Your TrustRating account carries your public reviewing identity — and if you manage a company, access to its reputation as well. That makes it worth protecting properly. The good news is that account security is mostly a handful of habits, and the platform is built to make the safe path the easy one. This guide covers the habits, the built-in protections, and the recovery steps for when something goes wrong.
If you only take one thing away, make it the first section: the strength of your password decides how hard everything else has to work.
Start with a passphrase, not a password
Most stolen accounts fall to one of two causes: a password that was easy to guess, or a password reused from another site that later leaked. Both have the same fix.
Length beats cleverness. A passphrase of three or four unrelated words is both easier to remember and dramatically harder to crack than a short string of substitutions like P@ssw0rd1. When you set or change your password, the live strength meter scores what you type, and a checklist shows what you are missing: length, upper and lowercase letters, a number, a symbol. Treat length as your main lever — every extra character multiplies the work an attacker faces.
Never reuse it. Your TrustRating password should exist nowhere else — reuse is how a breach at some unrelated forum becomes a takeover of your accounts everywhere. A password manager solves this completely: let it generate a unique random password and forget about memorability.
Tip: Changing your password on TrustRating automatically signs out every other device and sends you a confirmation email. It is the single fastest way to slam the door on anyone who should not be there.
Password or sign-in link?
TrustRating gives you two ways in from the login page: your password, or a one-time sign-in link emailed to you. Each has a place.
- Sign-in links shine on devices you do not fully trust. Nothing is typed that a shoulder-surfer or keylogger could capture, the link works exactly once, and it expires quickly. The trade-off: your account becomes exactly as secure as your email inbox, so protect that inbox well.
- Passwords are faster on your own devices and do not depend on email delivery being instant.
A sensible split: password on your own machine, sign-in link everywhere else. Both roads lead to the same account, so you can mix freely.
Add two-factor authentication
Two-factor authentication (2FA) means a password alone is not enough to sign in — a rotating six-digit code from an authenticator app on your phone is also required. Even someone who steals your password outright is stopped at the gate.
Enabling it takes a couple of minutes from the security page in your settings: scan the QR code with any standard authenticator app, confirm with a code, and you are protected. During setup you also receive a set of one-time recovery codes — store them somewhere safe that is not your phone, because they are how you get back in if the phone is lost. You can regenerate a fresh set whenever you want, and disabling 2FA later requires your current password, so a walked-away-from laptop is not enough for someone to strip your protections.
Recognizing phishing
Phishing — fake emails or pages built to trick you into handing over credentials — is the most common attack we see. The defense is knowing what we will never do:
- TrustRating will never ask for your password by email, in a support ticket, or anywhere except the sign-in and password forms on the site itself.
- We will never send you an attachment to open, ask you to "verify your account" by replying with personal details, or pressure you with a countdown.
When an email claims to be from us and something feels off, do not click its buttons. Open the site directly from a bookmark, sign in, and check your notifications — a real issue will be visible there. Unsure? Forward the message to support — we would much rather confirm a false alarm than clean up a takeover.
Tip: The password-change confirmation email doubles as a tripwire. If one arrives and you did not change anything, someone else did — go straight to the recovery steps below.
If you think your account is compromised
Move quickly and in this order:
- Reset your password immediately. If you can still sign in, change it from the security settings; if you cannot, use Forgot password on the login page to email yourself a reset link. Either way, the change signs out every session on every device — the intruder is out the moment the new password saves.
- Check your recent sign-in activity. The security page lists your latest sign-ins with time, device, and network details. Unfamiliar entries confirm the problem and tell you when it started.
- Review your account for changes — display name, profile, notification settings, and any reviews or replies you did not write. Undo what you can.
- Contact support. Tell our team what you found. We can investigate the account history server-side, undo damage you cannot, and flag anything posted while the account was not yours.
- Fix the source. If the same password was used anywhere else, change it there too, and consider whether your email account itself — the master key to all resets — needs a stronger password and 2FA.
Shared and public computers
Borrowed laptops, library machines, and hotel business centers deserve extra caution:
- Prefer a sign-in link over typing your password. Nothing reusable touches the keyboard.
- Decline the browser's offer to save your password, and use a private or incognito window so nothing persists after you close it.
- Sign out when you finish — closing the tab is not the same thing.
- Forgot to sign out? Change your password from any device you trust — that shared machine's session dies with everyone else's.
Why email verification matters
When you create an account, we email you a verification link, and the account stays limited until you click it. This is not busywork: verification proves the address is really yours, so nobody can register in your name, and every recovery path — reset links, sign-in links, security alerts — reaches the actual owner. It also feeds our review-integrity systems, since verified accounts are treated as more trustworthy — part of how we fight fake reviews. If the email never arrived, check spam, then request a fresh one from the sign-in page.
Account labels: suspended, review ban, unverified
TrustRating marks account standing with small labels, so status is never a mystery:
- Unverified means your email address has not been confirmed yet. Fix it by clicking the verification link — or requesting a new one.
- Review ban means the account is blocked from posting new reviews, usually after guideline violations. Existing reviews and the rest of the account continue to work.
- Suspended is the most serious: sign-in is blocked entirely, and you will see a notice explaining that when you try. Suspensions follow serious or repeated violations of the guidelines.
If you believe a suspension or review ban was applied in error, appeal by contacting support — include the account's email address and any context. A human reviews every appeal against our published guidelines.
Security FAQ
"Is the sign-in link less secure than a password?" No — it shifts the trust to your email inbox. If your inbox is well protected, sign-in links are excellent; if it is not, fixing the inbox is your real priority.
"I lost my phone and my recovery codes." Contact support from the email address on the account. Identity checks apply, deliberately — the same door cannot be easy for you and hard for an attacker.
"How often should I change my password?" Only when there is a reason: a suspected compromise, a breach at a service where you reused it, or a shared-computer session you did not close. Routine forced rotation mostly produces weaker passwords on sticky notes. One strong, unique passphrase — ideally with 2FA on top — beats a parade of mediocre ones.