Please ensure that you have taken the following security
measures.
Make sure that it is not possible for emails that are sent
to your users to be tampered with.
Keep SSL certificates up-to-date.
Restrict access to the server machine, and follow other
standard security practices.