Secure Login Flow (step-by-step)
H3 — Start: Visit the official login page
Always start at the official login URL. Bookmark it after you confirm it is correct to reduce phishing risk. Example: itrustcapital.com/login.
H4 — Step 1: Enter username / email
Use the email address associated with your account. If you share devices, enable a browser profile or use private browsing. Avoid saving credentials on public or shared machines.
H4 — Step 2: Two-Factor Authentication (2FA)
A 2FA layer (TOTP via authenticator app or SMS where supported) reduces the risk of unauthorized access. Prefer TOTP apps (Google Authenticator, Authy, or similar) over SMS when possible.
H4 — Step 3: Session protections & device recognition
After successful authentication, use device recognition and the platform's session timeout settings. Log out from devices you no longer use and review active sessions periodically in account settings.
H3 — Advanced protection: Identity verification & account freeze
For certain actions (withdrawals, account changes), additional identity verification may be required. Understand how to initiate an account freeze and whom to contact if suspicious activity is observed.
H3 — Accessibility & Recovery
H5 — Recovery options
Keep recovery methods up to date: recovery email, recovery phone, and documented authentication app backups. Document your recovery steps securely (not in plain text on the device).
Tip: Use a hardware security key (FIDO2) if offered — it provides phishing-resistant authentication and ease of use across devices.
Trust & Compliance
Regulatory posture
IRA custodians and crypto platforms often operate within overlapping regulatory frameworks. Look for custodial agreements, clear fee disclosures, audited processes, and compliance statements that explain how assets are held and insured (if applicable).
Customer responsibilities
Trust is a two-way street: keep your devices patched, use unique passwords, enable multi-factor authentication, and verify official contact methods before sharing personal information.
Managing an IRA with Crypto
Tax-sensitive assets
Crypto in an IRA must be managed with awareness of contribution limits, distribution rules, and prohibited transactions. Keep detailed records for tax reporting and consult a qualified tax advisor for retirement-planning decisions.
Diversification & risk
Crypto is volatile. While a crypto IRA can offer diversification, treat allocations carefully and align them with your retirement horizon and risk tolerance.
Troubleshooting & Support
Common login problems
- Forgot password — initiate the secure reset flow via the official page.
- Lost 2FA device — use the recovery process and contact support immediately.
- Suspicious emails — do not click links; go directly to the official website.
H4 — When to contact support
Contact support if you see unrecognized logins, unexpected transfers, or if you cannot recover access. Use official contact channels only.
H3 — Closing best practices
Regularly review account activity, update your contact information, keep backups of recovery codes, and educate yourself about social engineering tactics that target account access.