Since the newsletter is discussed I will post it here so people can understand from their own minds and read with us. But in my opinion we did make a mistake by stating
" ... and your email was flagged as ... " since this newsletter likely went out to everyone on our list (I will ask if this is so).
It's also possible that someone started the process but started over again for example when the page got expired.
"It's been a busy week among the AML BitCoin team, and we felt it important to share some important news to everyone on our newsletter.
We started an audit and your email was flagged as starting the contribution process but was never completed on TokenLot.com’s Payment Platform. If you were unable to complete your purchase feel free to contact us for assistance at
[email protected].
If you did a purchase and did not receive an Order Confirmation Email from TokenLot, please email our audit department at
[email protected]. Make sure to provide them with the email address you registered with along with the wallet address that you sent the funds to.
If you did a purchase and have received your Order Confirmation Email, please email
[email protected] your Aml Token Wallet address so that they can confirm the Token Address is the same one you registered with.
Once the audit is completed, we plan on distributing tokens shortly thereafter."
The original is here:
http://mailchi.mp/062f9adb18c8/important-aml-token-distribution-update-please-read?e=Stealth8368: I believe you are in the last category since you did receive the confirmation emails already and you should not be worried. We simply do a re-audit for maximum security. Please use the email address that best describes the status of your order(s). Like DroidR17A you can use
[email protected].
Thanks for responding to questions regarding the recent email. I have received a confirmation of sorts since then, but I do not see any response to my other questions here.
Namely that...given TokenLot's security failure, what steps are being taken to test the new service provider - e.g. manual/automated pen tests, load tests, etc.? Have any been done?
...and what about the data verification companies, for once the real coin actually launches? Will you be posting extracts from the SLA and pursuing independent data auditing and pen testing?
These are important questions given that people are currently risking money and will eventually be sharing PII in order to use the platform. I'm now more than a little concerned about the level of security audits being carried out with your 3rd party providers. What steps are you taking to secure our data and tokens moving forward?