Searching...
Filters
SmallMediumLarge
Home Print Show Topic URL Previous Next

About AdvisorMail system security

AdvisorMail User Guide

AdvisorMail contains multiple security features to ensure the integrity of your company's archived emails. These features include:

128-Bit SSL Encryption - When you log into AdvisorMail, your session is SSL encryption between your browser and our servers.

System Administrator account - There is only one System Administrator account per instance of AdvisorMail. This account is the only one that has access to Controls, Auditors, and Office Admin pages of AdvisorMail. The System Administrator account is the only account that can perform the following actions:

  • Add, edit, or remove auditor accounts.

  • Add, edit, or remove Office instances.

  • Modify System Settings and predefined text.

Strong passwords - For security reasons, passwords must be created using suitably complex criteria.

The following table lists the password requirements for auditor and administrator passwords, including the changes that were introduced in the October 2017 release:

Table: Auditor and administrator password complexity requirements

Password complexity requirements from October 2017 release

Changes from previous release

Minimum of 10 characters.

The previous minimum was 6 characters.

Maximum of 40 characters.

At least one lowercase alphabetic character (a, b, c, and so on.)

At least one uppercase alphabetic character (A, B, C, and so on.)

At least one numeric character (1, 2, 3, and so on.)

At least one special character.

The special character can be any character in the ASCII range or the Extended ASCII range that is not an uppercase or lowercase alphabetic character, a numeric character, or a space.

New requirement.

No space characters.

New requirement.

The same character cannot be repeated three or more times consecutively (111, ###, and so on.)

The same password must not have been active within the past 365 days.

Password Expiration - Auditor passwords expire after 60 days. Auditors start to receive notification emails 7 days before their password expires. They receive one notification email a day up until one day before the password expires. If the auditor does not change their password, they receive an email on day 60 informing them that the password has expired. AdvisorMail also displays a warning window that informs the auditor how many days they have before their password expires. The warning displays every time they log on, starting 7 days before the password expires.

Sign-in Deactivation - AdvisorMail accounts are automatically deactivated after three unsuccessful sign-in attempts, when the user enters the sign-in name correctly but enters an incorrect password.

A user can reactivate a deactivated account by using the Forgot password? option on the AdvisorMail Sign-in screen.

Multi-Tier Architecture - AdvisorMail provides a two-tier architecture. This architecture allows a corporate compliance department oversight over multiple, geographically distributed compliance departments.

See AdvisorMail Multi-tier architecture