Ex: Your routers, switches, RAID storage etc. are not immune to rootkits. However, if your message from A to B is encrypted and only decrypted locally by B, you've limited the exposure of this information.
There are no passwords - we use our own CA system, PKI, carefully selected cipher suites, physical security, mutiple vendors' products, logical isolation, tiered architecture, an IDS system, mirrored environments, tamper detection and automatic key disposal.
And I still don't sleep because there are a thousand ways around it all.
Still, we have insurance.
Integration between various companies, nothing more. We're a hub.
1. Get an email at your normal email that you have a message at secure email provider
2. Click link, get taken to a web page where you need to make an account to read the mail
3. Read mail at the link, you can reply and attach stuff to it, and that's it. No create mail functionality.
So you end with up with "email conversation as a link" sort of feeling. Very odd when you're used to dealing with any other "normal" webmail site.
I don't think trusting a third-party with highly confidential financial data is very good practice.