Web Security Policies
Managing Security — We Care.
Your Security Matters
We understand that you're concerned about the security and privacy of your online transactions.
This is why we use end-to-end security to ensure that valuable data such as our installers and support files are encrypted when you get them from our site.
Our Website Server
We are using best-of-breed and state-of-the-art servers that include the following traits:
Physical Servers: Locked, security surveillance monitored, restricted access, uninterrupted backup power.
Encryption: Hard drives encrypted at rest, folders encrypted at rest, files encrypted at rest.
Certifications:
- Australian Government IRAP
- CDSA
- CSA CCM
- DIACAP
- DISA Level 2
- FDA 21 CFR Part 11
- EU Model Clause
- FedRAMP
- FERPA
- FIPS 140-2
- FISC
- HIPAA / HITECH
- IRAP / CCSL
- IRS 1075
- ISO 27001 / 27002:2013
- ISO/IEC 27018:2014
- MLPS
- MTCS SS Tier 3
- NIST
- NZ GCIO
- PCI DSS Level 1
- Singapore MTCS Standard
- SOC1/SSAE16/ISAE 3402 and SOC2
- TCS CCCPPF
- United Kingdom G-Cloud
And more…
Encryption In-Transit
We employ state-of-the-art data encryption to ensure safe and secure transactions to our site.
Your computer and ours agree to transpose whatever you are downloading using an unintelligible “hash” of characters that starts as a 2,048 or longer key string.
We employ Extended Validation SSL Certificates using 256 bit RSA Encryption.
Without the shared key, no one can understand our encrypted communication.
This is the same level of security used for VPN and banking communications.
We do not use a Web Application Firewall (WAF) to avoid man‑in‑the‑middle risks.
Encryption At Rest
Files on a hard drive are considered “at rest.”
Our hard drives use three levels of 256 bit at-rest encryption: Hard drives, folders, and files.
Drive encryption keys are held by a third party.
Physical theft would require decrypting the drive, folders, and files individually.
These measures make physical data theft extremely difficult.
Installer Encryption and Code Signing
Installers use Code Signing Certificates with 256 bit RSA encryption.
This outer shell prevents any code changes from running.
When you install our software, it is indeed built by us.
Code signing prevents “Publisher could not be verified” warnings.
Microsoft routinely updates trust certificates for clean installs.
Code Scanning
Security scanning prevents SQL injections, password exposure, and similar risks.
All exposure risks noted by scans are corrected.
What is SSL / TLS?
SSL is the security technology for encrypting a link between a web server and a browser.
All data passed remains private and secure using 256 bit encryption.
SSL has been replaced with TLS due to naming rights.
The term SSL has stuck over the years.
Secure sites show a padlock and https://.
SSL/TLS Minimum Requirements
We reject older browsers that do not meet minimum encryption standards.
SSL2, SSL3, TLS 1.0, and TLS 1.1 are not accepted.
TLS 1.2 is required.
You cannot read this page without meeting the minimum.
How Files Reach Our Server
Files are uploaded through secure 256 bit encrypted FTP.
Our upload credentials are extremely long and encrypted.
We code sign programs and installers and use ultra secure servers.
Encrypted in transit and at rest.
Email Security
Our email uses SSL transmission (AES256) and domain authentication via SPF and DKIM.
We use secure mail vaults for sensitive documents.
Are We Really FinSoft, LLC?
SSL Certificates verify our identity.
Checking certificates helps avoid spoof websites.
Click the padlock to verify ownership.
Our EV‑SSL certificates are issued by Comodo CA.
Comodo is Web Trust‑compliant.
EV certificates confirm legal accountability.
We demonstrated domain control and business legitimacy.
Seeing an EV‑SSL certificate confirms secure encryption and verified identity.