The security Online safe for your Data and Password
Highly-secure and internationally renowned encryption methods (AES-256 using PBKDF#2, RSA-2048) for the encryption of all customer data.
My Secrets Online Data safe offers you even more privacy than a bank account. Neither malicious hackers itself can ever view your data. The Security Internet data safes provide the same high level of security as modern e-banking solutions.
Strong User Authentication:
Username and password with Secure Remote Password Protocol (SRP).
2-Factor authentication (mTAN, SRP) with My Secrets Password Basic Annual, Full Annual, Full Fifth and Eternal.
On the iPhone/ iPad/ Android mTAN is enhanced with the Security Innovation.
Encryption on the user computer/ iPhone/iPad:
My Secrets encrypts with a session key AES-256 all passwords that are temporary loaded in the memory of the user computer.
My Secrets encrypts with AES-256 keys all data that are locally stored on the iPhone/iPad for the use of the app in offline mode.
Secure Document Viewing:
View PDF documents and images securely directly in the safe without leaving traces on the local computer.
Highest protection of user credentials, meta-data and password-safe entries:
User credentials, meta-data and password-safe entries are double protected (AES-256).
In addition to SSL protection, My Secrets uses a session key to encrypt particularly sensitive data such as your user data and passwords saved in My Secrets.
AES-256 with a session key created during SRP authentication.
In contrast to other methods, My Secrets NEVER has to buffer your personal password or elements derived directly from it.
Username and password with Secure Remote Password Protocol (SRP).
EV certificates are only given to companies that have been explicitly verified.
You can recognize the EV certificate by the background color in the address field of your browser.
Servers Security:
Disaster recovery management by triple application mirroring across 2 datacenters 24h monitoring and alert escalation.
My Secrets applications are designed following NIST security standards.
OS and third party applications constantly updated and hardened.
Penetration testing by top security experts.
Daily security checks by Verysign.
Username and password with Secure Remote Password Protocol (SRP).
Highest physical security, certified by the banking commission.
All user data are encrypted strongly.Each document receives its own encryption
In contrast to many other companies, we provides customer-specific encryption for your data. This means that each document has its own key, and this security key is hung on a customer-specific key-ring.
My Secrets encrypts all customer data using a selection of highly-secure and internationally renowned encryption methods.
The key required to decrypt your data is created directly from your password using PBKDF#2 (RFC-2898). Your My Secrets online safe is thus protected from malicious hackers. Even My Secrets can never view your stored data and passwords.
AES-256 and RSA-2048 are used as encryption standards. These encryption methods are designed to provide a maximum level of protection for many years.
The world-leading external vulnerability assessment from VerySign By Norton protects against internet crime and hacker attacks.
Double protection for your data when being transferred over the internet
My Secrets uses EV SSL certificates. EV certificates are only given to companies that have been explicitly verified. You can recognize the EV certificate by the background color in the address field of your browser.
In addition to SSL protection, My Secrets uses a session key to encrypt particularly sensitive data such as your user data and passwords saved in My Secrets. This additional encryption provides extra protection against man-in-the-middle attacks, for example at internet cafés or airports.
Secure login & strong text-message authentication:
My Secrets has implemented the Secure Remote Password Protocol. This means that your data and passwords stored in your online safe remain optimally protected, and also means that you should never forget your login information, your data will be lost.
My Secrets offers you SMS authentication (mobile TAN), you will receive an additional code by SMS text for every login. This protects your account even if your password is revealed to an attacker.