Chris, the problem isn't just with Thunderbird. I verified that the same issue comes up with several other email clients as well. One of them was the standard Macintosh email client; my husband has a Mac Pro and I tested with it. Only certain webmail clients display your emails as rendered HTML.
Outside auditing of your site is a good thing. Frankly, from my experience, it has probably saved your bacon more than once because the people who are designing, coding, and managing the web site show every sign of not knowing how to do this kind of work.

You *really* need to get some more experienced developers ASAP.
I'm a technical writer by profession, but also do a lot of QA as part of my job. I work for a Fortune 500 company, in the division that provides security "solutions" (I HATE that term) for protecting customer-facing web portals for companies and organizations that have high security needs, such as banks and financial institutions. The technical side of your business is exactly the sort of thing that I spend most of my working day understanding, documenting, and figuring out how to protect. (As in -- write use cases for.)
I'm not hostile to Paxum. Nor do I think Paxum is trying to defraud anybody; I see no sign of that at all. What I do see is a sign of lack of sufficient experience in designing and managing secure web sites. You *MUST* get people in there who know how to handle the types of security required for a financial institution.