Security tips for your portal account

Your portal account holds your invoices, quotations, project files and company details. A few habits keep it safe.

Passwords

  • Use a password of at least twelve characters, unique to this account.
  • Never reuse your email or banking password. One breach elsewhere then exposes everything.
  • Store it in a password manager, not in a browser on a shared machine and not in a spreadsheet the whole office can open.
  • Change it immediately if you suspect anyone else has seen it.

One login per person

Shared logins destroy accountability and survive staff departures. Ask us to create separate contacts instead, and deactivate a contact the day someone leaves.

Watch for fake emails

Invoice fraud is common and it targets exactly this kind of relationship. Treat these as warning signs:

  • An email claiming our bank account details have changed. We do not change banking details by email. Verify by phone on a number you already have before paying anything.
  • A login link pointing to a domain that is not crm.zylax.com.my. Check the address carefully, including small misspellings.
  • Urgency and pressure to pay or log in immediately.
  • An unexpected attachment claiming to be an invoice.

When in doubt, do not click. Open crm.zylax.com.my by typing it yourself and check whether the document exists in your account.

Devices and networks

Sign out when using a shared or public computer. Avoid signing in over open public wifi. Keep your browser and operating system updated.

Sharing credentials with us

When a project needs your hosting or registrar credentials, send them through the portal rather than plain email or chat, and change the password after the project ends.

If something looks wrong

Unexpected activity on your account, an invoice you do not recognise, or a login alert you did not trigger should be reported straight away. Reset your password first, then tell us.

To report a suspicious message or a possible compromise, contact [email protected] or call us rather than replying to the suspect email.

Did you find this article useful?