Overview
Migma is built with enterprise-grade security and compliance at its core. We maintain SOC 2 certification, GDPR compliance, and help you meet email marketing regulations like CAN-SPAM and CASL.SOC 2 Certified
GDPR Compliant
Email Law Compliant
SOC 2 Compliance
What is SOC 2?
SOC 2 (Service Organization Control 2) is an auditing standard developed by the American Institute of CPAs (AICPA) that ensures service providers securely manage data to protect customer privacy. Migma’s SOC 2 Type II certification means we’ve been independently audited for:Security
Security
- Multi-factor authentication (MFA)
- Role-based access control (RBAC)
- Principle of least privilege
- Regular access reviews
- Encrypted data transmission (TLS 1.3)
- Encrypted data at rest (AES-256)
- Firewall protection
- Intrusion detection systems
- Code review processes
- Security testing
- Vulnerability scanning
- Dependency monitoring
Availability
Availability
- Redundant infrastructure
- Load balancing
- Auto-scaling
- Disaster recovery plan
- 24/7 system monitoring
- Automated alerting
- Performance metrics
- Incident response procedures
- Daily automated backups
- Multiple backup locations
- Point-in-time recovery
- Backup testing quarterly
Processing Integrity
Processing Integrity
- Input validation
- Error handling
- Transaction logging
- Audit trails
- Data validation rules
- Automated testing
- Manual verification for critical operations
- Reconciliation procedures
Confidentiality
Confidentiality
- Public, internal, confidential, restricted
- Appropriate handling per classification
- Access controls based on sensitivity
- Employee NDAs
- Vendor agreements
- Customer data agreements
Privacy
Privacy
- Clear privacy policy
- Consent mechanisms
- Purpose limitation
- Data minimization
- Right to access
- Right to deletion
- Right to portability
- Right to rectification
SOC 2 Benefits for Customers
GDPR Compliance
What is GDPR?
General Data Protection Regulation (GDPR) is EU law protecting personal data and privacy. It applies to:- Companies operating in the EU
- Companies offering goods/services to EU residents
- Companies monitoring EU residents’ behavior
GDPR Principles
Migma helps you comply with all seven GDPR principles:- Lawfulness
- Purpose Limitation
- Data Minimization
- Accuracy
- Storage Limitation
- Integrity & Confidentiality
- Accountability
- ✅ Consent: Clear opt-in mechanisms
- ✅ Contract: Transactional emails
- ✅ Legitimate interest: Service communications
- Consent tracking and timestamps
- Consent withdrawal mechanisms
- Documented lawful basis
Data Subject Rights
Migma supports all GDPR data subject rights:Right to Access
Right to Access
- Email privacy@migma.ai
- Verify identity
- Receive data within 30 days
- All personal data we hold
- How we use it
- Who we share it with
- Retention period
- Your rights
Right to Rectification
Right to Rectification
- Preference center updates
- Profile management
- Instant changes
- Email privacy@migma.ai
- Updated within 30 days
Right to Erasure ('Right to be Forgotten')
Right to Erasure ('Right to be Forgotten')
- Click “Delete my account” in settings
- Or email privacy@migma.ai
- Confirm deletion request
- ✅ Email address
- ✅ Name and profile data
- ✅ Preferences
- ✅ Email history
- ✅ Usage data
- Transaction records (tax law)
- Anonymized analytics
- Abuse prevention records
Right to Data Portability
Right to Data Portability
- Settings → Privacy → Export Data
- Download JSON or CSV
- Use anywhere
- Subscriber list with all fields
- Email templates
- Campaign history
- Analytics data
- Preference settings
Right to Restrict Processing
Right to Restrict Processing
- Preference center → Pause all emails
- Or email privacy@migma.ai
- No marketing emails sent
- Data retained but not processed
- Can be reversed anytime
Right to Object
Right to Object
- Direct marketing (unsubscribe)
- Profiling for marketing
- Legitimate interest processing
- Click unsubscribe in any email
- Preference center
- Email privacy@migma.ai
Right to Withdraw Consent
Right to Withdraw Consent
- Newsletter subscription
- Marketing emails
- Data processing
- Unsubscribe link
- Preference center
- Account deletion
GDPR Features in Migma
Built-in compliance tools:CAN-SPAM Compliance (USA)
What is CAN-SPAM?
Controlling the Assault of Non-Solicited Pornography And Marketing Act is US federal law regulating commercial email. Penalties: Up to $50,120 per violationCAN-SPAM Requirements
Migma helps you comply with all CAN-SPAM requirements:Accurate Header Information
- Verified sender domains
- Accurate from names
- Working reply-to addresses
- No deceptive routing information
Non-Deceptive Subject Lines
- ✅ “25% Off Summer Sale - Ends Friday”
- ❌ “Re: Your Order” (when there’s no order)
- ❌ “Urgent: Security Alert” (for marketing)
Identify as Advertisement
- Relationship exists
- Content is transactional
- Customer requested info
- Optional “Advertisement” disclosure
- Configurable per campaign type
Physical Postal Address
- Email footer
- Preference center
- Unsubscribe page
Clear Unsubscribe Mechanism
- Conspicuous unsubscribe option
- Works for 30 days after sending
- No fee, login, or additional info required
- ✅ One-click unsubscribe link
- ✅ 30+ day link validity
- ✅ No login required
- ✅ Instant processing
- ✅ Confirmation message
Honor Opt-Out Requests
- ⚡ Instant: Unsubscribes processed immediately
- ✅ No emails sent after opt-out
- 📝 Opt-out list maintained
- 🔒 Cannot sell/transfer opt-out list
CAN-SPAM Compliance Checklist
Before sending marketing emails:CASL Compliance (Canada)
What is CASL?
Canada’s Anti-Spam Legislation is stricter than CAN-SPAM. Key differences:- Opt-in required (vs opt-out in CAN-SPAM)
- Express or implied consent needed before sending
- Penalties: Up to $10 million CAD per violation
CASL Requirements
- Consent
- Identification
- Unsubscribe
- Explicit opt-in checkbox
- Clear what they’re consenting to
- Valid for perpetuity (until withdrawn)
- Existing business relationship
- Inquiry or application within 6 months
- Membership/volunteer relationship
- Consent date and source
- Type of consent (express/implied)
- Consent expiration (for implied)
CASL Features in Migma
Other International Regulations
EU ePrivacy (Cookie Law)
Requires consent for cookies and tracking Migma’s tracking:- Email open tracking (pixel)
- Link click tracking
- Analytics cookies (website)
- Preference center includes tracking consent
- Can disable tracking per subscriber
- Cookie consent banner (for web)
Australian Spam Act
Similar to CAN-SPAM but requires:- Consent (opt-in)
- Clear unsubscribe
- Accurate sender info
PECR (UK)
Privacy and Electronic Communications Regulations Requirements:- Consent for marketing emails
- Exceptions for existing customers
- Clear unsubscribe
Security Features
Encryption
Data in Transit
Data in Transit
- API requests
- Web interface
- Email sending
- Database connections
- Automatic redirect from HTTP
- HSTS headers
- Perfect forward secrecy
Data at Rest
Data at Rest
- Database (MongoDB encrypted)
- File storage (S3 encrypted)
- Backups (encrypted at rest)
- Separate encryption keys per customer (enterprise)
- Regular key rotation
- Hardware security modules (HSMs)
Authentication & Access Control
- User Authentication
- Role-Based Access
- API Security
- Minimum 12 characters
- Complexity requirements
- No common passwords
- Password hashing (bcrypt)
- TOTP authenticator apps
- SMS backup codes
- Enforce for all users (enterprise)
- Secure session tokens
- Automatic timeout
- Device tracking
Infrastructure Security
Application Security
Privacy Features
Data Processing Agreement (DPA)
For GDPR compliance: Enterprise customers receive a DPA covering:- Scope of processing
- Data protection obligations
- Sub-processors
- Data subject rights
- Security measures
- Breach notification
Subprocessors
Third-party services Migma uses:| Service | Purpose | Location |
|---|---|---|
| AWS | Hosting & infrastructure | USA |
| MongoDB Atlas | Database | USA |
| Anthropic | AI models | USA |
| Stripe | Payment processing | USA |
| Cloudflare | CDN & security | Global |
Data Residency
Current: Data stored in US (AWS us-east-1) Coming soon:- ✅ EU data residency option
- ✅ UK data residency option
- ✅ Customer-specified regions (enterprise)
Incident Response
Security Incident Process
Notification
- Customers notified within 72 hours
- Authorities notified (if required)
- Transparent communication
Breach Notification
If your data is compromised:- Email notification within 72 hours
- Details of what happened
- Data affected
- Steps taken
- Your recommended actions
Audit & Logging
Audit Logs
Migma logs all significant actions:Compliance Reporting
Enterprise features:- Downloadable compliance reports
- Activity summaries
- User access reports
- Data processing records
Best Practices
Use Double Opt-In (EU)
Use Double Opt-In (EU)
- User signs up
- Confirmation email sent
- User clicks confirm link
- Subscription activated
Keep Records
Keep Records
- When consent obtained
- How consent obtained
- What they consented to
- IP address (optional)
- Timestamp
Regular Compliance Review
Regular Compliance Review
- Review privacy policy (still accurate?)
- Check unsubscribe links (working?)
- Verify physical address (current?)
- Test preference center (functional?)
- Review retained data (still needed?)
Train Your Team
Train Your Team
- Privacy requirements
- How to handle data requests
- What not to do with subscriber data
- Breach reporting procedures
Intellectual Property & Prohibited Uses
Protection of Proprietary Systems
Migma’s proprietary technology is protected by intellectual property laws.Intellectual Property Rights
What Migma owns:Proprietary Technology
Proprietary Technology
- System prompts and configurations
- Model fine-tuning and training data
- Prompt engineering techniques
- AI workflow architectures
- Source code and algorithms
- Database schemas and structures
- API implementations
- User interface designs
- Email generation processes
- Image-to-email conversion algorithms
- Figma import technology
- Content optimization systems
User-Generated Content
User-Generated Content
- Your email content and copy
- Your uploaded images and assets
- Your subscriber lists and data
- Your brand materials
- Limited license to process and display your content
- Only for providing the service to you
- Revocable upon account deletion
- Non-transferable to third parties
- Claim ownership of your content
- Use your content for other customers
- Sell or license your content
- Train models on your private content (without consent)
Platform-Generated Content
Platform-Generated Content
- You receive a license to use commercially
- Migma retains underlying technology rights
- You cannot extract or reverse-engineer the generation process
- You cannot claim the AI system as your own
- ✅ Use AI-generated email in your campaigns
- ✅ Modify and customize AI output
- ❌ Extract prompts used to generate content
- ❌ Replicate our AI generation system
Enforcement & Violations
We actively monitor for violations:Detection
- Unusual API usage patterns
- Systematic data extraction attempts
- Unauthorized access to system internals
- Suspicious account activity
Investigation
- Account flagged for review
- Activity logs analyzed
- Scope of violation assessed
- Evidence documented
Enforcement Actions
- Warning notification
- Temporary access restrictions
- Mandatory compliance review
- Immediate account suspension
- Permanent account termination
- Legal action for damages
- Criminal referral (if applicable)
Penalties for Violations
Acceptable Use Policy
What you CAN do:Reporting Violations
If you discover misuse of Migma’s intellectual property:Report IP Violations
- Description of the violation
- Evidence (URLs, screenshots, etc.)
- Your contact information
- Date and time of discovery
Third-Party Compliance
If you’re building integrations or using our API:API Usage Requirements
API Usage Requirements
- Valid API key with proper scopes
- Respect rate limits
- Follow API documentation
- Proper attribution where required
- Sharing API keys
- Exceeding rate limits
- Undocumented API endpoints
- Automated account creation
Integration Guidelines
Integration Guidelines
- Official API integrations
- Zapier/Make.com workflows
- Custom internal tools
- Documented webhook usage
- Screen scraping
- Unofficial API access
- Bypassing authentication
- Extracting proprietary logic
Reseller/Agency Rules
Reseller/Agency Rules
- Manage client accounts (with permission)
- Create campaigns for clients
- Provide training and support
- Charge for your services
- Resell Migma access without authorization
- White-label Migma as your own product
- Share proprietary Migma technology
- Claim ownership of Migma features
Data Protection for Proprietary Content
How we protect our intellectual property:- Technical Measures
- Legal Measures
- Contractual Measures
- 🔒 Encrypted system prompts and configurations
- 🔐 Access controls on proprietary code
- 🛡️ Rate limiting and abuse detection
- 📊 Monitoring and anomaly detection
- 🚫 Obfuscation of sensitive algorithms
Educational Use & Research
Academic and research exceptions:- Must be non-commercial
- Requires prior written approval
- Proper attribution required
- Results may be published with permission
- Classroom demonstrations (with license)
- Student projects (non-commercial)
- Training materials (authorized only)