!. Privacy and Non-disclosure PoliciesIn addition to our access controls which allow you to specify who can see your information, LuxSci has a very strict privacy and non-disclosure policies - our technical support staff will never access your email or WebAides without your prior consent. Email SecurityEmail Security Highlights
End-To-End Email Encryption
SecureLine provides services compatible with PGP and S/MIME, as well as a secure message "Escrow" service that can be used to communicate securely with anyone. See Also: SecureLine End-To-End Email Encryption ServiceEmail Security (TLS and SSL) and Privacy FeaturesSecure WebMail: Your passwords and the contents of all of your messages are encrypted via SSL (Secure Socket Layer) when transmitted to our WebMail application. No one can eavesdrop, and you know for sure that you are communicating with LuxSci! Additionally, you can use our optional visual keyboard to enter your password using your mouse when logging into our WebMail portal. This tool helps you mitigate the possibility that spyware running on your computer (or the untrusted computer in the Internet Cafe that you may be using) could capture your password and deliver it to unauthorized people. Secure IMAP and POP: Regular IMAP and POP are insecure in that your username, password, and all your messages are sent back and forth to the email server in "plain text" so anyone listening in can see your messages and discover your password. With Secure IMAP and POP over SSL, all of this information is encrypted so that no one can eavesdrop or discover your password! Secure, Authenticated SMTP: Regular SMTP is insecure in the same way that regular IMAP and POP are, so anyone listening in can see your "plain text" messages and discover your password! With Secure SMTP, all of this information is encrypted so that no one can eavesdrop or discover your password! Our SMTP Server also requires authentication for SMTP Relaying so that you must send your username and password in order to send messages. This protects you and us from our servers being used for the sending of Spam. Our secure SMTP services are provided via both TLS (Transport Layer Security; STARTTLS for SMTP) and SSL, and are thus compatible with all email clients that support one of these mechanisms. Secure, Anonymous SMTP: Use our secure anonymous SMTP server to have all information about your computer, its Internet address, and your email client stripped from outgoing email messages. This provides enhanced privacy: your recipients will have no way of determining where you are sending your email from -- they will only be able to track the messages back to LuxSci's servers. Without this, recipients could use your computer address information to determine your physical location - the region, city, or even the address! Secure Inbound Email with TLS: LuxSci's inbound email servers support "Transport Layer Security - TLS". This allows email sent to you from other companies to be encrypted and secured during transit from their servers to LuxSci's servers, assuming the sender's servers support this feature. This also means that any email internally from one user to another on LuxSci is secured during transport. Login/Access Auditing: We track all logins to your account via POP, IMAP, SMTP, and WebMail. This includes the exact time and the IP address used, among other information. This auditing information is available to you, your account administrator, and technical support at all times. You can easily check if unwanted people or programs are logging into your accounts. Auditing of Email Sending: We track all messages sent from WebMail, your email servers (via SMTP), and your web sites. This allows you, your administrator, and our support team to see what email messages are being sent when and from where. It also allows us to proactively stop Spam attempts -- even if they are unintentional or the result of web site insecurity. Note, records of message content are not available to your administrators or our standard support teams, so this auditing does not tread on privacy concerns. Incoming Email Attack Guard: Attack Guard protects your messaging infrastructure from Denial of Service (DoS) attacks and other threats by the real-time monitoring and analysis of email traffic patterns. Dictionary attacks, mail bombs, email flooding and other attacks designed to interrupt service or harvest corporate or personal email addresses can be blocked with real-time detection. Additionally, the service scans the incoming Simple Mail Transport Protocol (SMTP) stream for abnormalities in protocol compliance and abuse. This service is automatically included as part of our Premium Email Filtering service. Customizable WebMail Session Timeouts: Account administrators and users can customize their WebMail session timeout from the default of 2 hours to anything between 5 minutes and 8 hours. Account administrators can optionally enforce that user timeouts are no longer than the account-wide default. Web Portal Security: XpressLuxSci provides an alternate secure members' web portal (the Xpress members' portal). Not only does the Xpress portal use minimal graphics for maximal speed, but it does not use cookies or JavaScript at all and suppresses some of the features of the full portal that may put you at risk, like viewing HTML attachments inline. The Xpress portal supports most of the features of the full members' portal (including WebMail, technical support, account administration, and file management facilities), and provides maximal browser compatibility and security. It is your choice if and when you use the Xpress portal or the Full portal (which does use cookies, JavaScript and more graphics). While the Xpress portal is faster and more secure, the full portal is more user friendly and somewhat more fully featured. See Also: About the Xpress portal. Web Hosting SecurityWeb Hosting Security Highlights
Account Administration Security FeaturesAccount Administration Security SettingsEnforced use of SSL: Account administrators can choose to force their users to only connect to our email services (i.e. WebMail, POP, IMAP, and SMTP) over SSL. When the account administrator enables this option by checking a single checkbox in his/her account, all account users will be denied access to these services unless they connect over SSL-secured channels. Thus, enforcing policies regarding security use is very easy. Password Security: In addition to the SSL-protection of usernames and passwords, administrators can customize the required degree of complexity for user passwords. This can be anywhere from very weak to very strong (8+ alphanumeric characters that pass the "crack" password guessing criteria). Login Session Enforcement: Account administrators can configure a maximum WebMail login session timeout for all users of anywhere from 5 minutes to 8 hours of inactivity. Administrative Access: Administrators can delegate administrative access to other account users on a per-domain basis, as needed. Administrators can also manage multiple LuxSci accounts from a single login if needed. SecureLine: Account administrators can enable SecureLine email encryption settings quickly and easily on an account-wide and/or domain-wide basis. This includes auto-creation of user PGP and S/MIME certificates, forced use of email encryption, inbound email auto-decryption, etc. Maximal Security SettingLuxSci provides account administrators with a "Maximal Security" button that allows them, in one click, to configure all of the global security options in their account to settings that ensure maximal security. This configures such things as forced use of SSL, strong passwords, and forced use of SecureLine (if you have purchased it) with S/MIME certificates. Account managers can also contact support to have these settings "Locked Down" so that no one in the account can alter them without contacting support directly, getting approval, and leaving an audit trail. If you want maximal email security and the assurance that it is setup correctly and cannot be circumvented, this is for you. Collaboration Security FeaturesLuxSci's WebAides allow you to create a variety of collaboration instruments such as Blogs and file archives. LuxSci ensures the security of your data in many ways, including:
HIPAA Security FeaturesAs far as HIPAA, the Health Insurance Portability and Accountability Act, is concerned, email compliance implies "securing patient records containing individually identifiable health information so that they are not readily available to those who do not need them". It does not specify what technologies must be used to do this, leaving that decision up to the individual health care organizations. LuxSci allows health care and other organizations to meet and exceed these goals by providing:
See also:
Pricing
|
|
|
about us |
blog |
services |
quotes & orders |
privacy |
contact us |
site map |
login |
xpress
Copyright © 2004-2010 Lux Scientiae®, Incorporated |