CatalogueSafe and trusted23of36

The padlock, and the half of it nobody sees

The site carries the padlock a customer looks for, what is stored is locked where it sits, and the parts of the system talk to each other the same way.

What arrives

The padlock
on every page of the site I build for you
What is stored
is locked where it sits, not only on the way there
The copies
kept for safety are locked the same way as the original
A stolen disk
is not a readable copy of your business
The parts
of the system talk to each other locked, not only to the outside
Old, weak connections
are refused rather than quietly allowed through

The part a customer actually checks#

Most people could not tell you what encryption is and can tell you instantly when the padlock is missing. Browsers stopped being subtle about it years ago, and a warning page standing between a customer and your prices is the most expensive kind of technical detail there is.

The half nobody sees#

The padlock covers the journey. It says nothing about what happens once the information arrives, and that is where most of the risk sits - a database on a disk somewhere, a copy kept for safety, an export somebody made in a hurry.

So what is stored is locked too, and so are the copies. A disk in the wrong hands is a disk of nothing readable, which is the difference between an incident and a disaster.

What a lock cannot do#

This protects the road and it protects the store. It does not protect a person who is talked into handing over their own password, and no amount of it ever will.

And it is worth being exact about the store rather than letting you assume more than is true. Locking the disk defeats somebody who walks off with the hardware. It does not defeat somebody who has legitimately got into the running system, because to that person the information is simply readable. Which is why who is allowed in at all is the more useful conversation, and it has a page of its own.