Security at Griner
The company invests extensive effort, using the most advanced technological tools, so that you can view information and perform actions in your account easily, conveniently, and securely.
What do we do to protect your information
All information transferred between your computer and the company's systems (and vice versa) is encrypted, in order to prevent interception by any unauthorized party.
Data encryption
All information transferred between your computer and the company's systems (and vice versa) is encrypted, in order to prevent interception by any unauthorized party.
Advanced information security
The company's core databases are not directly connected to the public internet. Access to and from these systems is protected by advanced and intelligent security solutions.
Automatic logout
If you log in to the company's online services and no activity is detected for a certain period of time, the system will automatically log you out. This is designed to prevent unauthorized activity in your account.
Continuous security monitoring
The company's website is monitored on an ongoing basis by professionals specializing in cyber and information security, in order to detect and respond in real time to intrusion attempts and to provide you with a safe browsing experience.
Ongoing updates
The company and its service providers continuously improve and upgrade the information security systems in line with evolving threats on the internet.
Safe Browsing Guidelines
In addition to the security measures taken by the company, we recommend that you follow these best practices when using the website:
- When you enter the site, make sure that a closed padlock icon appears in your browser's address bar. This indicates that the communication between your device and the site is secure.
- Verify that the URL begins with https (indicating encrypted, secure communication).
- You can double-click the padlock icon to view the digital certificate confirming that the site belongs to the company.
- To ensure you are on the official company website and not a phishing site, avoid entering the site via links sent from unknown sources (including email or messages). Instead, type the site address directly into your browser.
- When you finish using the website, always log out by clicking the "Logout" button.
Protecting Your Personal Computer
Place of access
It is not recommended to access your account from public networks. Prefer using a private computer or mobile device only.
Protect your device
We recommend installing and regularly using security tools such as:
- Up-to-date antivirus software
- Firewall software
- Anti-spyware tools
Operating system updates
Use updated versions of your operating system, as they often include important security patches.
Information Security Guidelines for Smartphones
A smartphone is, in many ways, a small computer with extensive functionality. To protect it from security threats, we recommend:
- Protect your device with a personal access code (PIN/password/biometrics) and enable automatic screen lock after inactivity.
- Avoid logging into your account when connected to unknown or unsecured Wi-Fi networks.
- Be cautious when opening SMS messages that contain links; these may lead to phishing sites, or ask you to send login details. If a message looks suspicious, do not click any links and do not reply.
- Turn off the GPS component when it is not needed.
- Approve Bluetooth connections only from known sources, and turn Bluetooth off when not in use.
- Download apps only from official app stores (e.g., Google Play for Android, App Store for iOS). Avoid installing apps from unknown sources.
- Use devices according to the manufacturer's instructions. Do not use "jailbroken" or modified devices.
- Keep your device's operating system up to date, as updates often include security fixes.
- Install a mobile antivirus app that provides continuous protection.
Registration and Login on the Website
- At the end of the registration process, you will be asked to change the initial password to a new password of your choice.
- If 7 days pass from your first login and you do not access the website again, your password will be blocked automatically. To unblock it, you will need to use the "Forgot Password" function on the site or contact Customer Support.
- After completing registration, every time you want to access your personal account, you must log in using your username (email address) and the personal password you chose.
Choosing a Strong Password
- We recommend choosing a unique and complex password that is hard for others to guess.
- Password length: minimum 6 characters, maximum 10 characters, combining letters and digits.
- For stronger security, we recommend including special characters such as: !, @, #, $.
Avoid:
- Passwords that are easy to guess (birthdates, phone numbers, pet names, etc.).
- Storing passwords on your phone or computer in plain text, or writing them on notes in accessible places.
- Relying on the browser's built-in password saving. Instead, you may use a dedicated password manager.
- Using the same password for multiple accounts and devices. Use different passwords so that one compromised password does not expose all of your accounts.
Company representatives will never ask for your password in any situation.
If anyone asks for it, refuse and report it immediately to Customer Support.
- Do not send confidential account information (such as account number, username, passwords, or credit card number) by email.
- You can change your password at any time (we recommend doing so every 90 days).
- Entering the wrong password five times in a row will result in your account being locked. To unlock it, use the password recovery option on the website or contact Customer Support.
- For security reasons, your password is valid for a limited time and will eventually expire. You will receive an email reminder to update your password shortly before expiration.
Phishing Messages
A phishing message is an attempt by malicious actors to obtain personal information such as usernames, passwords, personal details, or credit card numbers by impersonating a trusted entity. Phishing can be delivered through:
- Fake websites
- Emails
- SMS messages
- Messaging apps such as WhatsApp
- Online ads
Examples of Phishing:
- An email that appears to be from technical support, asking you to click a link and enter your username and password.
- An email that appears to be from a legitimate company, asking you to "verify" your details by entering your login credentials and additional information such as credit card details, phone number, address, or security questions.
- An online advertisement with an attractive (often dubious) offer that leads to a malicious or fake website.
- A fake "security alert" message claiming your account was compromised and urging you to change your password via a link.
- An SMS or WhatsApp ("smishing") that includes a link to a fake website or an app download.
How to Recognize a Phishing Attempt
- Check the sender's email address. If you usually receive emails from an official domain and suddenly receive one from a generic address like @gmail.com, it may be suspicious.
- Look for unusual language, spelling mistakes, or awkward phrasing.
- Ask yourself: did you expect this email from this sender? A legitimate, secure organization usually already knows your personal details and does not need to ask you for them in email.
- Be suspicious of messages that create pressure ("urgent action required"), threaten consequences if you don't respond quickly, or offer something "too good to be true".
- If you receive a link asking you to perform an action on a site you know, do not click the link. Instead, visit the official site by typing the address directly into your browser.
- Be cautious with attachments. Open only those you expected from a known and trusted sender. If unsure, contact the sender through another channel (phone, SMS, WhatsApp, etc.) before opening.
How to Protect Yourself from Phishing
- Do not share personal information (ID number, bank account number, credit card number, username, password) via email, SMS, chat, or social media.
- The company may send you emails or SMS messages from time to time, but will never ask you to reply with your username or password.
- When calling Customer Support, the representative will identify you using the phone number you registered with. If the system does not recognize your number, you may be asked for certain personal identification details (such as ID issue date or bank account details), but never for your password.
- Delete any suspicious email or message immediately, without opening links or attachments.
- Avoid entering your email address and password on unfamiliar websites.
If You Responded to a Suspicious Message
- Notify the company's Customer Support immediately.
- If you entered personal information on a fake website, change your password immediately and report it to Customer Support.
Suspected Cyber Incident
If you suspect any unauthorized use of your account or believe your login details have been compromised, you must inform the company immediately via one of the following channels:
- WhatsApp message to: +972-50-5444652
- Phone call to Customer Support (during operating hours): +972-3-8008729
- Email to: Support@griner.io