How We Secure Your Account
When you create an ekatoto account, verification begins before you can deposit funds or place any bet. Email confirmation, then KYC (Know Your Customer) document upload—national ID, proof of address—establish your identity. This two-stage process complies with financial regulations and prevents duplicate accounts.
Initial Setup and Identity Verification
Account creation requires four steps: email address, password creation, identity verification, and payment method registration. Your password is your first line of defence. We recommend 12 or more characters mixing uppercase, lowercase, numbers, and symbols. Avoid birthdates, common words, or sequential numbers. After creation, change your password every 90 days and never share it with anyone—including ekatoto support staff.
After password setup, you upload a government-issued ID (national card or passport) and proof of address (utility bill, lease agreement, or bank statement not older than three months). This KYC data is encrypted and stored separately from your account balance, betting history, and transaction log. We do not sell or share this data with third parties outside regulatory requirements.
Verification bridges account creation and fund deposits. We process most verifications within one working day, though high-volume periods—before Liga 1 finals or Champions League fixtures—may add 24 hours.
Payment Method Registration and Security
Once verified, you register a payment method: e-wallet, mobile banking, local payment, online payment, e-wallet, mobile banking, or a bank account (local payment, Mandini, online payment, e-wallet). Each is registered and verified separately. When you deposit, we confirm your identity a second time through a code sent to your registered email or SMS. We do not store your full payment credentials. mobile banking, local payment, and online payment transactions are tokenised—we hold a reference code, not your login details. Bank transfers use your account number, which we encrypt and log separately from your betting activity.
Withdrawals follow the same verification gate: you request a withdrawal, confirm your identity via email code, and funds return to the exact payment method you deposited from. Cross-payment withdrawals—depositing with e-wallet but requesting withdrawal to mobile banking—are not permitted. This rule prevents account takeover and money-laundering routing.
Session Management and Login Verification
Each login is recorded: device type, browser, location, and timestamp. Unusual patterns—your account accessed from Jakarta at 9 AM and Bandung at 9:30 AM, or a new device logging in outside your normal hours—trigger additional email verification. Sessions expire after subject to verification of inactivity. If you step away, your betting slip clears and you are logged out. This prevents shoulder-surfing in shared spaces.
We support optional two-factor authentication (2FA) via authenticator app. Enabling 2FA adds a verification step at login: you enter your password, then a time-based code from your authenticator. This is especially useful during live-betting windows for Liga 1 matches, Piala AFF games, and Champions League nights, when account activity peaks.
Real-Time Fraud Monitoring
Our systems monitor transactions in real-time. Large deposits followed by immediate withdrawals, rapid betting across multiple accounts, or unusual IP addresses accessing your account trigger automatic alerts. Our support team reviews flagged accounts within four hours. If you suspect unauthorised access—bets you did not place, withdrawals to unknown accounts, or balance changes—contact our support team immediately via email or live chat. Provide your account email, dates and times of suspicious activity, and any screenshots. We freeze your account during investigation and restore funds if fraud is confirmed.

Password Recovery and Account Access
If you forget your password, we send a reset link to your registered email. The link expires after two hours. You then create a new password and confirm your identity with an email code. This intentional multi-step process prevents automated password-reset attacks. Never share password-reset links, and verify that reset requests come from an ekatoto email domain.
Data Encryption and Protection
Your account data—betting history, payment methods, personal details—is encrypted in transit (HTTPS) and at rest (AES-256). We do not log your password in plaintext; we store a cryptographic hash. We do not retain full payment credentials, even for local payment, online payment, or e-wallet—only tokenised references. During holiday periods (Idul Fitri, Idul Adha, Imlek), backup systems continue protecting your data. Our data centres maintain redundancy so service disruptions do not expose your information.
We collect only data necessary for account verification, payment processing, and regulatory compliance. We do not share your data with advertising platforms, data brokers, or third-party analytics. Our privacy policy details what data we collect, how we use it, and how long we retain it.

