By VA Workers PH Team · Published June 18, 2026
VAs often get access to sensitive client information — email accounts, customer data, financial details, passwords. Handling that responsibly isn't just good practice, it's often what determines whether a client trusts you with bigger responsibilities.
Tools like Bitwarden (free tier is solid) or 1Password let you store and share client credentials securely without emailing passwords in plain text or writing them in a shared doc anyone could stumble on. Many password managers also support secure sharing, so a client can grant you access without you ever seeing the actual password.
If a client shares login credentials, keep them only in the password manager they've approved — not in your notes app, not in a personal spreadsheet, not in your email. If you switch clients or projects, revoke/remove access rather than leaving old credentials sitting around.
Enable 2FA wherever a client's tools support it, and understand how to use authenticator apps (not just SMS, which is less secure) — clients notice when a VA proactively suggests better security practices rather than seeing it as extra friction.
If you work from cafes or co-working spaces, use a VPN when accessing client accounts on public networks — sensitive data (client CRM logins, financial dashboards) shouldn't be accessed over unsecured wifi without that extra layer.
Occasionally a client might ask for something that crosses a line — sharing their own client's personal data insecurely, bypassing a security step "just this once," or using your personal accounts to send on their behalf in a way that mixes identities. It's reasonable to flag these gently rather than just complying; a client who values good practice will respect it, and it protects you too.
Ready to find your next VA job?
Browse 100+ verified remote VA jobs from real employers — free to browse, free to apply.
Browse jobs now →More articles: