Security

Get peace of mind

Ultra-secure offline funds. Best-in-class software. Private key management. Invest and Stocks is committed to the confidentiality, integrity, and availability of data entrusted to the organization. We help you keep your crypto and your data secure. Information security is a top priority and has the full support of top management. Our information security management system is continuously maturing to stay up-to-date with best-in-class security. Security controls are regularly audited both internally and externally.

    95% of all funds are stored in offline cold wallets

    • Funds are distributed worldwide in facilities globally-recognized for physical security.
    • Multi-signature validation means no one can unilterally access your funds. Not our CEO. Not even Satoshi.
    • Private keys don’t leave Hardware Security Modules where funds are stored, a cryptographic best practice.
     

    Secure software on desktop and mobile

    • The Wallet and Exchange both support 2FA and use AES-256 encryption. Additionally, we store the private keys for custodied funds in FIPS 140-2 certified devices.
    • Invest and Stocks enforces TLS 1.2 for Internet-facing applications and audits support cypher periodically.
    • Strong cyphers are used to enforce storage encryption across the cloud and physical facilities.

    Compliance

    • ISO 27001 Certified

      ISO 27001 Certified

      At Invest and Stocks, we have implemented an integrated Information Security Management System certified against an internationally recognized standard. Controls undergo an external audit on an annual basis and are consistently monitored internally as well.

    • CryptoCurrency Security Standard (CCSS) Level 3

      CryptoCurrency Security Standard (CCSS) Level 3

      CCSS has specialized information security requirements tailored to the crypto industry. In an external audit against this standard, Invest and Stocks has achieved Level 3 compliance, the maximum classification available.

    • SOC 2

      SOC 2

      Invest and Stocks’s controls are assessed by A-LIGN, who specialize in compliance across multiple industries, on an annual basis. A copy of this report can be shared upon NDA signature.

    • PCI DSS Compliant

      PCI DSS Compliant

      The payment card industry requires compliance with strict standards to ensure the confidentiality of any cardholder data. Invest and Stocks is aligned with PCI DSS requirements.