
Account security
Every purchase moves real money. That’s why we require 2FA, sign your sessions and verify payments: compromising your account or your money becomes far harder.
Mandatory 2FA for everyone
Even if someone gets your password through a leak, phishing or cross-site reuse, they can’t get in without the code from your authenticator app. Activation is mandatory from your first sign-in. Works with Google Authenticator, Authy, 1Password or any standard TOTP app. Step-by-step guide.
10 backup codes
When you enable 2FA you receive 10 single-use backup codes. If you lose your authenticator app, you can get in with one. Each code is stored as a bcrypt hash in our database: not even we can read them.
Country re-verification
If we detect your session is being used from a country different from the original login, we force immediate 2FA verification. Mitigates stolen sessions used from another location.
HMAC-signed cookies
2FA session cookies are signed with HMAC-SHA256 using a secret key that only lives on the server. They can’t be forged or reused between users. Sessions expire after 24h for customers and 4h for admins, who handle more sensitive data.
Codes never by email
Tibia Game Codes are delivered inside your order panel, protected by your session + 2FA. We never send codes by email. Drastically reduces phishing and accidental forwarding risk.
Verifiable payments
Stripe (cards), PayPal, Binance Pay and more. Card and PayPal go through recognized processors with buyer protection. We don’t process cards directly: our database never stores your card number, its CVV or similar data.
Mind your side
We cover our part, you cover yours: do not reuse passwords across sites, do not share backup codes by chat, and do not trust “cheaper” offers in private messages. Any official Tonyzales communication comes from @tonyzales.com or from our authorized WhatsApp.
Audits and reviews
Every change to the payment or authentication flow goes through a dedicated security review before reaching production. Critical findings are resolved before the change ships; minor ones are documented and closed in recurring reviews.
If you find a security issue, write to [email protected] with the detail. We do not publicly expose unpatched vulnerabilities.
Haven’t enabled 2FA yet?
It’s mandatory to buy and takes you under 2 minutes.
Enable 2FA now