Secure Shopping

You can use any of the payment types listed in the payment area when you make an order to pay for your order. All Payment services are established leaders in the field of secure transaction processing.

1. Payment Services

When you shop with us, our secure server encrypts all of your personal information, including name, address and credit card information. We use Stripe which are an industry leader in secure internet transactions. Stripe is used by thousands of other UK businesses for transaction security.

All transaction information passed between our website and the Stripe Payment System is encrypted using AES-256 SSL certificates. No cardholder information is ever passed unencrypted and all messages from Stripe are signed using MD5 hashing to prevent tampering. You can be completely secure in the knowledge that nothing passed to Stripe can be examined, used or modified by any third parties attempting to gain access to sensitive information.

Once on the Stripe system, all sensitive data is secured using the same internationally recognised 256-bit encryption standards used by, among others, the US Government. The encryption keys are held on state-of-the-art, tamper proof systems in the same family as those used to secure VeriSign's Global Root certificate, making them all but impossible to extract. The data they hold is extremely secure and they are regularly audited by the banks and banking authorities to ensure it remains so.

Stripe has multiple private links into the banking network that are completely separate from the Internet and which do not cross any publicly accessible networks. Any cardholder information sent to the banks and any authorisation message coming back is secure and cannot be tampered with.

No individuals within our company or Stripe are able to decrypt transaction information or cardholder data. Their systems only allow access to our most senior staff and only in extenuating circumstances (such as investigations of Card Fraud by the Police). Your card information is secure even from their own employees because the systems never display the full card numbers, even on administration screens.

2. Website Security

We are certified by ESET SSL Filter CA to *edinburghcashmere.co.uk, and we go through rigorous daily checks of network security.

The process of certification is completed in six stages. The first three stages comprise the dynamic detection ports (Dynamic Port Scanning), screened at port level (Port-level Network Services Vulnerability Testing), and the screening of the web application (Web Application Vulnerability Testing).

The next two stages, the fourth and fifth, are the updates that are sent in case of detected security problems and the remediation management of these problems.

The result of this process is to have a dynamic secure website.