How to Review Devices and Sessions on GroveX
Learn why device and session reviews matter, what suspicious access can look like and what to do if you do not recognize a login.
Why device reviews matter
Account security is not only about the password.
A session can remain active after a successful login, and an attacker with access to a trusted device or session may not need to enter the password again immediately.
Reviewing devices and sessions helps you identify access you do not recognize.
Where to review security activity
Open GroveX account security settings and review the available device or session information.
Depending on the interface, you may see information such as:
- device or browser type;
- login time;
- approximate IP or location information;
- session status;
- recent account access.
Some information can be approximate. For example, mobile networks, VPNs and internet providers can make location information appear different from your physical location.
What to look for
Investigate activity that you cannot explain, including:
- a device you have never used;
- a browser you do not recognize;
- logins at unexpected times;
- unfamiliar IP information;
- security changes you did not make;
- new API keys you did not create;
- unexpected withdrawal activity.
If you recognize the activity
A new browser profile, operating-system update, mobile carrier change or VPN can sometimes make a familiar device appear different.
Compare the timing and device details with your own activity before deciding whether a session is suspicious.
If you do not recognize a device
Treat unexplained access seriously.
Recommended actions:
- end or revoke unfamiliar sessions where the interface allows it;
- change the GroveX account password;
- make the new password unique;
- secure the email address connected to the account;
- verify that two-factor authentication is still configured correctly;
- review API keys and remove unfamiliar credentials;
- review recent orders, withdrawals and security changes;
- contact GroveX Support if there is any indication of unauthorized activity.
Secure your email account too
Your registered email can be part of password recovery and security verification.
If the email account is compromised, changing only the GroveX password may not be enough.
Use a strong email password and enable multi-factor authentication with your email provider where available.
Review API credentials
API keys can provide programmatic account access according to their permissions.
If you suspect account compromise, inspect API keys even if you do not normally use the API.
Remove any credential you do not recognize.
Read Understanding API Keys and Permissions.
Do not share screenshots containing secrets
When contacting Support, avoid screenshots that expose passwords, private keys, seed phrases, authenticator setup secrets or API secrets.
Submit a support request: https://grovexcom-help.freshdesk.com/support/tickets/new