Your account holds sensitive information
The Cosmos platform holds genuinely sensitive information about you and your company: identity documents, ownership details, financial information, and the documents that make up your formation and ongoing administration. Keeping your account secure is the most important thing you can do to protect it. None of this is complicated, but a few habits, kept consistently, make a real difference.
Use a strong, unique password
Choose a password you do not use anywhere else. A reused password is only as strong as the weakest site that holds it; a single breach elsewhere can let someone into your Cosmos account. A strong password is long, mixes characters, and is not based on guessable personal information such as a date of birth or a pet's name. The simplest way to manage one well is to use a password manager, so you do not have to remember it.
Turn on two-factor authentication
Two-factor authentication, often shortened to 2FA, asks for a second piece of information beyond your password when you sign in, normally a one-time code from an app on your phone. It is the single most effective protection against someone with your password trying to use it. Where Cosmos offers two-factor authentication, turn it on.
Be careful with shared and public devices
Sign in to Cosmos only on devices you trust. Avoid signing in on a public or shared computer, and if you ever do, sign out completely afterwards, and do not save the password to the browser. If you sign in on a device that is later lost or replaced, sign out of all sessions and consider changing your password.
Watch for phishing
Phishing is the most common way accounts are compromised: a message that looks like it is from us, asking you to click a link and re-enter your password, or to confirm a payment. Treat any unexpected request to verify your details or confirm your account with caution. If anything looks off, do not click. Open Cosmos directly in your browser and check from there, or message us in the chat. See Recognising real emails and messages from Cosmos.
Keep your contact details current
Your email is your account's anchor. If it changes and you do not tell us, you cannot receive password resets, security alerts or important notifications. See Keeping your contact details current.
Do a quick check from time to time
Once in a while, look back at your account: does anything look unfamiliar, do the contact details match, are there sessions or devices listed that you do not recognise. If anything is wrong, deal with it now rather than later.
If something feels off, tell us
If you ever suspect your account has been accessed by someone else, or you receive a message you are not sure is genuine, write to the team straight away. We would much rather check a false alarm than handle a real breach later. See If you think your account has been compromised.
