SkyHills Casino — Security Guide: Password, 2FA, Recovery
Security at a Glance
| SkyHills — Security & Account Protection | |
|---|---|
| Casino | SkyHills — skyhillscaasino.com |
| License | Costa Rica |
| KSA Status | No KSA License |
| Founded | 2024 |
| SSL/TLS | 256-bit SSL, TLS 1.3 |
| Password Requirements | Min. 8 characters |
| Brute-force Protection | Account lockout after 5 attempts |
| Session Timeout | Automatic logout after inactivity |
| Login Notifications | Email alert on new device login |
| Withdrawal Notifications | Email + dashboard notification for every withdrawal |
| RNG Audits | Periodic audits by independent third party |
| Transaction History | Accessible via dashboard, 12 months |
| Self-exclusion | 24 hours / 1 week / 1 month / 6 weeks / permanent |
| Anti-phishing Policy | Passwords are never requested via email |
| Support Organizations | GamCare, Gambling Therapy |
| Bonus Terms | See our guide → |
| Mobile Experience | See our guide → |
Quick Overview: Security at SkyHills
SkyHills Casino was founded in 2024 and holds a license from Costa Rica. The platform offers an integrated sportsbook alongside the casino section and processes transactions via both crypto and traditional payment methods. The welcome bonus is 200% on the first deposit up to €1,500, with a minimum deposit of €20 and a wagering requirement of 35x (deposit + bonus) within 7 days.
On the security front, the infrastructure relies on TLS 1.3 transport encryption for all connections between your browser and our servers. Account security is implemented in layers: in addition to a strong password, we offer two-factor authentication (2FA) via TOTP apps. KYC verification is mandatory before the first withdrawal. For mobile use, a responsive mobile site is available; no iOS or Android app is available.
The sections below cover each security topic in technical depth: exact steps, decision trees, comparison tables and checklists. Bonuses and payments are only covered at a high level here — for details, please refer to the bonus page.
Two-Factor Authentication (2FA): Step by Step
What is TOTP and How Does It Work
TOTP stands for Time-based One-Time Password (RFC 6238). Every 30 seconds, the authenticator app on your phone generates a new 6-digit code based on a shared secret (a QR code you scan once) and the current Unix time. Our servers independently calculate the same value. If the code matches, you are logged in. The code expires after 30 seconds, making replay attacks pointless.
Because the code is generated locally on your device — without any network traffic — TOTP is more robust than SMS verification. SMS codes are vulnerable to SIM swapping; TOTP codes are not.
Enabling 2FA: Exact Steps
- Log in via SkyHills login with your existing password.
- Go to Account Settings → Security → Two-Factor Authentication.
- Click Enable 2FA. The page will display a QR code and a text-based secret key (26 characters, base32-encoded).
- Open your authenticator app (see comparison table below) and scan the QR code, or enter the text key manually.
- The app will immediately display a 6-digit code. Enter this in the confirmation field. You have up to 30 seconds; wait for the next cycle if needed.
- Save your backup codes. We display ten single-use codes of 12 characters each. Store these offline — in a password manager or printed and kept in a safe.
- Click Confirm and Activate. From this point on, 2FA is required for every new session.
TOTP App Comparison
Not every authenticator app offers the same backup and recovery capabilities. The table below compares the three most widely used options on the points most relevant for account recovery.
| App | Cloud Backup | Multiple Devices | Export Feature | Open Source | Recommended For |
|---|---|---|---|---|---|
| Google Authenticator | Yes (Google account, v6.0+) | Yes (via backup) | QR export to new device | No | Users already in the Google ecosystem |
| Authy | Yes (Authy cloud, encrypted) | Yes (up to 5 devices) | No (intentionally restricted) | No | Users who use multiple devices |
| Microsoft Authenticator | Yes (Microsoft account) | Yes (via backup) | Limited (backup/restore) | No | Users in a Microsoft 365 environment |
| Aegis (Android) | No (local only) | No (manual export) | Yes (encrypted JSON) | Yes | Users who prioritize control over their own data |
| Raivo (iOS) | Yes (iCloud, encrypted) | Yes (iCloud devices) | Yes (encrypted ZIP) | Yes | iOS users who prefer open source |
Lost Your Phone: What Now
If you have lost your phone and cannot access your authenticator app, there are two routes. Route 1: use one of the ten backup codes you saved when activating 2FA. Each code works only once. Route 2: contact our customer support and go through the identity verification process — you will need a government-issued ID that matches your KYC documents. See the account recovery section for the full decision tree.
Password Policy and Password Management
Minimum Password Requirements
Our system will only accept a password if it meets all of the following criteria:
- At least 12 characters long
- At least one uppercase letter (A–Z)
- At least one lowercase letter (a–z)
- At least one digit (0–9)
- At least one special character (!@#$%^&* and similar)
- No three or more consecutive identical characters (e.g., "aaa")
- Not identical to your email address or username
- Not present in our list of 100,000 known compromised passwords (based on the Have I Been Pwned dataset)
Common Mistakes
Adding a capital letter at the beginning and an exclamation mark at the end of a recognizable word ("Casino1!") technically meets the minimum requirements, but is in practice easily guessable for an attacker running dictionary attacks. A password like "Blue3Bicycle!Moon" — four random words with variation — already has an entropy of over 50 bits at 12 characters, making brute-force attacks with standard hardware practically infeasible.
Reusing the same password across multiple platforms is the single greatest security risk when it comes to account compromise. If another platform suffers a data breach and your password is exposed, automated scripts will immediately attempt that password on hundreds of other services — including online casinos.
Recommended Password Managers
We recommend using a password manager to generate and store unique passwords. Bitwarden (open source, free basic version), 1Password and KeePassXC (fully local) are popular choices. A password manager generates random strings of 20+ characters per service, making password reuse structurally impossible.
Do not store your SkyHills password in your browser's built-in password manager if that browser is synced to an account whose security you do not fully control. A standalone password manager with its own master password provides an additional layer of isolation.
Account Recovery: Decision Tree for Five Scenarios
Below you will find a structured decision tree for the five most common situations where you cannot access your account. Follow the steps in order; do not skip any step.
Account Recovery Decision Tree
| Scenario | First Step | Second Step | Third Step | Expected Processing Time |
|---|---|---|---|---|
| 1. Forgot Password | Click "Forgot Password" on the login page | Check your email inbox for the reset link (valid for 15 minutes) | Set a new password that meets the policy requirements | 2–5 minutes |
| 2. Account Locked (too many failed attempts) | Wait 30 minutes; the lock is lifted automatically | Log in with the correct password + 2FA code | If password is unknown: see scenario 1 | 30-minute wait |
| 3. 2FA Device Lost, Backup Codes Available | Log in with your password; enter a backup code on the 2FA screen | Go to Security → 2FA and disable the old 2FA | Link a new device and re-enable 2FA | 5–10 minutes |
| 4. 2FA Device Lost, No Backup Codes | Contact our customer support | Provide a government-issued ID matching your KYC documents | After verification, our team manually disables 2FA; you then link a new device | 1–3 business days |
| 5. Account Compromised (unauthorized login) | Use "Forgot Password" to immediately block the attacker's access | Contact our customer support immediately and report the incident | Our security team freezes withdrawals, reviews session logs and sends an incident report | Initial response within 4 hours; full investigation 2–5 business days |
| 6. Session Expired (automatically logged out) | Sessions expire after 60 minutes of inactivity or when the browser is closed | Log in again via SkyHills login with password + 2FA | Not applicable | Immediate |
| 7. Email Address No Longer Accessible | Contact customer support with your account name and KYC documents | Our team verifies your identity via document + liveness check | After verification, the email address is updated; you receive a confirmation at the new address | 2–4 business days |
Exact Flow for an Account Lockout
When you enter an incorrect password five times in a row, our system records a timestamp and blocks further login attempts for 30 minutes. You will automatically receive an email notification at your registered address showing the time of the lockout and the IP address of the last attempt. If you did not make that attempt yourself, treat this as scenario 5 above.
After 30 minutes, the lockout is automatically lifted without any customer support intervention. There is no button to speed up the waiting period. This is a deliberate security measure to slow down automated attacks.
Encryption and Data Protection
Transport Layer Security (TLS)
All connections between your browser and our servers use TLS 1.3. TLS 1.0 and 1.1 are disabled on our servers; TLS 1.2 is available as a fallback for older devices but is not prioritized. The certificate is issued by a publicly trusted CA and has a validity of 90 days with automatic renewal.
You can verify the connection security yourself: click the padlock icon in your browser's address bar and check that the certificate is valid for the domain skyhillscaasino.com. A valid TLS connection effectively eliminates man-in-the-middle attacks over the network.
Data Storage
Passwords are never stored in plain text. We use bcrypt with a work factor of 12 for password hashing. This means that even in the hypothetical event of a database breach, the passwords would not be directly usable by an attacker — cracking a single bcrypt hash with work factor 12 takes several seconds per attempt on standard hardware.
Payment details (card numbers, banking details) are not stored on our servers. Transactions are processed through certified payment processors that maintain PCI DSS Level 1 compliance. We receive only a transaction ID and a masked reference.
What Data We Collect
We collect: name, date of birth, address, email address, phone number, IP address logs (retained for up to 12 months for fraud investigation), session data, gaming history and deposit/withdrawal history. KYC documents (proof of identity, proof of address) are stored encrypted and are accessible only to our compliance team.
8-Point Security Audit: Check Your Own Account
- 2FA enabled? Go to Account Settings → Security and verify that 2FA is active.
- Backup codes saved? Check that you have stored your ten backup codes offline.
- Password unique? Do not use this password anywhere else. Check via haveibeenpwned.com whether your email address appears in a known breach.
- Email address current? Log in and verify that the registered email address is still active and exclusively yours.
- Check active sessions? Go to Security → Active Sessions. Do you recognize all devices and locations? If not, log out of all sessions and change your password.
- KYC complete? A fully verified account blocks withdrawals to unverified methods, providing an additional layer of protection in the event of account compromise.
- Notifications enabled? Make sure email notifications are enabled for login attempts, password changes and withdrawals.
- Recovery details up to date? Verify that your phone number and recovery email address are correct and still belong to you.
KYC Verification: Documents, Processing Times and Rejections
Why KYC Is Mandatory
KYC (Know Your Customer) is a legal requirement under anti-money laundering regulations that applies to Costa Rica-licensed operators as well. Practically speaking, KYC protects you: a withdrawal to an unverified account is blocked, which prevents an attacker from transferring your balance to an unknown account.
Accepted Documents
| Document Type | Purpose | Requirements |
|---|---|---|
| Passport | Proof of identity | Valid, both sides, all four corners visible, no flash glare |
| National identity card (ID card) | Proof of identity | Valid, front and back, legible MRZ line |
| Driver's license (with photo) | Proof of identity (secondary) | Valid, both sides, name and date of birth legible |
| Bank statement | Proof of address | No more than 3 months old, name + address + bank logo visible, not cropped |
| Utility bill | Proof of address | No more than 3 months old, name + address + supplier name visible |
| Selfie with ID document | Liveness check (if requested) | Face and ID document fully visible in one photo, no filters |
Processing Times
During periods of high request volumes, this can take up to 72 hours. You will receive an email confirmation once verification is complete or when additional documents are requested.
What Happens When a Document Is Rejected
If a document is rejected, you will receive an email with the specific reason: illegible text, expired document, name mismatch, or document is cropped. You may resubmit the document. There is no limit on the number of resubmissions, but each new submission starts a new processing period of 24–48 hours. Make sure photos are taken in good lighting, without flash and without any deliberate editing.
Withdrawals are blocked until KYC is fully completed. Deposits and gameplay are possible without full KYC, but we recommend completing verification immediately after registering with SkyHills to avoid delays when withdrawing.
Phishing and Fraud Protection
How to Recognize Our Official Site
The only official domain for this platform is skyhillscaasino.com. Always check the full URL in the address bar before logging in or entering payment details. Phishing domains use variants such as "skyhills-casino.com", "skyhi11s.com" or subdomains like "bonus.skyhillscasino.net" — these are not official domains.
What We Will Never Ask via Email or Chat
- Your full password (we never ask for a password — only you know it)
- Your 2FA code outside of the login process
- Credit card details via email or chat
- Payment of a "verification fee" or "processing fee" before a withdrawal
- Access to your device via remote desktop software
- Your PIN or CVV code
Common Attack Patterns
Bonus phishing: An email or message claims you have won an exclusive bonus and asks you to log in via an external link. The link leads to a fake login page that captures your credentials. Always verify the sender and navigate to the site manually rather than clicking links.
Customer support impersonation: An attacker contacts you via social media or a chat platform, posing as a SkyHills Casino employee. Our customer support team never proactively reaches out via external social media channels and never asks for login credentials. If someone claims to be one of our staff members, log in yourself via the official site and contact us through the official channel to verify.
SIM swapping: An attacker convinces your mobile carrier to transfer your phone number to a new SIM card, then intercepts SMS verification codes. This is one reason why we recommend TOTP-based 2FA over SMS verification — TOTP codes cannot be intercepted via your phone number.
How to Report a Suspicious Incident
If you suspect phishing or fraud targeting your account, contact our customer support immediately via the official channel on the site. If possible, include a screenshot of the suspicious message. Our security team will document the incident and can, if necessary, preventively freeze your account while the investigation is ongoing.
Responsible Gambling and Self-exclusion Tools
Available Limits on Our Platform
We offer the following self-management tools via Account Settings → Responsible Gambling:
| Tool | Description | Effective From | Removal Procedure |
|---|---|---|---|
| Deposit Limit | Daily, weekly or monthly maximum on deposits | Immediately | Increase: 24-hour waiting period. Decrease: immediate. |
| Session Limit | Maximum play time per session | Immediately | Increase: 24-hour waiting period. Decrease: immediate. |
| Loss Limits | Maximum loss per day, week or month | Immediately | Increase: 24-hour waiting period. Decrease: immediate. |
| Cooling-off Period | Temporary exclusion from 24 hours to 6 weeks | Immediately | Automatically lifted after the chosen period ends |
| Self-exclusion | Permanent or long-term exclusion (minimum 6 months) | Immediately | Reactivation only after the set period + written request |
Support Organizations
If you are concerned about your own gambling behavior or that of someone close to you, the following organizations are available:
| Organization | Website | Phone |
|---|---|---|
| AGOG (Anonymous Gamblers / Family of Gamblers) | agog.nl | — |
| Jellinek | jellinek.nl | 0900-1090 |
| Loket Kansspel | loketkansspel.nl | — |
| CRUKS (KSA-licensed operators only) | cruks.kansspelautoriteit.nl | — |
Playing from the Netherlands: What You Need to Know
SkyHills Casino NL partly targets Dutch-speaking players, but the platform does not hold a license from the Netherlands Gambling Authority (KSA). This has direct implications for your legal position and the availability of certain protective mechanisms.
| Topic | Situation |
|---|---|
| KSA License | Not applicable — license is issued by Costa Rica |
| CRUKS Affiliation | Not applicable — only KSA-licensed operators are affiliated with CRUKS |
| Own Self-exclusion | Available via Account Settings → Responsible Gambling (platform-specific) |
| Tax on Winnings (NL) | Dutch gambling tax applies to winnings above the exemption threshold. Consult the Dutch Tax Authority or a tax advisor for your personal situation. |
| Minimum Age | 18 years — identity verification mandatory via KYC |
| Currency | Euro (€) as primary currency; cryptocurrency also available |
| Local Payment Methods | Specific availability not published; refer to the main page for current payment options |
| Consumer Protection | Dutch consumer law may not apply; disputes fall under the jurisdiction of Costa Rica |
Gambling can be addictive. Play responsibly. 18+.
SkyHills Bonus: Key Facts
The welcome bonus at SkyHills Casino is 200% on the first deposit up to a maximum of €1,500. The minimum deposit to activate the bonus is €20. No bonus code is required — the bonus is automatically credited on your first deposit after registering with SkyHills.
Wagering Requirement: Worked Example
The wagering requirement is 35x on the combined total of deposit and bonus. Below is a worked example using the maximum bonus:
| Parameter | Value |
|---|---|
| Deposit | €750 |
| Bonus amount (200% of €750) | €1,500 |
| Total wagering required (35 × (€750 + €1,500)) | €78,750 |
| Time limit | 7 days from activation |
| Required wager per day (average) | €11,250 |
This is a substantial wagering volume. Read the full bonus terms on the bonus page before activating the bonus. The wagering requirement also affects how quickly you can withdraw: as long as the wagering requirement has not been completed, withdrawals of bonus funds are blocked. Your own deposited funds remain withdrawable at all times, unless the bonus terms state otherwise.
Conclusion: Security Status of SkyHills
The platform's security infrastructure is built on TLS 1.3, bcrypt password hashing, TOTP-based 2FA and mandatory KYC verification before withdrawal. These are solid foundational measures. Your own contribution — a unique strong password, 2FA enabled, backup codes saved and KYC completed — largely determines how well your account is actually protected.
Use the registration page to create an account and activate 2FA immediately after signing up. Consult the bonus page for the full bonus terms before making a deposit.
Gambling can be addictive. Play responsibly. 18+. This platform is not licensed by the Netherlands Gambling Authority (KSA) and is not affiliated with CRUKS. For self-exclusion from KSA-licensed operators: cruks.kansspelautoriteit.nl.