What it's for
When you set up your account, you choose a security question and give an answer, your mother's maiden name, the make of your first car, your father's middle name, the name of your first pet, and so on. It is used for exactly one thing: resetting your client portal password. Nothing else asks for it, and nobody at Linuxweb needs it for anything else.
Your email address has to be verified first
Before any of this works, your registered email address must be confirmed as genuinely yours. We require verification when you first register an account, and again whenever your password is changed. The same applies if your email address changes at any point, whether you update it yourself or ask us to do it for you, the new address starts unverified and must be confirmed.
This matters more than it sounds: an unverified email address cannot be used to reset a password. If you change your address and leave the verification email sitting unread, you will discover the problem at the worst possible moment, when you are locked out and trying to get back in. Verify it the day it arrives.
Why the security question exists on top of that
A password reset works by emailing a reset link to your verified address. That is secure right up until someone else has access to your email, at which point your email becomes the master key to everything, as our article on compromised email accounts explains at length. The security question is the second lock: reaching your inbox is not enough, an attacker also has to know something about you personally. Two independent things, both needed, which is meaningfully harder than one.
Your answer doesn't have to be true
These questions have one weakness, and it is not the questions themselves, it is how much of your life is public. Maiden names appear in public records. The name of your first pet may be sitting in a birthday post from years ago. Anyone determined enough can often find the honest answer.
So do not give the honest answer. Nothing checks it against reality, the system only cares that what you type at reset time matches what you typed at signup. Treat it as a second password: something unrelated to the question, and stored in your password manager alongside your other credentials.
One condition comes with that, and it is not negotiable: whatever you choose must be entered exactly, character for character, every time you reset a password, and it is case sensitive. A capital letter in the wrong place will fail just as surely as the wrong answer entirely. So whether you pick a random string or a real word, save it somewhere you will still have it in two years, a password manager entry alongside the account is the right home. An answer you cannot reproduce exactly is the same as no answer at all, and recovering from that means contacting us and verifying your identity the long way.
If you have forgotten your answer
Contact us through a support ticket or our Business WhatsApp on +27 72 270 9321, and we will verify your identity against our records before making any change. If the details you give do not match what we hold, we will not proceed, and we will require an email from the registered account holder before going further. That is not us doubting you, it is the same protection working in the other direction, and it is exactly what stops someone else doing this on your behalf.
Good to know
Our staff never ask for your security question answer, and never ask for any of your passwords, in a ticket, on WhatsApp, or anywhere else. If anything claiming to be us asks for either, it is not us. The only time your answer is ever typed in is by you, on our own password reset screen, which you reached by going to our website yourself rather than by clicking a link in an email.