Skip to content
Back to Site

Account Security Best Practices

Reduce credential and access risk throughout the migration lifecycle by hardening sign-in, controlling delegated or temporary access, reviewing activity, and cleaning up after completion.

Secure account access protects purchases, migration services, connection details, activity, and support records throughout the project.

AreaRecommended practice
PasskeysAdd passkeys only on devices, browser profiles, or security keys controlled by authorized users.
PasswordUse a unique password that is not reused for a source store, target store, or hosting account.
2FAEnable two-factor authentication for accounts that manage purchases or migration services.
Backup CodesStore valid, unused Backup Codes securely and outside the primary authentication device.
Account emailProtect access to the email used for verification and recovery.
Account ConnectionsKeep only authorized Google, Apple, and Facebook accounts connected.
Login ActivityReview unfamiliar devices, locations, IP addresses, and failed attempts.

Confirm that:

  • the migration owner and any delegated collaborators who still require access are identified;
  • only authorized users can access the account;
  • registered passkeys belong only to authorized users and controlled devices;
  • the account email can receive verification and support messages;
  • 2FA and recovery methods are available;
  • recent Login Activity does not show unexplained successful access.
  • Do not share passwords, Backup Codes, API tokens, or private keys through ordinary tickets or chat messages.
  • Grant only the access needed to complete connection, migration, validation, or support tasks.
  • Review Login Activity after password, 2FA, email, or Account Connection changes.
  • When another person needs to operate a purchased migration, use Delegate Access instead of sharing the main account sign-in.
Cleanup taskWhy it matters
Revoke temporary API credentialsPrevents unused platform access from remaining active.
Revoke delegated migration accessRemoves collaborator or support access that is no longer needed. Use Delegate Access.
Remove KitConnectRemoves temporary connection files from each store where KitConnect was installed, after migration and required follow-up work are complete and accepted.
Rotate temporary store or server passwordsInvalidates credentials shared for migration work.
Review Account ConnectionsConfirms that only authorized social accounts remain connected.
Review Login ActivityConfirms there are no unexpected sign-ins after completion.
Close or update support recordsKeeps the final issue and access state clear.
  1. Change the account password.
  2. Confirm that other active sessions were signed out.
  3. Review Account Connections and disconnect anything unauthorized.
  4. Enable 2FA or regenerate Backup Codes.
  5. Review Login Activity for unfamiliar devices, locations, IP addresses, or failed attempts.
  6. Check Orders, Checkout, and Support for unexpected activity. For purchased migration activity, expand Migrations and select My Migrations.
  7. Contact Support with the affected account email, activity time, device, location, IP address, and relevant migration service.

Security practices in this guide help reduce operational risk, but they are not a legal or regulatory compliance attestation. Requirements such as GDPR depend on the applicable processing relationship, data, jurisdictions, contractual terms, and the policies in force for the service.

For a compliance review, use the applicable Next-Cart privacy, data-processing, contractual, and service-policy materials as the governing sources. Keep customer data minimized in support evidence, avoid exposing secrets or plaintext passwords, and escalate organization-specific legal requirements through the appropriate commercial or compliance channel before migration work begins.

  • Use Security to change sign-in protection or review Login Activity.
  • Use Settings to change the account email or delete the account.
  • Use Migrations to review purchased migration-service activity.
  • Use Delegate Access to review or revoke migration-level access.