Account & security

Keeping your account and payments safe

Practical checks for passwords, payment instructions and suspicious messages.

THE SHORT ANSWER

Use a unique password, enable an authenticator where available and verify links before signing in. Never share passwords, codes, wallet secrets or remote access.

Applies to
People accessing or protecting their Ostro account.

Updated

In this guide

Use a unique password and protect both your Ostro account and the email address connected to it. Keep your authenticator and recovery access under your control.

Check the destination before acting

Use the official Ostro website and application links. If an email or message asks you to change payment instructions, verify the request through a trusted channel before sending money.

Do not assume a familiar display name, logo or screenshot proves that a message is genuine.

Information you should never share

  • Your account password or one-time login codes.
  • Your authenticator QR code or setup secret.
  • Password-reset links.
  • Wallet private keys or seed phrases.

Support can investigate using account and transaction references. It does not need those secrets.

If something looks wrong

Stop interacting with the message or unfamiliar website. Open Ostro directly using the known address. Secure your email and account where you can safely do so, and contact support promptly.

Report unfamiliar payments with their date and reference. If you received a suspicious message, describe it without opening attachments or forwarding active links unnecessarily.

Ostro cannot guarantee recovery of funds sent to a fraudulent or unsupported destination. Acting quickly helps establish what options remain available.

Something unclear? Suggest a correction or ask a question.

Need a little more help?

Tell us what’s happening. We’ll help you find the next step.

Contact Ostro support