Showing posts with label Updates. Show all posts
Showing posts with label Updates. Show all posts

Tuesday, May 8, 2012

SSL makes Go2Show More Secure


Proper management of credit card information has always been a concern taken seriously by calan. 

The ever increasing utilization of the application has heightened the concern that both you and calan take all reasonable business steps to protect that information. As a result we have elected to take an aggressive set of measures as to how we COLLECT, DISPERSE and ARCHIVE credit card information. 

First, we have a difficult business model to accommodate. In discussions, all of you have indicated a reluctance to absorb the costs of a third party payment firm.  calan has no desire to become a bank where we incur additional accounting costs and assume greater business risks, that we would be forced to pass on to you in the form of higher subscription rates. However we do want to improve our management of this information.

Based on our research of PCI compliance requirements there are three main areas of concern. The collection of the information and perhaps even more important what happens with the information once it is collected with respect to dispersal and archiving. 

As this is clearly a sensitive and critical component of successful customer service and internal business work flow we want you to be aware of our migration plan and timing so you can manage your customer’s expectations and internal teams. There is a timeline at the end of the three initiatives we are undertaking for you review. 

Here is how we will be addressing each of those three critical components of information management:

 1: How we COLLECT information 
We have obtained an SSL certificate and created a secure transaction page. When implemented, Users who select to pay by credit card on the Payment Selection screen will receive a pop-up that they are being redirected to a secure site. They will be given an option to decline. If they so choose, they will be returned to the Payment Selection screen where they can select and alternative payment type. 

Once on the SSL credit card entry screen the User will be informed of the following:
The credit card information will be emailed to your Program Manager and then deleted.
Should you need to update your information please contact:
< Name of G2S Program Manger of the G2S URL inserted >
< Phone of G2S Program Manger of the G2S URL inserted >
< Email of G2S Program Manger of the G2S URL inserted >

Should you wish to cancel select the “X” in the upper right corner to close this secure pop-up.

Note:
All credit card information will be required to click Submit. The User can not Submit without making appropriate entries.

We DO NOT validate the card.

On Cancel by the User (Should they exit out of the SSL Pop-up without selecting Submit)
calan will purge any credit card information entered and return the User to the Payment Selection screen. The User may select an alternative payment type.

On Submit by the User
The User is provided a POP-UP.
You are leaving the SSL secured environment.
You will be returned to the Payment Selection Screen where you can change you Payment Type if you wish.
When you select NEXT on the Payment screen your information will be sent to your Program Manger and deleted.

calan will accept the credit card information entered for use in an email. 

When the User is clicks NEXT from the Payment Screen a confirming alert statement appears:
Your credit card information has been emailed to your Program Manager and deleted.
The credit card information for this order can no longer be edited.
If you canceled your credit card entry, please select Cancel below and choose another payment type from the Payment screen drop down.
Select OK to continue with your order.

When the User clicks NEXT from the payment screen, the information will be sent in an email to the designated < email of G2S Program Manger of the G2S URL > and purged from our servers.


A User returning to the Payment Screen in Edit mode will see the following:
The credit card information previously entered is on file.
Should you need to update your credit card information or change the payment type selection please contact:
< Name of G2S Program Manger of the G2S URL inserted >
< Phone of G2S Program Manger of the G2S URL inserted >
< Email of G2S Program Manger of the G2S URL inserted >

2. How we DISPERSE information collected
The information collected is immediately  sent in an email to the email alias of your designated Program Manager for the G2S URL when the User clicks Submit on our SSL credit card collection screen.

The credit card information collected is not written to any other screen or report.
In all cases where the information might be expected to appear there is an insert:
Credit Card on File with:
                < Name of G2S URL Program Manager >
                < Phone of G2S URL Program Manager >
< Email of G2S URL Program Manager >

calan no longer retains any credit card information on our servers.

3. How we ARCHIVE the information collected
calan does not retain any credit card information on the system servers or the email servers used to send the information to your G2S Program manager; except for the few seconds that the information is on our servers as the automated email is built and sent, calan does not hold the information in any form outside of our SSL collection environment. Your Program Manager is the only individual in possession of this information.
To support the cut over to our new procedures we have built a report that will allow you to capture your entire history of credit card activity, should you choose to do so. Please contact us at support@calancom.com to confirm if you want this data and to arrange for a transfer of existing records. The timeline at the end of this document indicates our PURGE date.

 4. What you should consider:
calan has passed the information to a single email alias for your Program Manager. Once received the information should be managed within your own protocols to ensure that the dispersal of the information is restricted to an identified set of individuals and that any archiving of the information is done in an encrypted environment.

Printed copies should be strictly limited, restricted in distribution and destroyed when no longer required.

Should you need to contact your customer regarding the card for any reason the Project Summary will identify who entered the request and provide their contact information?
As noted above the external User placing the order is provided your Program Manager’s contact information should they need to contact you with respect to the credit card information or any other issues pertaining to the selected payment type for their order.

Deployment Timeline:

Date

Step Taken
May 8

Go2Show SSL initiative advisory released.
Please begin any communication efforts you feel appropriate to your customers and internal employees.
May 15

Cut over to SSL credit card collection process implemented
Note: For the first week, ending on May 21, the immediate delete of the information collected will NOT be executed, This is to allow for your validation of the process and accommodate any internal adjustments to your internal work flow.
May 23

Immediate delete of collected information from calan servers implemented.
Individual Site data purges begin. History reports available if requested.
May 31

All credit card history for all sites will be purged from calan servers.

Friday, April 20, 2012

Optimized vs. My Reports Settings. A New Choice.


Tuesday April 24th, we are releasing a new option for your Users, aimed at improving navigational response times. There will be a follow on change to the Project Summary screen but that is a few months out.

This initial release is a Change to the User Home Page and a Project’s Home Page. This change will NOT change any current settings for your User community. The choice to change any settings will require a conscious decision on their/your part.

They will however see a purple button appear on their User’s Home page for the My Tasks and My Projects dashboards and again on the Project’s Home page for the My Tasks and File Status dashboards. These new buttons will be located among the familiar orange buttons. 

This blog post is to provide you an understanding of what the button offers so you can answer any questions and we hope adopt an active role in a switch to many if not all of your Users to this new setting.

Over time we have added various data sets to the queries for the User’s Home Page and the Project’s Home Page. The result is the dashboards have gone from quick at a glance information tools to become very complex business reports. On the one hand it is wonderful to have all of that information. On the other hand, there is a price tag in response when collecting all of that information, on every click, for every Project on your site, especially, when a majority of the time, you don’t really require all of it. Certainly the majority of your User community is not concerned with business “reporting” tool on their dashboards; they just want to get to their work as quickly as possible. 

The new option being deployed will allow a User to make a decision on enhanced performance if they don’t require all of the “extra” data to do their job. The best part is they can have their cake and eat it too. The code will allow the User to toggle between the current, My Reports setting, to the faster, Optimized setting during a session with just a mouse click. All previous Personalized Reports created in the current My Reports will be retained and can easily be called on demand.

Most importantly, the User can choose to change their default setting on Change My Profile under the Blue Bar, User Information or you can edit for the User on their User Summary page. 

Note: If the User wants to see the improved performance on Login and not have to toggle the switches every time they Login, they or you will need to change their default setting by checking the check-box, < Switch to Optimized viewing as my Default: >. This can be easily changed should they decide to change back.

In addition to their choice of default setting, a User can use the buttons on the screens to toggle back and forth at will. A change in setting, made from a screen’s buttons will hold for their current session (until they Log Out).

We have added convenient visual cues to help the User know which setting they are currently operating within. 
 
 Each of these two settings allow for a Personalized Reports library. The difference is the data called. The configuration options for grouping and sort order remain for each.

An individual User who elects to operate in the Optimized settings should experience a performance improvement. Collectively as more Users elect to utilize the Optimized setting there should be an overall benefit.

NOTE: If you have created default reports that calan has populated for your use, these will need to be rebuilt in the Optimized Reports library and provided to your Users.To discuss this new option or to have your default site level reports transferred to the Optimized setting selected library for your User's use contact us at your convenience.

Tuesday, March 27, 2012

New Log Off code to help with Login frustration


calan made a choice 5 years ago to allow a User to let a 30 minute period of time pass without interacting with the system and on then on their next click be provided a Re-Login screen; so that any data they had entered would be saved and the action they were requesting could be seamlessly continued. This feature requires that the User’s unique browser session be stored and checked by every page on the entire system before executing the request. So we could not allow a single User to have two simultaneous occurrences in the system, say the shipping page for Project A, and the Shipping page for Project B open on two separate tabs of the same browser session (all TABS of one browser session hold the same session ID). If one or both were allowed to sit for 30 minutes when the User selected an action, Re-logged in popped up and the User Re-logged in, the system could inadvertently substitute one session occurrence for the other, resulting in data from Project A being updated in Project B.

So you got this:

 I know not every User uses Tabs. However, the same cross over situation could occur if a user returned to the Login screen in a single browser session after having previously navigated away from the site and having not closed their browser (creating a new session) before a Login a second time. We saw the same session variable, the one already being stored, so for that that User we popped the now “infamous” message above.
While we cannot remove the protective code as described above, it is laced into every page and required to retain the Re-Login feature; we can offer a solution that places the User in control. The system has always had a Log Off button.

Yes the little red button in the upper right corner of every screen, that few Users make use of. We have updated the code of that button to flush the stored browser session when selected. We know by this action that the User has consciously said I am leaving the site, you DO NOT need to hold the session key so that I can easily Re-Login…I’m gone for now. If the User selects this button to leave the site they will be placed on the site’s Login screen. They could immediately Log back in if they choose or go to another URL, return later and even though they never left their original browser session Login because we are no longer storing that original browser session. But ONLY when the User selected the LOG Off button to exit the site after their original use of the site. If they did not they will receive a NEW pop-up on attempting to Login to the site.

You currently have an existing Browser session open in the site. You cannot enter the site with a second Login using the SAME Browser session. Please COMPLETELY close your Browser, reopen it and Login to the site.
TO AVOID RECEIVING THIS MESSAGE IN THE FUTURE ALWAYS EXIT THE SITE USING THE LOG OFF BUTTON LOCATED IN THE UPPER RIGHT CORNER OF EVERY SCREEN.

Please communicate this new update to your community. The pop-up itself is worded to be self educating but Users are notorious for not reading and given the fact that this is a new message it is even more likely they will just assume the status quo and close the browser, missing the new message.

Friday, February 24, 2012

User Home Page Expands the View


On Monday a new functionality will be available for all Users.
In response to numerous requests we have added the ability to expand the view pane of the User’s Tasks and MY Projects on the Home Page.

Located across the top of the My Tasks view is a new orange button:


Selecting this Button will open BOTH the My Task & My Projects views by about 150% in vertical viewing.

You when you open the view a second button will appear:


This button returns to the original default view.

The code behind these buttons is Session Based. If you open it, it will stay open until you Log out of the system. When you return the Expand button will reappear and you can again choose to work in the normal or Expanded views. While in a single session Login you can click it Expand or Contract and it will hold that setting for the course of the Login.

Thursday, August 18, 2011

Blue Bars & More Reporting Power


Those inventive little code guys have figured out how to build customized roll up Reports from the data captured under Blue Bars. In addition the data capture tools of Blue bars have been increased to include both Single select and Multi-select drop downs.

In short, you can now capture data on Blue Bars from many Projects and bring that data back to meaningful business reporting tools. There is a cost for this customized report development but if you have any thoughts on what might make for a good report please feel free to reach out and discuss that with us. 

Note: If you idea has enough merit and we feel it would benefit many sites we will work with you on that pricing.