Security, how we protect your account

Account security on Inves 21 is built in layers: something you know, something you have, and a record of everything that happens. This page explains all nine measures in plain language, what each one does and does not protect against, and the part you play in keeping your own account safe.

The nine measures

Each measure below is standard on every account and every tier. There is no security upgrade to buy, because security is not a product here.

1. Two-factor authentication

Two-factor authentication (2FA) is supported through authenticator apps and one-time codes delivered to your verified contact details. It is mandatory before the first withdrawal, so a stolen password on its own can never move money out of your account.

If you lose access to your 2FA device, recovery is possible only through the verified support route with identity re-confirmation, described in measure 6. There is no shortcut, and that is deliberate.

2. Encryption

All traffic between your device and the platform is encrypted in transit with TLS, and data at rest is encrypted on the systems that store it. Identity documents collected during verification are stored separately from general account data, with access limited to the compliance team that needs them.

Encryption protects data from interception and from casual exposure. It does not protect an account whose password was handed over willingly, which is why measures 3 and 4 exist.

3. Fraud and phishing protection

Official communication comes only from the domain inves21.org and the address [email protected]. We never ask for your password, your 2FA codes, or remote access to your device, and any message that does is fraudulent regardless of how it looks.

The fraud warning page lists the three checks that confirm you are dealing with us: the domain, the address, and the behaviour. Learn them before your first deposit, not after a scare.

4. Login alerts

Every login from a new device or an unusual location triggers an email alert to your registered address. Alerts state the device, the approximate location, and the time, so a session that is not yours stands out immediately.

If an alert does not match something you did, change your password, review active sessions in settings, and contact support the same day. Speed matters more than embarrassment; we would rather hear about ten false alarms than one real one late.

5. Devices and sessions

Settings list every active session with its device type and last activity, and any session can be ended remotely with one click. Sessions expire automatically after a period of inactivity, and a password change invalidates all other sessions at once.

This matters most for shared computers. If you reviewed your portfolio at an internet cafe or a family laptop, signing the session out remotely is a two-second habit worth building.

6. Account recovery

Recovery of a lost password or a lost 2FA device goes through identity verification with the support desk: registered details are confirmed, identity documents are re-checked, and a cooldown applies before sensitive changes take effect. The cooldown exists so an attacker who convinces one agent cannot act before you notice the alert emails.

Recovery can only restore access to the rightful account holder. It cannot be used to change the destination bank account and withdraw in the same motion; payout changes follow their own waiting period under the withdrawal policy.

7. API key rights

Where the platform connects to a venue on your behalf, API keys are created with the minimum rights the function requires: reading market data, placing orders within your limits, and never withdrawing funds. Withdrawal rights are not granted to trading keys at all, as a matter of architecture rather than policy preference.

Keys are stored encrypted, rotated on a schedule, and revoked the moment a function they served is no longer needed. You can ask which connections exist on your account at any time, and support answers in writing.

8. Audit log

Every login, every session, every strategy or limit change, every withdrawal request, and every change to your personal details is written to an audit log with a timestamp. The log cannot be edited from the account side, which is exactly what makes it useful.

When something looks wrong on a statement or a setting you do not remember changing, the audit log is what support reads back to you, line by line. The table further down this page lists what is recorded.

9. Incident support

If you suspect unauthorised access, write to [email protected] with the subject line Security. The account can be frozen while the audit log is reviewed, payouts are held during an open investigation, and you receive a written summary of what happened and what changed.

Incident reports are answered within one business hour during support hours, and a first response to an active security concern is treated as urgent regardless of your tier.

Three rings, one account

It helps to picture security here as three rings. The outer ring is the platform layer: encryption, API key discipline, and infrastructure hardening that you never see but that everything else depends on. The middle ring is the account layer: 2FA, login alerts, session control, and the audit log that make any unusual activity loud. The inner ring is the money layer: verification before withdrawals, payout changes with waiting periods, and the withdrawal policy that governs every payout.

An attacker has to defeat all three rings to reach funds, and each ring is designed on the assumption that the one before it might fail. That is also why an account holder who hands over a password and a 2FA code to a convincing caller has effectively opened the door from inside: no ring survives its owner turning the lock. The fraud warning page covers what we will never ask you, which is the fastest test there is.

The anatomy of a real attack attempt

Most attacks on investment accounts in South Africa follow the same short script. First comes contact: a call, an SMS, or a message that claims to be from your platform, often referencing a made-up security incident to raise urgency. Then comes authority: a caller who knows your name and maybe your registration date, which is less private than people assume. Then comes the ask: your password, your one-time code, or approval of a transaction you did not make, always framed as protection.

The counter-script is shorter. Hang up or ignore the message. Open the platform yourself by typing inves21.org, never through a link someone sent you. Check the alerts and the audit log for anything you did not do. If something genuinely needs fixing, support will still be there when you contact them first, and a real security process never requires you to act within minutes.

What the audit log records

The events below are timestamped against your account. You can request a copy through support at any time.

EventWhat is recorded
LoginsTime, device, approximate location, and whether 2FA was satisfied.
Failed login attemptsTime and source, so repeated attempts against your account are visible.
Password and detail changesTime, what changed, and the session that changed it.
Strategy and limit changesThe previous value, the new value, and when the change took effect.
Deposit and withdrawal requestsAmount, method, destination, and the checks applied to the request.
Payout detail changesThe old and new destination, and the waiting period applied before it becomes usable.
Support contactsWhen you contacted support and a summary of what was actioned.

Your part, honestly stated

The platform carries most of the weight, and your part is deliberately small but not zero. Use a password you do not use anywhere else, keep 2FA active, treat every unexpected contact as hostile until proven otherwise, and read the login alerts even when you are busy. Those four habits close the routes that no platform-side measure can close, because they start at your side of the screen.

Security also has limits that honesty requires stating. These measures protect access, data, and the integrity of your account settings. They do not protect the value of what the account holds: markets can fall regardless of how well locked the door is. Read this page together with the risk disclosure, and treat both as part of the same promise, which is that we tell you the plain version of things.

Questions about anything on this page go to Client Support and Compliance at [email protected], Monday to Friday, 8:30 to 17:30 SAST (excluding public holidays). Security questions are answered in writing, always.