Information Security Policy Statement

AquaRich International Investment Group Limited

Effective Date: [2026/5/1]

Document No.: WEB-SEC-001

AquaRich International Investment Group Limited regards information security as a core foundation of platform operations and customer protection. Protecting users’ digital assets, account security, business systems, transaction records, and personal information is an important component of the Company’s ongoing operations and risk management.

This statement summarizes the Company’s core principles and primary measures relating to information security, asset protection, access control, incident response, and security cooperation. This statement is a principles-based public disclosure and does not constitute a commitment regarding any specific technical architecture, fixed performance standard, absolute security outcome, or ongoing future implementation.

1. Security Governance Principles

The Company follows the following core principles in its information security management:

1. Least Privilege: Employees, systems, and services are granted only the minimum access necessary to perform their functions.

2. Segregation of Duties: Key functions involving funds, configuration, approval, recording, and audit are subject to separation and layered control.

3. Defense in Depth: Multi-layer controls are implemented across network, system, application, data, account, and operational layers.

4. Enhanced Controls for High-Risk Activities: Sensitive operations, critical configuration changes, permission grants, and large or high-risk asset actions are subject to enhanced approval, review, or restriction.

5. Continuous Improvement: Security measures are continually reviewed and improved in light of business changes, evolving threats, incident reviews, and audit results.

2. Digital Asset and System Security Measures

Depending on its business model, technical architecture, and risk control needs, the Company may implement measures including, without limitation:

  • layered management of hot and cold wallet environments to reduce online exposure;
  • graded protection of key materials, sensitive configurations, and high-risk permissions;
  • multi-level approval, dual review, or other enhanced controls for important operations;
  • additional security checks for withdrawal address management, newly introduced high-risk actions, and anomalous device behavior;
  • reconciliation controls, operational audit trails, anomaly alerts, and permission revocation procedures;
  • monitoring and protective measures for core systems, interfaces, logs, databases, and critical infrastructure.

3. Account and Data Protection

The Company applies reasonable technical and organizational safeguards to protect user accounts and data, including, without limitation:

  • login protection, secondary verification, or other additional account security controls;
  • detection of unusual logins, unusual devices, unusual network environments, and anomalous behavior;
  • encryption in transit, data access controls, and protection of sensitive fields;
  • tiered management of identity records, customer support records, transaction records, and other sensitive data;
  • role-based access control and internal authorization management;
  • employee confidentiality obligations and internal security training.

4. Vulnerability Management and Security Testing

The Company may conduct appropriate security scanning, configuration checks, remediation activities, security testing, or independent reviews based on business needs and risk management requirements in order to identify and reduce potential security risks.

For important systems, critical modules, or major version changes, the Company may combine internal checks, third-party review, penetration testing, log analysis, or other validation measures to assess and address security risks.

5. Security Incident Response

The Company maintains a framework for identifying, classifying, responding to, containing, remediating, recovering from, and reviewing security incidents. Where incidents involve account security, data security, asset security, system availability, or third-party service disruption, the Company will take necessary control and remedial measures based on the nature of the incident, its impact, and applicable legal and regulatory requirements.

Where legally permitted and reasonably practicable, the Company may notify affected users through announcements, in-platform notices, email, or other appropriate channels.

6. User Security Reminders

To better protect your account and assets, please note the following:

  • Please access the platform only through the official Anwin app or the official website at anwin.tech;
  • Please properly safeguard your password, verification codes, email account, mobile number, and other authentication information;
  • Please enable any additional account protection features supported by the platform where available;
  • If you detect unusual login activity, suspicious withdrawals, imitation websites, fake customer support, or any other security risk, please contact us immediately through official channels;
  • Platform personnel will never ask you through unofficial channels for your password, verification code, private key, seed phrase, or any other sensitive authentication information.

7. Security Vulnerability Disclosure

If you identify a potential security vulnerability, weakness, or other information security risk affecting the platform, you may contact us through:

We encourage responsible disclosure of security issues. Please do not exploit vulnerabilities, damage systems, access data that does not belong to you, or disclose information to third parties in a manner that may create security harm.