1. Purpose
  • This Policy sets mandatory security controls for all Followme user accounts and describes how two‑factor authentication (2FA) must be implemented to safeguard access.
2. Password Requirements
  • Length & Complexity: Minimum of 12 characters, including upper- and lower-case letters, numbers, and symbols. Users may not reuse any of their previous five passwords.
  • Storage: Followme applies industry-standard password protection, encryption, and authentication controls to help safeguard user accounts and credentials.
  • Expiry: Strong passwords do not automatically expire; however, compromised credentials must be reset immediately.
3. Two-Factor Authentication (2FA)
  • Followme may require users to enable two-factor authentication for certain high-risk actions, including withdrawals, payout requests, API key creation, security setting updates, or other sensitive account activities.
  • Supported Factors: (a) TOTP authenticator apps (preferred), (b) FIDO2 hardware security keys, and (c) SMS OTP as a fallback option.
  • Recovery Codes: Recovery codes issued during 2FA setup should be stored securely offline by users.
4. Session & Device Controls
  • Device Limit: Max 5 concurrently active devices per account. Followme may limit the number of concurrently active devices per account. If the limit is exceeded, Followme may require the user to remove an existing device, reject the new login, or invalidate the oldest active session.
  • Timeout: Inactive web sessions may automatically expire after 30 minutes, while mobile authentication tokens may refresh every 24 hours.
  • New Device Alerts: Email & in‑app alert sent on first login from a new device or location.
5. Compromise Response
  • Detection: Followme may monitor credential-stuffing attempts, brute-force attacks, darknet breach data, suspicious login activities, and other indicators of potential account compromise.
  • Lockout: 10 failed login attempts may trigger temporary account lockouts 30 minutes, CAPTCHA verification requirements, or progressive security delays.
  • Incident Handling: Users must promptly report suspected account compromise to [email protected]. Followme may enforce password resets or invalidate active tokens where necessary.
6. User Liability
  • Users are responsible for maintaining control of their devices, login credentials, and 2FA recovery codes. Followme shall not be liable for losses resulting from weak passwords, credential sharing, negligence, or failure to secure recovery information.
7. Security Awareness
  • Followme may provide periodic in-app or email security reminders encouraging users to review account protection settings, update recovery information, and enable the most secure 2FA methods available.
8. Policy Enforcement
  • Users who do not comply with mandatory security requirements, including enabling 2FA where required, may be restricted from accessing certain high-risk platform features or account functions.
9. Updates
  • Followme reserves the right to amend, revise, or update this Policy at any time. Material changes may be communicated through email notifications, in-app announcements, or website updates.
10. Contact
  • For questions, concerns, or support regarding account security, please contact [email protected].