Account Security Best Practices
Protect Next-Cart account access and remove temporary migration access responsibly.
Account Security Best Practices
Section titled “Account Security Best Practices”Secure account access protects purchases, migration services, connection details, activity, and support records throughout the project.
Maintain a secure account baseline
Section titled “Maintain a secure account baseline”| Area | Recommended practice |
|---|---|
| Passkeys | Add passkeys only on devices, browser profiles, or security keys controlled by authorized users. |
| Password | Use a unique password that is not reused for a source store, target store, or hosting account. |
| 2FA | Enable two-factor authentication for accounts that manage purchases or migration services. |
| Backup Codes | Store current Backup Codes securely and outside the primary authentication device. |
| Account email | Protect access to the email used for verification and recovery. |
| Account Connections | Keep only authorized Google, Apple, and Facebook accounts connected. |
| Login Activity | Review unfamiliar devices, locations, IP addresses, and failed attempts. |
Before migration work
Section titled “Before migration work”Confirm that:
- the correct account owns the order and purchased migration service;
- only authorized users can access the account;
- registered passkeys belong only to authorized users and controlled devices;
- the account email can receive verification and support messages;
- 2FA and recovery methods are available;
- recent Login Activity does not show unexplained successful access.
During migration work
Section titled “During migration work”- Do not share passwords, Backup Codes, API tokens, or private keys through ordinary tickets or chat messages.
- Grant only the access needed to complete connection, migration, validation, or support tasks.
- Review Login Activity after password, 2FA, email, or Account Connection changes.
- Use Delegate Access where available instead of sharing the main account sign-in.
After migration work
Section titled “After migration work”| Cleanup task | Why it matters |
|---|---|
| Revoke temporary API credentials | Prevents unused platform access from remaining active. |
| Remove KitConnect | Removes the temporary source-store connection package when it is no longer needed. |
| Rotate temporary store or server passwords | Invalidates credentials shared for migration work. |
| Review Account Connections | Confirms that only authorized social accounts remain connected. |
| Review Login Activity | Confirms there are no unexpected sign-ins after completion. |
| Close or update support records | Keeps the final issue and access state clear. |
Respond to suspicious activity
Section titled “Respond to suspicious activity”- Change the account password.
- Confirm that other active sessions were signed out.
- Review Account Connections and disconnect anything unauthorized.
- Enable 2FA or regenerate Backup Codes.
- Review Login Activity for unfamiliar devices, locations, IP addresses, or failed attempts.
- Check Orders, Migrations → My Migrations, Checkout, and Support for unexpected activity.
- Contact Support with the affected account email, activity time, device, location, IP address, and relevant migration service.
Next step
Section titled “Next step”- Use Security to change sign-in protection or review Login Activity.
- Use Settings to change the account email or delete the account.
- Use Migrations to review purchased migration-service activity.