Protect your account
The habits and settings that actually reduce your risk, and the emergency lock.
Version 1.0 · Last updated
When you would read this
When you set up, and periodically as a check. Most losses in this kind of product come from ordinary process failures rather than anything exotic.
Protect your own access
- Register a passkey on each device you use regularly, so you are not relying on the fallback method every time.
- Store your recovery key offline, and not in the same password manager you sign in from.
- Never share a sign-in code with anyone, including anyone claiming to be from Stablerail. We will never ask for one.
- Sign out on shared machines rather than relying on the idle timeout.
Protect the organisation
Keep your quorum above one for meaningful amounts. A second reader is the control that catches what the first one misses. A quorum of one means one compromised account is enough.
Set your new-recipient threshold low. First payments to new addresses are where fraud lands.
Pay from saved counterparties, never from a pasted address. And never copy an address out of your transaction history.
Verify payment detail changes by phone, on a number you already hold, before adding a new address. See "Manage counterparty addresses safely".
Review the audit log periodically. Look for fallback sign-ins, policy changes you do not recognise, and members you did not expect.
Remove people promptly when they leave, and check your quorum still works afterwards.
Use quarantine addresses for unknown senders so your operating vaults stay clean.
The emergency lock
An Admin can engage an emergency lock from Settings › Security. It halts payments immediately across the organisation.
To engage it you type LOCK to confirm. To release it you type UNLOCK.
Use it the moment you suspect something is wrong. It is reversible, it costs you an hour of inconvenience, and it is far cheaper than the alternative. Do not wait until you have established what happened.
What to expect
None of these controls prevent a determined insider with legitimate access from making a legitimate-looking payment. What they do is ensure it takes more than one person, and that everything is recorded.
Engaging and releasing the lock are both recorded in the audit log.
Common problems and what they mean
Your team finds the controls slow. That is the trade-off you configured. Review the thresholds rather than switching controls off.
You cannot engage the lock. You are not an Admin.
Payments are all failing and nobody knows why. Check whether the lock is engaged.
