Laserfiche WebLink
System Process and Data Security <br /> Data used in the Ticket Payment Program can travel through several servers. This is common for <br /> web ecommerce. At its beginning, data is taken from the Anoka County JLEC RMS system. The <br /> data is filtered to remove material which is protected by the Minnesota Data Practices Act. The <br /> remaining data is uploaded to a "cloud" server where pieces of data may pass to several venders <br /> who use it to process functions of the Ticket Payment Program. <br /> Initially, the data is uploaded to a server managed by SurveyGizmo. They provide cloud -based <br /> storage of the data and hold the educational components of the process. Once a defendant begins <br /> using the program some of their data initially appears through SurveyGizmo site and is passed to <br /> the UltraCart company server. Only basic information such as name, address, email, citation <br /> number, and offense codes are passed into a `shopping cart' of offenses. The cart calculates the <br /> total each user is asked to pay. The cart then passes data to merchant processor which takes <br /> credit card or check data. During the testing phase of the Program payments will be processed by <br /> the Intuit company (payments will be processed by Wells Fargo after the system is finalized). <br /> Payment data is downloaded back to an in -house server at MLS. Money is deposited to Wells <br /> Fargo. Credit card data is not transmitted to MLS, and is only used by the merchant processor. <br /> Below are descriptions from the vendors regarding their data security. <br /> Statement from SurveyGizmo website regarding Data Security <br /> How Secure is SurveyGizmo? <br /> All of the surveys and data collected reside on our servers. <br /> We use what is called Advanced Encryption Standard (AES) 256 bit encryption on secure survey <br /> links to transmit data back to our servers. <br /> The Advanced Encryption Standard (AES) is the encryption method used by the US government, <br /> including the US National Security Agency for classified top secret information. <br /> In regards to the servers themselves, our database, a MySQL database cluster, is a firewalled <br /> private network with tight system, database, application level security. We went through a 3 <br /> month long security review with a third party vendor called Applied Trust. We are already PCI <br /> compliant, and Applied Trust is working on recommendations for additional certifications. <br /> SurveyGizmo is scanned daily by HackerSafe to help protect data. It is monitored 24 -7 with a <br /> state of the art service and hardware based intrusion detection system <br /> Physical access is restricted, requires card access and is monitored 24 -7. <br /> Our data servers are managed by Viawest in their Denver facility. They are in high security data <br /> centers, monitored via closed circuit television and 24x7 onsite security personnel guard the <br /> facility while military-grade pass card access and biometric handscan units provide further layers <br /> of security. The facilities are equipped with an FM200 gas - based, hardware- friendly fire <br /> suppression system and diesel backup power generators. <br /> 3 <br />