SureLC - Security Info - Attention Needed

Published: Sat, 09/05/15




Hi ,

As you're probably aware by now, SuranceBay has worked to implement enhanced security functionality within SureLC. As part of our enhanced security protocols, it is imperative to review the following information as it may (or may not), pertain to your agency:

1. Single-Sign-On: If your agency utilizes Single-Sign-On (SSO), it is imperative someone from your agency completes the SSO Password Assessment. Pass this email along to the most appropriate person from your agency who is capable of responding to this assessment.

  • The assessment only needs to be completed if your agency has enabled producers to login to your agency's website, AND subsequently click a link/button to access SureLC.
  • The most important aspect is completing this assessment. Follow-up messages related to requirements (if any) will be communicated to your dedicated personnel completing the assessment.
  • Failure to complete this assessment by Sept. 21st, 2015 will result in disablement of SSO to SureLC until the assessment has been completed. 
  • Questions - Please email support@surancebay.com.

2. iFrame - Many agency clients have embedded the SureLC-Web application within an iFrame on their website. This too can be cause for a security concern, so SuranceBay is restricting access to embedding SureLC-Web in an iFrame to ONLY those authorized agencies.

  • CLICK HERE for an example of enabling iFrame. Notice that our YouTube videos are "embedded within an iFrame".
  • If your agency has SureLC embedded within an iFrame on your website - you should be good to go without any problems. We already know all of our agency's domain addresses, and have allocated acceptance to these website domains for iFraming purposes. It is those websites embedding SureLC-Web that we don't know about that could be cause for concern - so let us know them. 
  • If your agency uses the Add-Config Tab to create special URL's for your sub-agencies, AND they have posted SureLC-Web to their website embedding it within an iFrame, they likely will encounter problems UNTIL you've communicated to us (support@surancebay.com) their website domain so we can authorize such usage.
  • All website domains outside of yours that have not been communicated to SuranceBay by Sept. 21st, 2015 using iFrame embedding will cease to be available until we've received authorization from your agency for such usage.

Should you have any follow-up questions, please let us know by emailing us at support@surancebay.com




Thank you,

Brian Morton

SuranceBay
877-264-6888