Behind the Scenes posts

Trust Guard, Apache & Rails

We recently added the Trust Guard service to VendorRisk.com.  As part of the package we purchased, Trust Guard scans our server each day looking for vulnerabilities.  On the first scan, it found 4 “medium risk” issues that had to be resolved in order to pass PCI compliance.  Here are the issues and what we did …

Comments: 0

Rails, authlogic and password history

vendorrisk.com client sites use the excellent Authlogic gem to handle user sessions. As we mentioned in the previous blog article, we recently added the ability for site admins to declare that users cannot use a password they’ve used in the past.

After a bit of Googling, I didn’t see any solutions out there for dealing with this issue, so we rolled our own. Here’s how we went about it…

Comments: 1

Fun with Rails A/B testing

When we launched VendorRisk.com a few weeks back, we added a very simple A/B experiment to test which sign up call to action worked better.  The first two options we chose were “View plans and pricing” and “Try free for 30 days!”.  We assumed that the latter would perform better because it sounded more enticing …

Comments: 0