Skip to main content

Keeping your account secure

A few habits that protect your Cosmos account.

Written by Rupert Searle

Your account holds sensitive information

The Cosmos platform holds genuinely sensitive information about you and your company: identity documents, ownership details, financial information, and the documents that make up your formation and ongoing administration. Keeping your account secure is the most important thing you can do to protect it. None of this is complicated, but a few habits, kept consistently, make a real difference.

Use a strong, unique password

Choose a password you do not use anywhere else. A reused password is only as strong as the weakest site that holds it; a single breach elsewhere can let someone into your Cosmos account. A strong password is long, mixes characters, and is not based on guessable personal information such as a date of birth or a pet's name. The simplest way to manage one well is to use a password manager, so you do not have to remember it.

Turn on two-factor authentication

Two-factor authentication, often shortened to 2FA, asks for a second piece of information beyond your password when you sign in, normally a one-time code from an app on your phone. It is the single most effective protection against someone with your password trying to use it. Where Cosmos offers two-factor authentication, turn it on.

Be careful with shared and public devices

Sign in to Cosmos only on devices you trust. Avoid signing in on a public or shared computer, and if you ever do, sign out completely afterwards, and do not save the password to the browser. If you sign in on a device that is later lost or replaced, sign out of all sessions and consider changing your password.

Watch for phishing

Phishing is the most common way accounts are compromised: a message that looks like it is from us, asking you to click a link and re-enter your password, or to confirm a payment. Treat any unexpected request to verify your details or confirm your account with caution. If anything looks off, do not click. Open Cosmos directly in your browser and check from there, or message us in the chat. See Recognising real emails and messages from Cosmos.

Keep your contact details current

Your email is your account's anchor. If it changes and you do not tell us, you cannot receive password resets, security alerts or important notifications. See Keeping your contact details current.

Do a quick check from time to time

Once in a while, look back at your account: does anything look unfamiliar, do the contact details match, are there sessions or devices listed that you do not recognise. If anything is wrong, deal with it now rather than later.

If something feels off, tell us

If you ever suspect your account has been accessed by someone else, or you receive a message you are not sure is genuine, write to the team straight away. We would much rather check a false alarm than handle a real breach later. See If you think your account has been compromised.

Did this answer your question?