Security
At Good Invest, the security of your funds and personal data is our highest priority. We employ institutional-grade security infrastructure that exceeds industry standards, ensuring your investments and information are protected around the clock.
Data Encryption
- TLS 1.3 encryption for all data in transit between your device and our servers
- AES-256 encryption at rest for all stored personal data, documents, and financial records
- End-to-end encryption for all internal communications between system components
- Hardware Security Modules (HSMs) for cryptographic key management
Platform Security
- Two-Factor Authentication (2FA) mandatory for all accounts (TOTP and SMS options)
- Biometric login support (Face ID, Touch ID) on mobile devices
- IP whitelisting and device management for withdrawal operations
- Automatic session expiration and suspicious login detection with instant alerts
- Rate limiting and CAPTCHA protection against brute-force attacks
Infrastructure
- Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II and ISO 27001 certifications
- Geographically distributed data centers with real-time failover for zero-downtime operations
- DDoS protection and Web Application Firewall (WAF) filtering all incoming traffic
- 24/7 Security Operations Center (SOC) monitoring with automated threat detection
- Regular penetration testing by independent cybersecurity firms (quarterly)
Fund Security
- Segregated accounts — Client funds are held in separate bank accounts at Tier-1 custodian institutions, completely isolated from Good Invest’s operating capital.
- Cold storage — For digital asset positions, the majority of funds are stored in offline cold wallets with multi-signature authorization.
- Withdrawal controls — All withdrawal requests require 2FA confirmation, with large transactions triggering additional manual review.
- Insurance — Comprehensive cyber insurance and professional indemnity coverage.
Compliance & Audits
- Annual SOC 2 Type II audit by an independent auditor
- Quarterly penetration testing and vulnerability assessments
- Continuous compliance monitoring with regulatory requirements
- Internal security training for all employees on a quarterly basis
Responsible Disclosure
We welcome reports from security researchers who discover potential vulnerabilities in our systems. If you believe you have found a security issue, please contact us at security@goodinvest.hk. We commit to investigating all legitimate reports and will not take legal action against researchers who act in good faith.