You can consult this hardening guide written by the NSA for Red Hat: http://www.nsa.gov/ia/_files/os/redhat/rhel5-guide-i731.pdf. Even though you're using Ubuntu, the same general principles apply. Follow that guide to the letter and you will be secure enough until you can afford to higher professional pen testers.
Note that the NSA guide doesn't cover web application security, so you'll need to take other steps to ensure that part of your business is secure.
The bad news is that "bank-level" encryption and assertions of good intentions are not sufficient for me to give you my Google password. My Google password is one of two that is not recorded anywhere. The second is for the vault that contains my other 575 passwords. I almost edited my original post to be less melodramatic, but on reflection I think it's right. For a cool grand, I would spend the time to completely separate the associated accounts (analytics, webmaster, docs, calendar, talk, voice) and any password reminders that forward into my gmail now into a separate account. Short of that, I just can't do it. I'm selfishly hopeful that Google gives you a way in without needing to store my password.
indeed I'd say my google account needs more inventive protection than my bank detail. The chance of misuse is a lot higher.
Have you had a vulnerability assessment done? Do you protect against SQL Injection? Do you protect against Cross-Site Scripting? How about Cross-Site Request Forgery? What preventative measures have you taken to lock down your servers?
I know most users don't care about all of those and you're trying to be friendly by saying you use "bank-level" encryption, but some more info would be nice for those of us that care.
We use the latest in bank-level 256-bit SSL encryption to protect your information, and your passwords are securely encrypted.
Right. 256 bits, like everyone else, like it makes some critical difference over 128 unless you're the freaking NSA, and like anyone even bothers trying to break into a TLS session. Not encouraging.
First thing I always check is whether the site's behind a gateway, so let's try and connect on 22:
$ ssh etacts.com
The authenticity of host 'etacts.com (173.203.202.141)' can't be established.
RSA key fingerprint is ec:c2:2f:fe:ef:7e:06:a3:a5:f0:a3:54:04:79:2a:16.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'etacts.com,173.203.202.141' (RSA) to the list of known hosts.
sailormoon@etacts.com's password:
Permission denied, please try again.
Tsk. Early days I know, but .. if you become popular for storing a large database of people's login creds for gmail .. that's a nice juicy target.And I actually found the mention that they're encrypting the passwords, like that means anything (the key is obviously somewhere on the server, and once they're in, they're in) to be more worrisome than not.
The Google Contact API supports OAuth, which is fantastic because so many sites want your email address and password to get contacts (for like invite friend style functionality) but it doesn't appear they store any kind of communication frequency data.
[1] I Am Not a Security Expert
Of course, this would limit the reliability of your service to the reliability of my connection, but that's a trade-off I'd be willing to make.
Just curious, what encryption scheme are you using?
EVERY company in the world promises to not be evil. Not all of them keep their promise.