If I were ever writing a recommendation I would go with "industry standard" or "industry best practise" both almost equally meaningless. But still more valid, specially in financial system. As with standards you can't be blamed for doing it wrong.
I don't think most people think that, but I would say that the target market for this service would tend to suspect such an ambiguous term. I'd just specify the actual encryption algorithm (AES-256 I assume, which is frequently what is meant by "military grade")
If I were ever writing a recommendation I would go with "industry standard" or "industry best practise" both almost equally meaningless. But still more valid, specially in financial system. As with standards you can't be blamed for doing it wrong.