AquaRich International Investment Group Limited
Effective Date: [2026/5/1]
Document No.: WEB-SEC-001
AquaRich International Investment Group Limited regards information security as a core foundation of platform operations and customer protection. Protecting users’ digital assets, account security, business systems, transaction records, and personal information is an important component of the Company’s ongoing operations and risk management.
This statement summarizes the Company’s core principles and primary measures relating to information security, asset protection, access control, incident response, and security cooperation. This statement is a principles-based public disclosure and does not constitute a commitment regarding any specific technical architecture, fixed performance standard, absolute security outcome, or ongoing future implementation.
The Company follows the following core principles in its information security management:
1. Least Privilege: Employees, systems, and services are granted only the minimum access necessary to perform their functions.
2. Segregation of Duties: Key functions involving funds, configuration, approval, recording, and audit are subject to separation and layered control.
3. Defense in Depth: Multi-layer controls are implemented across network, system, application, data, account, and operational layers.
4. Enhanced Controls for High-Risk Activities: Sensitive operations, critical configuration changes, permission grants, and large or high-risk asset actions are subject to enhanced approval, review, or restriction.
5. Continuous Improvement: Security measures are continually reviewed and improved in light of business changes, evolving threats, incident reviews, and audit results.
Depending on its business model, technical architecture, and risk control needs, the Company may implement measures including, without limitation:
The Company applies reasonable technical and organizational safeguards to protect user accounts and data, including, without limitation:
The Company may conduct appropriate security scanning, configuration checks, remediation activities, security testing, or independent reviews based on business needs and risk management requirements in order to identify and reduce potential security risks.
For important systems, critical modules, or major version changes, the Company may combine internal checks, third-party review, penetration testing, log analysis, or other validation measures to assess and address security risks.
The Company maintains a framework for identifying, classifying, responding to, containing, remediating, recovering from, and reviewing security incidents. Where incidents involve account security, data security, asset security, system availability, or third-party service disruption, the Company will take necessary control and remedial measures based on the nature of the incident, its impact, and applicable legal and regulatory requirements.
Where legally permitted and reasonably practicable, the Company may notify affected users through announcements, in-platform notices, email, or other appropriate channels.
To better protect your account and assets, please note the following:
If you identify a potential security vulnerability, weakness, or other information security risk affecting the platform, you may contact us through:
We encourage responsible disclosure of security issues. Please do not exploit vulnerabilities, damage systems, access data that does not belong to you, or disclose information to third parties in a manner that may create security harm.