Password strength and account verification
We require passwords at least eight characters long, mixing uppercase letters, lowercase letters, numbers, and symbols. Avoid dictionary words, birthdays, or sequential numbers—these are easier for attackers to guess. When you first register on slottoto777, create a password you have not used elsewhere, so if one website is breached, your slottoto777 account remains protected.
Before you can withdraw funds, we verify your identity using Know Your Customer (KYC) rules. You upload a photo of your national ID, passport, or driving licence through your mobile app or browser, along with a selfie. Our automated system checks the document's validity; if it passes, verification completes within hours. If our system flags something—blurry photo, mismatched details, expired ID—we ask you to resubmit. This step happens once; future withdrawals do not require additional ID verification.
Never share your KYC documents or password
We never ask for your ID, selfie, or password via email or chat. If someone claiming to be from slottoto777 requests these, it is a phishing attempt—report it immediately.
Two-factor authentication (2FA) setup
Enabling 2FA on slottoto777 requires an authenticator app on your phone. We support Google Authenticator, Microsoft Authenticator, or Authy. Once you enable 2FA, every login from a new device or location asks for a six-digit code from your authenticator app, in addition to your password. This prevents account takeover even if someone steals your password.
To set up 2FA on your phone, open your slottoto777 account → Settings → Security → Two-Factor Authentication. Tap "Enable 2FA," and we display a QR code. Scan it with your authenticator app, which generates a time-based code. Enter that code to confirm activation. We also give you backup codes—write them down and store them in a safe place, separate from your phone. If you lose your authenticator app, these backup codes let you regain access to your account.
-
1
Download authenticator appOn your phone
Install Google Authenticator, Microsoft Authenticator, or Authy from your phone's app store.
-
2
Go to slottoto777 Security SettingsAccount menu
Open slottoto777, tap Account → Settings → Security, and select "Enable 2FA."
-
3
Scan QR codeWith your app
Use your authenticator app to scan the QR code we display on screen.
-
4
Enter six-digit codeFrom authenticator
Type the code your authenticator app shows, and tap Confirm. Save your backup codes offline.
Session timeouts and device management
When you log into slottoto777 on your phone, we create a session that lasts for your active browsing. If you close the app or browser without explicitly logging out, your session times out after subject to verification of inactivity. This protects you if you leave your phone unattended in a public place like a café in Jakarta, Surabaya, Bandung, or Medan. On a shared desktop, we recommend logging out manually after each session.
You can view all active sessions in your Account → Security → Active Sessions. We list each device (Android phone, iOS Safari, desktop browser) with login time and location. If you see a session you do not recognize, tap "Logout Remotely" to end that session immediately. This is your first line of defense if you suspect unauthorized access.



Password recovery and account lockout
If you forget your password, tap "Forgot Password" on the login screen. We send a password-reset link to your registered email address. Click the link within one hour and create a new password. If you do not receive the email, check your spam folder—some mail filters block automated emails. If the link expires, request a new one; there is no limit on reset requests.
If you enter your password incorrectly five times in a row, slottoto777 locks your account for subject to verification as a fraud-prevention measure. This prevents attackers from repeatedly guessing your password. After subject to verification, you can try logging in again. If your account is locked and you believe it is an error, contact our support team through the Help menu in your account. We are available in English and respond during standard business hours across all regions.
Protecting your payment information
When you deposit on slottoto777, you never enter your DANA, e-wallet, mobile banking, local payment, online payment, or bank account details directly into our platform. Instead, we redirect you to your e-wallet or bank's secure payment gateway. Your bank or wallet provider handles encryption; we see only a confirmation that the transaction succeeded. For direct bank transfers via e-wallet Virtual Account, mobile banking Virtual Account, local payment Virtual Account, or online payment Virtual Account, the Virtual Account number is tied to your slottoto777 user ID, not to you personally—only our system can map it back.
We log every deposit and withdrawal attempt. If you notice a transaction you do not recognize, go to Account → Transaction History and note the timestamp, amount, and payment method. Contact our support team with this information; we can investigate and, if fraudulent, reverse the transaction. During peak times—such as Liga 1 or Piala AFF tournaments—our support team may experience higher volume, but we prioritize security-related inquiries.
What to do if you suspect unauthorized access
If your account shows activity you did not initiate—unusual game bets, withdrawals you did not request, or login notifications from locations you have never visited—take immediate action. Change your password from a secure device (your personal phone or computer, not a shared device). Log out of all active sessions via Account → Security → Active Sessions. Enable or re-verify 2FA. Then contact our support team and provide details: when you first noticed the suspicious activity, what device you normally use, and any sessions or transactions that look wrong.
We take security breaches seriously. If we detect compromise, we may temporarily freeze your account while we investigate, notify you via email and phone, and guide you through recovery steps. This is rare—our encryption and verification systems catch most attacks before they succeed—but we are prepared to handle it. Report suspicious activity immediately; every minute counts.
