Account Security Best Practices
Reduce credential and access risk throughout the migration lifecycle by hardening sign-in, controlling delegated or temporary access, reviewing activity, and cleaning up after completion.
Account Security Best Practices
Section titled “Account Security Best Practices”Secure account access protects purchases, migration services, connection details, activity, and support records throughout the project.
Maintain a secure account baseline
Section titled “Maintain a secure account baseline”| Area | Recommended practice |
|---|---|
| Passkeys | Add passkeys only on devices, browser profiles, or security keys controlled by authorized users. |
| Password | Use a unique password that is not reused for a source store, target store, or hosting account. |
| 2FA | Enable two-factor authentication for accounts that manage purchases or migration services. |
| Backup Codes | Store valid, unused Backup Codes securely and outside the primary authentication device. |
| Account email | Protect access to the email used for verification and recovery. |
| Account Connections | Keep only authorized Google, Apple, and Facebook accounts connected. |
| Login Activity | Review unfamiliar devices, locations, IP addresses, and failed attempts. |
Before migration work
Section titled “Before migration work”Confirm that:
- the migration owner and any delegated collaborators who still require access are identified;
- only authorized users can access the account;
- registered passkeys belong only to authorized users and controlled devices;
- the account email can receive verification and support messages;
- 2FA and recovery methods are available;
- recent Login Activity does not show unexplained successful access.
During migration work
Section titled “During migration work”- Do not share passwords, Backup Codes, API tokens, or private keys through ordinary tickets or chat messages.
- Grant only the access needed to complete connection, migration, validation, or support tasks.
- Review Login Activity after password, 2FA, email, or Account Connection changes.
- When another person needs to operate a purchased migration, use Delegate Access instead of sharing the main account sign-in.
After migration work
Section titled “After migration work”| Cleanup task | Why it matters |
|---|---|
| Revoke temporary API credentials | Prevents unused platform access from remaining active. |
| Revoke delegated migration access | Removes collaborator or support access that is no longer needed. Use Delegate Access. |
| Remove KitConnect | Removes temporary connection files from each store where KitConnect was installed, after migration and required follow-up work are complete and accepted. |
| Rotate temporary store or server passwords | Invalidates credentials shared for migration work. |
| Review Account Connections | Confirms that only authorized social accounts remain connected. |
| Review Login Activity | Confirms there are no unexpected sign-ins after completion. |
| Close or update support records | Keeps the final issue and access state clear. |
Respond to suspicious activity
Section titled “Respond to suspicious activity”- Change the account password.
- Confirm that other active sessions were signed out.
- Review Account Connections and disconnect anything unauthorized.
- Enable 2FA or regenerate Backup Codes.
- Review Login Activity for unfamiliar devices, locations, IP addresses, or failed attempts.
- Check Orders, Checkout, and Support for unexpected activity. For purchased migration activity, expand Migrations and select My Migrations.
- Contact Support with the affected account email, activity time, device, location, IP address, and relevant migration service.
Privacy and regulatory questions
Section titled “Privacy and regulatory questions”Security practices in this guide help reduce operational risk, but they are not a legal or regulatory compliance attestation. Requirements such as GDPR depend on the applicable processing relationship, data, jurisdictions, contractual terms, and the policies in force for the service.
For a compliance review, use the applicable Next-Cart privacy, data-processing, contractual, and service-policy materials as the governing sources. Keep customer data minimized in support evidence, avoid exposing secrets or plaintext passwords, and escalate organization-specific legal requirements through the appropriate commercial or compliance channel before migration work begins.
Next Steps
Section titled “Next Steps”- Use Security to change sign-in protection or review Login Activity.
- Use Settings to change the account email or delete the account.
- Use Migrations to review purchased migration-service activity.
- Use Delegate Access to review or revoke migration-level access.