Account & security
Keeping your account and payments safe
Practical checks for passwords, payment instructions and suspicious messages.
THE SHORT ANSWER
Use a unique password, enable an authenticator where available and verify links before signing in. Never share passwords, codes, wallet secrets or remote access.
- Applies to
- People accessing or protecting their Ostro account.
Updated
In this guide
Use a unique password and protect both your Ostro account and the email address connected to it. Keep your authenticator and recovery access under your control.
Check the destination before acting
Use the official Ostro website and application links. If an email or message asks you to change payment instructions, verify the request through a trusted channel before sending money.
Do not assume a familiar display name, logo or screenshot proves that a message is genuine.
Information you should never share
- Your account password or one-time login codes.
- Your authenticator QR code or setup secret.
- Password-reset links.
- Wallet private keys or seed phrases.
Support can investigate using account and transaction references. It does not need those secrets.
If something looks wrong
Stop interacting with the message or unfamiliar website. Open Ostro directly using the known address. Secure your email and account where you can safely do so, and contact support promptly.
Report unfamiliar payments with their date and reference. If you received a suspicious message, describe it without opening attachments or forwarding active links unnecessarily.
Ostro cannot guarantee recovery of funds sent to a fraudulent or unsupported destination. Acting quickly helps establish what options remain available.
Something unclear? Suggest a correction or ask a question.
Tell us what’s happening. We’ll help you find the next step.
Contact Ostro support