Security & FDIC
The SmartyPig application has been successfully ethically hacked and our infrastructure
scanned by Integrity. Integrity is a trusted and experienced IT Risk Management,
Information Security and Compliance consulting firm specializing in IT auditing,
risk analysis, penetration testing, policy development and digital forensics.
SmartyPig.com utilizes the most trusted and secure option for SSL, DigiCert®
True 128-bit Extended Validation SSL. This provides the strongest encryption available.
SmartyPig.com is tested and certified daily to pass the McAfee® SECURE Security
Scan. McAfee® SECURE is the world‘s leading provider of website security
services and probes SmartyPig.com daily for known vulnerabilities. To help address
concerns about possible hacker access to your confidential data, and the safety
of visiting this site, the "live" McAfee® SECURE mark appears only when this
site passes the daily McAfee® SECURE tests.
Trustwave is a leading provider of Secure Sockets Layer (SSL) certificates and Payment
Card Industry (PCI) compliance to organizations worldwide. SmartyPig has been certified
by Trustwave for adherence to PCI security guidelines and has been qualified by
Trustwave for their Trusted Commerce program.
Your SmartyPig account is a separate account held in your name at BBVA Compass, an FDIC insured
bank. FDIC insurance covers an individual account holder for up to the maximum amount
allowed by law in accounts held at BBVA Compass. For more information about BBVA Compass, please visit
Secure Account Set-Up
When you log on to create a SmartyPig account, we ask you to create a username,
password, pass phrase and select a security image. This information is encrypted
during transmission and will remain a secret as long as you do not disclose it.
We strongly recommend that you do not use your Social Security Number as your username
Secure Account Log-In
To securely log on to your SmartyPig account, you are asked to provide your username,
you are shown your security image and pass phrase, and then asked to confirm your
password. For your protection, ALWAYS make sure your security image and pass phrase
are displayed correctly before confirming your password. If you suspect fraud, please
contact us immediately at
SmartyPig’s system will automatically log you off after 15 minutes of inactivity.
This reduces the risk of others accessing your information from your unattended
SmartyPig’s computer systems are protected 24 hours a day by a powerful, state-of-the-art
firewall that blocks unauthorized entry. In order to gain access to authorized information,
the Web browser you are using must know the proper protocol, or language; and even
then only select information is available.
From the moment account information leaves your computer to the time it enters SmartyPig’s
system all online access is encrypted. SmartyPig employs some of the strongest forms
of encryption commercially available for use on the Web today. During any transaction,
our 128-bit encryption turns your information into a coded sequence with billions
of possible variations, making it nearly impossible for unwanted intruders to decipher.
Additionally, private information collected to verify your identity is stored in
an encrypted fashion in our database. SmartyPig’s computers possess the proper formulas
to turn this code back into meaningful information and complete your transaction.
Look for a “closed lock” icon in your browser to confirm if encryption is being
used on any Web page you are viewing. Any Web address beginning with “https://...”
indicates the page you are viewing uses encryption. The “s” stands for “secured.”
DigiCert® Extended Validation SSL
The SmartyPig site is secured with DigiCert® Extended Validation SSL, , the highest standard
for Web site authentication. EV SSL signifies that our organization has passed a
rigorous identity authentication process. In high-security browsers, an EV SSL Certificate
triggers the browser address bar to turn green, display https://, and show the name
of the organization that owns this Web site, as well as DigiCert, the certificate
authority that verified the owner’s identity using a rigorous authentication process.
When your address bar turns green, be sure to make sure that the owner of this Web
site is the organization you intended to visit.
SmartyPig’s security team maintains and monitors all security systems 24/7
to make sure that your accounts are safe and secure.
In order to confront constantly evolving online threats, SmartyPig is committed
to keeping up with and utilizing the latest technology to ensure your account security.
SmartyPig supports the latest versions of Internet Explorer, Firefox, Opera, Safari,
and Chrome. For your protection, SmartyPig does not support beta versions of browsers.
Under normal circumstances, SmartyPig will support the final version of a browser
shortly after the release date. SmartyPig regularly monitors and tests browsers
is a requirement to use the SmartyPig site.