1) Quick Preparation
Before logging in, ensure:
- You use a bookmark or the official mobile app (never click random links).
- Your device OS, browser, and iTrustCapital app are updated.
- Your second factor (authenticator, hardware key) is ready.
2) Password Practices
Use a password manager to generate a long, unique password for iTrustCapital. Aim for 16+ characters or a strong passphrase. Avoid reusing passwords across sites. If your email is exposed in a data breach, change your iTrustCapital password immediately.
Password managers only autofill on the exact saved domain. If autofill fails, check the URL — it may not be the official site.
3) Two-Factor Authentication & Passkeys
Enable 2FA to protect your account:
- Hardware security keys: Best protection against phishing.
- Passkeys: Modern, phishing-resistant login method supported by newer devices.
- Authenticator apps: Use Authy, Google Authenticator, etc., and store backup codes safely.
- SMS codes: Only if stronger options are unavailable.
If you change phones, reconfigure your authenticator promptly using official iTrustCapital instructions.
4) Device & Browser Hygiene
Keep your phone or computer updated, use strong device locks, avoid shady apps/extensions, and use private browsing if login problems arise.
5) Network Safety
Avoid public Wi-Fi for logins. Prefer private networks or a trusted VPN. If forced to use public Wi-Fi, prefer cellular data or ensure VPN encryption is active.
6) Account Recovery Planning
- Secure the email tied to iTrustCapital with its own MFA.
- Store recovery/backup codes offline and safe.
- Bookmark the official password reset & support pages for emergencies.
7) Troubleshooting Login Issues
- Check official domain or app.
- Ensure caps lock/layout isn’t interfering.
- Use the “Forgot password?” reset flow if necessary.
- Sync device time for correct 2FA codes.
- Try incognito/private browsing.
- Use official support if issues persist.
8) If You Suspect Compromise
- Change your password immediately from a secure device.
- Reset 2FA and re-enable stronger options.
- Contact iTrustCapital support via official channels.
- Monitor linked bank/IRA transfers for suspicious activity.
9) Best Practices Checklist
- Unique password in manager ✅
- 2FA enabled (hardware key/passkey) ✅
- Backup codes stored offline ✅
- Device patched & locked ✅
- Secure network ✅
- Official links bookmarked ✅
Applying these steps makes your retirement investments safer from account takeover attempts.