> ## Documentation Index
> Fetch the complete documentation index at: https://docs.migma.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> SOC 2, GDPR, CAN-SPAM compliance and enterprise-grade security features

## Overview

Migma is built with enterprise-grade security and compliance at its core. We maintain SOC 2 certification, GDPR compliance, and help you meet email marketing regulations like CAN-SPAM and CASL.

<CardGroup cols={3}>
  <Card title="SOC 2 Certified" icon="shield-check">
    Third-party audited security controls
  </Card>

  <Card title="GDPR Compliant" icon="scale-balanced">
    Full data privacy compliance for EU
  </Card>

  <Card title="Email Law Compliant" icon="envelope-circle-check">
    CAN-SPAM, CASL, and international regulations
  </Card>
</CardGroup>

<CardGroup cols={2}>
  <Card title="What you can send" icon="envelope-circle-check" href="/get-started/what-you-can-send">
    Permission-based email and no cold outreach policy.
  </Card>

  <Card title="CAN-SPAM checklist" icon="gavel" href="/compliance/can-spam-checklist">
    Practical U.S. commercial email checklist before sending.
  </Card>

  <Card title="GDPR newsletter consent" icon="user-check" href="/compliance/gdpr-newsletter-consent">
    EU and UK signup and consent best practices.
  </Card>

  <Card title="Acceptable use" icon="file-contract" href="/legal/acceptable-use">
    Platform policy summary for email and marketing use.
  </Card>
</CardGroup>

***

## SOC 2 Compliance

### What is SOC 2?

**SOC 2 (Service Organization Control 2)** is an auditing standard developed by the American Institute of CPAs (AICPA) that ensures service providers securely manage data to protect customer privacy.

**Migma's SOC 2 Type II certification** means we've been independently audited for:

<AccordionGroup>
  <Accordion title="Security" icon="shield-halved">
    **Controls to protect against unauthorized access:**

    ✅ **Access controls**

    * Multi-factor authentication (MFA)
    * Role-based access control (RBAC)
    * Principle of least privilege
    * Regular access reviews

    ✅ **Infrastructure security**

    * Encrypted data transmission (TLS 1.3)
    * Encrypted data at rest (AES-256)
    * Firewall protection
    * Intrusion detection systems

    ✅ **Secure development**

    * Code review processes
    * Security testing
    * Vulnerability scanning
    * Dependency monitoring
  </Accordion>

  <Accordion title="Availability" icon="server">
    **System uptime and reliability:**

    ✅ **99.9% uptime SLA**

    * Redundant infrastructure
    * Load balancing
    * Auto-scaling
    * Disaster recovery plan

    ✅ **Monitoring**

    * 24/7 system monitoring
    * Automated alerting
    * Performance metrics
    * Incident response procedures

    ✅ **Backups**

    * Daily automated backups
    * Multiple backup locations
    * Point-in-time recovery
    * Backup testing quarterly
  </Accordion>

  <Accordion title="Processing Integrity" icon="gears">
    **Data processed completely, accurately, and authorized:**

    ✅ **Quality controls**

    * Input validation
    * Error handling
    * Transaction logging
    * Audit trails

    ✅ **Accuracy**

    * Data validation rules
    * Automated testing
    * Manual verification for critical operations
    * Reconciliation procedures
  </Accordion>

  <Accordion title="Confidentiality" icon="eye-slash">
    **Protection of confidential information:**

    ✅ **Data classification**

    * Public, internal, confidential, restricted
    * Appropriate handling per classification
    * Access controls based on sensitivity

    ✅ **Confidentiality agreements**

    * Employee NDAs
    * Vendor agreements
    * Customer data agreements
  </Accordion>

  <Accordion title="Privacy" icon="user-lock">
    **Personal information collection, use, retention, and disposal:**

    ✅ **Privacy notice**

    * Clear privacy policy
    * Consent mechanisms
    * Purpose limitation
    * Data minimization

    ✅ **Data subject rights**

    * Right to access
    * Right to deletion
    * Right to portability
    * Right to rectification
  </Accordion>
</AccordionGroup>

### SOC 2 Benefits for Customers

<Check>**Trust:** Independent verification of security practices</Check>
<Check>**Compliance:** Helps meet your own compliance requirements</Check>
<Check>**Risk reduction:** Vendor security validated</Check>
<Check>**Due diligence:** Satisfies security questionnaires</Check>

**Need our SOC 2 report?** Contact [enterprise@migma.ai](mailto:enterprise@migma.ai)

***

## GDPR Compliance

### What is GDPR?

**General Data Protection Regulation (GDPR)** is EU law protecting personal data and privacy. It applies to:

* Companies operating in the EU
* Companies offering goods/services to EU residents
* Companies monitoring EU residents' behavior

**Penalties for non-compliance:** Up to €20 million or 4% of global revenue, whichever is higher.

### GDPR Principles

Migma helps you comply with all seven GDPR principles:

<Tabs>
  <Tab title="Lawfulness">
    **Lawful basis for processing personal data**

    Migma supports:

    * ✅ **Consent:** Clear opt-in mechanisms
    * ✅ **Contract:** Transactional emails
    * ✅ **Legitimate interest:** Service communications

    **How Migma helps:**

    * Consent tracking and timestamps
    * Consent withdrawal mechanisms
    * Documented lawful basis
  </Tab>

  <Tab title="Purpose Limitation">
    **Data collected for specified purposes only**

    **Migma's approach:**

    * Clear purpose statements
    * No unexpected data uses
    * Purpose documented in privacy policy

    **Example:**
    Email addresses collected for newsletter → only used for newsletter, not sold to third parties.
  </Tab>

  <Tab title="Data Minimization">
    **Only collect necessary data**

    **Migma collects only:**

    * Email address (required)
    * Name (if provided)
    * Preferences (user-selected)
    * Usage data (for service functionality)

    **We don't collect:**

    * Unnecessary personal data
    * Sensitive categories (race, religion, health)
    * Children's data without verification
  </Tab>

  <Tab title="Accuracy">
    **Keep data accurate and up-to-date**

    **Migma provides:**

    * Preference center for updates
    * Data export for verification
    * Automated bounce handling
    * Regular data cleaning
  </Tab>

  <Tab title="Storage Limitation">
    **Retain data only as long as necessary**

    **Migma's retention:**

    * Active subscribers: Retained while subscribed
    * Unsubscribed: 30 days, then deleted
    * Deleted accounts: Immediate removal
    * Backups: 90-day retention

    **Custom retention:** Enterprise customers can configure
  </Tab>

  <Tab title="Integrity & Confidentiality">
    **Secure data processing**

    **Migma's security:**

    * Encryption in transit (TLS 1.3)
    * Encryption at rest (AES-256)
    * Access controls
    * Regular security audits
    * Incident response plan
  </Tab>

  <Tab title="Accountability">
    **Demonstrate compliance**

    **Migma provides:**

    * Privacy policy
    * Data Processing Agreement (DPA)
    * SOC 2 report
    * Audit logs
    * Compliance documentation
  </Tab>
</Tabs>

### Data Subject Rights

Migma supports all GDPR data subject rights:

<AccordionGroup>
  <Accordion title="Right to Access" icon="folder-open">
    **Individuals can request their data**

    **How to request:**

    1. Email [privacy@migma.ai](mailto:privacy@migma.ai)
    2. Verify identity
    3. Receive data within 30 days

    **What you receive:**

    * All personal data we hold
    * How we use it
    * Who we share it with
    * Retention period
    * Your rights

    **Format:** Machine-readable (JSON/CSV)
  </Accordion>

  <Accordion title="Right to Rectification" icon="pen-to-square">
    **Individuals can correct inaccurate data**

    **Self-service:**

    * Preference center updates
    * Profile management
    * Instant changes

    **Request correction:**

    * Email [privacy@migma.ai](mailto:privacy@migma.ai)
    * Updated within 30 days
  </Accordion>

  <Accordion title="Right to Erasure ('Right to be Forgotten')" icon="eraser">
    **Individuals can request deletion**

    **How to request:**

    1. Click "Delete my account" in settings
    2. Or email [privacy@migma.ai](mailto:privacy@migma.ai)
    3. Confirm deletion request

    **What gets deleted:**

    * ✅ Email address
    * ✅ Name and profile data
    * ✅ Preferences
    * ✅ Email history
    * ✅ Usage data

    **Retained (legal requirements):**

    * Transaction records (tax law)
    * Anonymized analytics
    * Abuse prevention records

    **Timeline:** Immediate deletion, confirmed within 24 hours
  </Accordion>

  <Accordion title="Right to Data Portability" icon="download">
    **Individuals can export their data**

    **Export your data:**

    1. Settings → Privacy → Export Data
    2. Download JSON or CSV
    3. Use anywhere

    **Includes:**

    * Subscriber list with all fields
    * Email templates
    * Campaign history
    * Analytics data
    * Preference settings
  </Accordion>

  <Accordion title="Right to Restrict Processing" icon="hand">
    **Individuals can limit how data is used**

    **How to restrict:**

    1. Preference center → Pause all emails
    2. Or email [privacy@migma.ai](mailto:privacy@migma.ai)

    **Effect:**

    * No marketing emails sent
    * Data retained but not processed
    * Can be reversed anytime
  </Accordion>

  <Accordion title="Right to Object" icon="ban">
    **Individuals can object to processing**

    **Object to:**

    * Direct marketing (unsubscribe)
    * Profiling for marketing
    * Legitimate interest processing

    **How:**

    * Click unsubscribe in any email
    * Preference center
    * Email [privacy@migma.ai](mailto:privacy@migma.ai)
  </Accordion>

  <Accordion title="Right to Withdraw Consent" icon="circle-xmark">
    **Individuals can withdraw consent anytime**

    **Consent for:**

    * Newsletter subscription
    * Marketing emails
    * Data processing

    **Withdraw:**

    * Unsubscribe link
    * Preference center
    * Account deletion
  </Accordion>
</AccordionGroup>

### GDPR Features in Migma

**Built-in compliance tools:**

<Check>**Double opt-in** for EU subscribers (configurable)</Check>
<Check>**Consent timestamps** recorded and auditable</Check>
<Check>**Cookie consent** for tracking (where applicable)</Check>
<Check>**Privacy policy** link in all emails</Check>
<Check>**Data Processing Agreement** available for enterprise</Check>
<Check>**EU data residency** option (coming soon)</Check>

***

## CAN-SPAM Compliance (USA)

### What is CAN-SPAM?

**Controlling the Assault of Non-Solicited Pornography And Marketing Act** is US federal law regulating commercial email.

**Penalties:** Up to \$50,120 per violation

### CAN-SPAM Requirements

Migma helps you comply with all CAN-SPAM requirements:

<Steps>
  <Step title="Accurate Header Information">
    **Required:** From, To, and Reply-To must be accurate

    **Migma enforces:**

    * Verified sender domains
    * Accurate from names
    * Working reply-to addresses
    * No deceptive routing information
  </Step>

  <Step title="Non-Deceptive Subject Lines">
    **Required:** Subject must reflect email content

    **Examples:**

    * ✅ "25% Off Summer Sale - Ends Friday"
    * ❌ "Re: Your Order" (when there's no order)
    * ❌ "Urgent: Security Alert" (for marketing)

    **Migma's AI:** Helps generate accurate subjects
  </Step>

  <Step title="Identify as Advertisement">
    **Required for commercial emails**

    **Not always necessary if:**

    * Relationship exists
    * Content is transactional
    * Customer requested info

    **Migma includes:**

    * Optional "Advertisement" disclosure
    * Configurable per campaign type
  </Step>

  <Step title="Physical Postal Address">
    **Required:** Valid physical address in every email

    **Migma automatically includes:**

    ```
    Your Company Name
    123 Main Street, Suite 100
    San Francisco, CA 94105
    ```

    **Configure once:** Settings → Compliance → Business Address

    **Where it appears:**

    * Email footer
    * Preference center
    * Unsubscribe page
  </Step>

  <Step title="Clear Unsubscribe Mechanism">
    **Required:**

    * Conspicuous unsubscribe option
    * Works for 30 days after sending
    * No fee, login, or additional info required

    **Migma provides:**

    * ✅ One-click unsubscribe link
    * ✅ 30+ day link validity
    * ✅ No login required
    * ✅ Instant processing
    * ✅ Confirmation message

    **Automatically in every email footer**
  </Step>

  <Step title="Honor Opt-Out Requests">
    **Required:** Process unsubscribes within 10 business days

    **Migma processing:**

    * ⚡ **Instant:** Unsubscribes processed immediately
    * ✅ No emails sent after opt-out
    * 📝 Opt-out list maintained
    * 🔒 Cannot sell/transfer opt-out list
  </Step>

  <Step title="Monitor Third Parties">
    **Required:** Responsible for all email sent on your behalf

    **If using agencies/contractors:**

    * Ensure they comply with CAN-SPAM
    * Monitor their sending practices
    * You're liable for violations

    **Migma helps:**

    * User permission system
    * Audit logs of all sends
    * Agency access controls
  </Step>
</Steps>

### CAN-SPAM Compliance Checklist

Before sending marketing emails:

<Check>From address is accurate and yours</Check>
<Check>Subject line reflects email content</Check>
<Check>Physical address in footer</Check>
<Check>Clear unsubscribe link</Check>
<Check>Unsubscribe works immediately</Check>
<Check>No deceptive headers or routing</Check>

**Migma automatically handles most of these!**

***

## CASL Compliance (Canada)

### What is CASL?

**Canada's Anti-Spam Legislation** is stricter than CAN-SPAM.

**Key differences:**

* **Opt-in required** (vs opt-out in CAN-SPAM)
* **Express or implied consent** needed before sending
* **Penalties:** Up to \$10 million CAD per violation

### CASL Requirements

<Tabs>
  <Tab title="Consent">
    **Must have consent before sending**

    **Express consent:**

    * Explicit opt-in checkbox
    * Clear what they're consenting to
    * Valid for perpetuity (until withdrawn)

    **Implied consent (expires after 2 years):**

    * Existing business relationship
    * Inquiry or application within 6 months
    * Membership/volunteer relationship

    **Migma tracks:**

    * Consent date and source
    * Type of consent (express/implied)
    * Consent expiration (for implied)
  </Tab>

  <Tab title="Identification">
    **Must identify sender clearly**

    **Required in every email:**

    * Your name/business name
    * Physical mailing address
    * Contact information (phone, email, or web)

    **Migma includes:**

    * Company name in header/footer
    * Physical address
    * Contact info
  </Tab>

  <Tab title="Unsubscribe">
    **Must provide easy unsubscribe**

    **Requirements:**

    * Free
    * Functional for 60 days (vs 30 for CAN-SPAM)
    * Processed within 10 business days

    **Migma provides:**

    * One-click unsubscribe
    * 90-day link validity
    * Instant processing
  </Tab>
</Tabs>

### CASL Features in Migma

<Check>**Checkbox consent** tracking (express)</Check>
<Check>**Consent timestamps** and source</Check>
<Check>**Consent expiration** warnings (implied)</Check>
<Check>**Canadian compliance** mode toggle</Check>

***

## Other International Regulations

### EU ePrivacy (Cookie Law)

**Requires consent for cookies and tracking**

**Migma's tracking:**

* Email open tracking (pixel)
* Link click tracking
* Analytics cookies (website)

**Compliance:**

* Preference center includes tracking consent
* Can disable tracking per subscriber
* Cookie consent banner (for web)

### Australian Spam Act

**Similar to CAN-SPAM but requires:**

* Consent (opt-in)
* Clear unsubscribe
* Accurate sender info

**Migma supports:** All requirements via settings

### PECR (UK)

**Privacy and Electronic Communications Regulations**

**Requirements:**

* Consent for marketing emails
* Exceptions for existing customers
* Clear unsubscribe

**Migma compliance:** Same as GDPR + consent tracking

***

## Security Features

### Encryption

<AccordionGroup>
  <Accordion title="Data in Transit" icon="arrow-right-arrow-left">
    **All data encrypted during transmission:**

    ✅ **TLS 1.3** for all connections

    * API requests
    * Web interface
    * Email sending
    * Database connections

    ✅ **HTTPS enforced**

    * Automatic redirect from HTTP
    * HSTS headers
    * Perfect forward secrecy
  </Accordion>

  <Accordion title="Data at Rest" icon="database">
    **All data encrypted when stored:**

    ✅ **AES-256 encryption**

    * Database (MongoDB encrypted)
    * File storage (S3 encrypted)
    * Backups (encrypted at rest)

    ✅ **Key management**

    * Separate encryption keys per customer (enterprise)
    * Regular key rotation
    * Hardware security modules (HSMs)
  </Accordion>
</AccordionGroup>

### Authentication & Access Control

<Tabs>
  <Tab title="User Authentication">
    **Secure login:**

    ✅ **Password requirements**

    * Minimum 12 characters
    * Complexity requirements
    * No common passwords
    * Password hashing (bcrypt)

    ✅ **Multi-factor authentication (MFA)**

    * TOTP authenticator apps
    * SMS backup codes
    * Enforce for all users (enterprise)

    ✅ **Session management**

    * Secure session tokens
    * Automatic timeout
    * Device tracking
  </Tab>

  <Tab title="Role-Based Access">
    **Team permissions:**

    **Roles:**

    * **Owner:** Full access
    * **Admin:** Most features
    * **Editor:** Create/edit emails
    * **Viewer:** Read-only

    **Permissions:**

    * Granular control per feature
    * Audit log of all actions
    * Can't escalate own permissions
  </Tab>

  <Tab title="API Security">
    **Secure API access:**

    ✅ **API keys**

    * Unique per project
    * Scoped permissions
    * Rotatable
    * Revocable

    ✅ **Rate limiting**

    * Prevent abuse
    * DDoS protection
    * Per-key limits

    ✅ **IP allowlisting** (enterprise)

    * Restrict API access by IP
    * Multiple IPs supported
  </Tab>
</Tabs>

### Infrastructure Security

<Check>**SOC 2 Type II audited infrastructure**</Check>
<Check>**Regular penetration testing** (quarterly)</Check>
<Check>**Vulnerability scanning** (continuous)</Check>
<Check>**DDoS protection** (Cloudflare)</Check>
<Check>**WAF (Web Application Firewall)**</Check>
<Check>**Intrusion detection** (automated)</Check>

### Application Security

<Check>**Input validation** on all user input</Check>
<Check>**XSS protection** (content sanitization)</Check>
<Check>**CSRF tokens** on all forms</Check>
<Check>**SQL injection prevention** (parameterized queries)</Check>
<Check>**Dependency scanning** (automated updates)</Check>
<Check>**Code review** before deployment</Check>

***

## Privacy Features

### Data Processing Agreement (DPA)

**For GDPR compliance:**

Enterprise customers receive a DPA covering:

* Scope of processing
* Data protection obligations
* Sub-processors
* Data subject rights
* Security measures
* Breach notification

**Request DPA:** [enterprise@migma.ai](mailto:enterprise@migma.ai)

### Subprocessors

**Third-party services Migma uses:**

| Service       | Purpose                  | Location |
| ------------- | ------------------------ | -------- |
| AWS           | Hosting & infrastructure | USA      |
| MongoDB Atlas | Database                 | USA      |
| Anthropic     | AI models                | USA      |
| Stripe        | Payment processing       | USA      |
| Cloudflare    | CDN & security           | Global   |

**Enterprise customers:** Can request dedicated infrastructure or data residency options.

### Data Residency

**Current:** Data stored in US (AWS us-east-1)

**Coming soon:**

* ✅ EU data residency option
* ✅ UK data residency option
* ✅ Customer-specified regions (enterprise)

***

## Incident Response

### Security Incident Process

<Steps>
  <Step title="Detection">
    **Automated monitoring:**

    * Intrusion detection
    * Anomaly detection
    * Alert systems
  </Step>

  <Step title="Assessment">
    **Within 1 hour:**

    * Classify severity
    * Identify scope
    * Determine impact
  </Step>

  <Step title="Containment">
    **Immediate actions:**

    * Isolate affected systems
    * Block malicious activity
    * Prevent spread
  </Step>

  <Step title="Notification">
    **If personal data affected:**

    * Customers notified within 72 hours
    * Authorities notified (if required)
    * Transparent communication
  </Step>

  <Step title="Remediation">
    **Fix and recover:**

    * Patch vulnerabilities
    * Restore from backups
    * Enhanced monitoring
  </Step>

  <Step title="Post-Incident">
    **Learn and improve:**

    * Root cause analysis
    * Update procedures
    * Additional safeguards
  </Step>
</Steps>

### Breach Notification

**If your data is compromised:**

* Email notification within 72 hours
* Details of what happened
* Data affected
* Steps taken
* Your recommended actions

**GDPR requirement:** 72-hour notification to authorities

***

## Audit & Logging

### Audit Logs

**Migma logs all significant actions:**

<Check>User logins and logouts</Check>
<Check>Email creation and edits</Check>
<Check>Email sends</Check>
<Check>Subscriber additions/deletions</Check>
<Check>Setting changes</Check>
<Check>Team member actions</Check>
<Check>API calls</Check>

**Retention:** 1 year (enterprise: 7 years)

**Access:** Settings → Audit Logs

### Compliance Reporting

**Enterprise features:**

* Downloadable compliance reports
* Activity summaries
* User access reports
* Data processing records

***

## Best Practices

<AccordionGroup>
  <Accordion title="Use Double Opt-In (EU)" icon="envelope-circle-check">
    **For GDPR compliance:**

    1. User signs up
    2. Confirmation email sent
    3. User clicks confirm link
    4. Subscription activated

    **Migma setting:**
    Settings → Compliance → Double Opt-In: ON
  </Accordion>

  <Accordion title="Keep Records" icon="file-lines">
    **Document everything:**

    * When consent obtained
    * How consent obtained
    * What they consented to
    * IP address (optional)
    * Timestamp

    **Migma tracks automatically**
  </Accordion>

  <Accordion title="Regular Compliance Review" icon="calendar-check">
    **Quarterly checklist:**

    * Review privacy policy (still accurate?)
    * Check unsubscribe links (working?)
    * Verify physical address (current?)
    * Test preference center (functional?)
    * Review retained data (still needed?)
  </Accordion>

  <Accordion title="Train Your Team" icon="chalkboard-user">
    **Ensure team knows:**

    * Privacy requirements
    * How to handle data requests
    * What not to do with subscriber data
    * Breach reporting procedures
  </Accordion>
</AccordionGroup>

***

## Intellectual Property & Prohibited Uses

### Protection of Proprietary Systems

**Migma's proprietary technology is protected by intellectual property laws.**

<Warning>
  **Strictly Prohibited Activities:**

  The following actions are expressly forbidden and constitute violations of our Terms of Service:

  * ❌ **Extracting, copying, or reverse-engineering** our AI model instructions, prompts, or system configurations
  * ❌ **Scraping, harvesting, or systematically collecting** emails, templates, or content from the platform
  * ❌ **Reproducing or redistributing** our proprietary algorithms, workflows, or technical implementations
  * ❌ **Using extracted content for commercial purposes** including training competing AI models
  * ❌ **Sharing, selling, or licensing** any proprietary Migma technology or content to third parties
  * ❌ **Automated data extraction** via bots, scrapers, or unauthorized API usage
</Warning>

### Intellectual Property Rights

**What Migma owns:**

<AccordionGroup>
  <Accordion title="Proprietary Technology" icon="microchip">
    **Protected intellectual property includes:**

    ✅ **AI model instructions and prompts**

    * System prompts and configurations
    * Model fine-tuning and training data
    * Prompt engineering techniques
    * AI workflow architectures

    ✅ **Platform technology**

    * Source code and algorithms
    * Database schemas and structures
    * API implementations
    * User interface designs

    ✅ **Proprietary methodologies**

    * Email generation processes
    * Image-to-email conversion algorithms
    * Figma import technology
    * Content optimization systems

    **Legal protection:** Copyright, trade secret, and patent laws
  </Accordion>

  <Accordion title="User-Generated Content" icon="user-pen">
    **Your content ownership:**

    ✅ **You retain ownership of:**

    * Your email content and copy
    * Your uploaded images and assets
    * Your subscriber lists and data
    * Your brand materials

    ✅ **License you grant Migma:**

    * Limited license to process and display your content
    * Only for providing the service to you
    * Revocable upon account deletion
    * Non-transferable to third parties

    ✅ **What we don't do:**

    * Claim ownership of your content
    * Use your content for other customers
    * Sell or license your content
    * Train models on your private content (without consent)
  </Accordion>

  <Accordion title="Platform-Generated Content" icon="wand-magic-sparkles">
    **AI-generated content rights:**

    **Content created by Migma's AI:**

    * You receive a license to use commercially
    * Migma retains underlying technology rights
    * You cannot extract or reverse-engineer the generation process
    * You cannot claim the AI system as your own

    **Example:**

    * ✅ Use AI-generated email in your campaigns
    * ✅ Modify and customize AI output
    * ❌ Extract prompts used to generate content
    * ❌ Replicate our AI generation system
  </Accordion>
</AccordionGroup>

### Enforcement & Violations

**We actively monitor for violations:**

<Steps>
  <Step title="Detection">
    **Automated monitoring for:**

    * Unusual API usage patterns
    * Systematic data extraction attempts
    * Unauthorized access to system internals
    * Suspicious account activity
  </Step>

  <Step title="Investigation">
    **Upon detection:**

    * Account flagged for review
    * Activity logs analyzed
    * Scope of violation assessed
    * Evidence documented
  </Step>

  <Step title="Enforcement Actions">
    **Depending on severity:**

    **Minor violations:**

    * Warning notification
    * Temporary access restrictions
    * Mandatory compliance review

    **Serious violations:**

    * Immediate account suspension
    * Permanent account termination
    * Legal action for damages
    * Criminal referral (if applicable)
  </Step>

  <Step title="Legal Remedies">
    **We reserve the right to:**

    * Seek injunctive relief
    * Pursue monetary damages
    * Report to law enforcement
    * Pursue criminal charges for theft of trade secrets
  </Step>
</Steps>

### Penalties for Violations

<Warning>
  **Legal consequences may include:**

  💰 **Financial penalties:**

  * Statutory damages up to \$150,000 per work (copyright)
  * Actual damages plus profits from misuse
  * Attorney fees and court costs
  * Punitive damages for willful violations

  ⚖️ **Civil liability:**

  * Breach of contract claims
  * Misappropriation of trade secrets
  * Unfair competition
  * Tortious interference

  🚨 **Criminal liability:**

  * Trade secret theft (up to 10 years imprisonment)
  * Computer fraud and abuse
  * Wire fraud
  * Copyright infringement
</Warning>

### Acceptable Use Policy

**What you CAN do:**

<Check>Use Migma to create and send your email campaigns</Check>
<Check>Export your own subscriber data and content</Check>
<Check>Integrate via official API with proper authentication</Check>
<Check>Share publicly available documentation and guides</Check>
<Check>Provide feedback and feature suggestions</Check>
<Check>Use AI-generated content in your business</Check>

**What you CANNOT do:**

<Check>❌ Reverse-engineer our AI models or prompts</Check>
<Check>❌ Scrape or systematically download platform content</Check>
<Check>❌ Share or resell access to Migma technology</Check>
<Check>❌ Use extracted data to build competing products</Check>
<Check>❌ Circumvent security or access controls</Check>
<Check>❌ Violate rate limits or terms of service</Check>

### Reporting Violations

**If you discover misuse of Migma's intellectual property:**

<Card title="Report IP Violations" icon="shield-exclamation" href="mailto:legal@migma.ai">
  **Email:** [legal@migma.ai](mailto:legal@migma.ai)

  **Include:**

  * Description of the violation
  * Evidence (URLs, screenshots, etc.)
  * Your contact information
  * Date and time of discovery

  **We investigate all reports within 48 hours**
</Card>

### Third-Party Compliance

**If you're building integrations or using our API:**

<AccordionGroup>
  <Accordion title="API Usage Requirements" icon="plug">
    **Authorized API use only:**

    ✅ **Required:**

    * Valid API key with proper scopes
    * Respect rate limits
    * Follow API documentation
    * Proper attribution where required

    ❌ **Prohibited:**

    * Sharing API keys
    * Exceeding rate limits
    * Undocumented API endpoints
    * Automated account creation
  </Accordion>

  <Accordion title="Integration Guidelines" icon="diagram-project">
    **Building on Migma:**

    ✅ **Allowed:**

    * Official API integrations
    * Zapier/Make.com workflows
    * Custom internal tools
    * Documented webhook usage

    ❌ **Not allowed:**

    * Screen scraping
    * Unofficial API access
    * Bypassing authentication
    * Extracting proprietary logic
  </Accordion>

  <Accordion title="Reseller/Agency Rules" icon="handshake">
    **If you're an agency or reseller:**

    ✅ **You may:**

    * Manage client accounts (with permission)
    * Create campaigns for clients
    * Provide training and support
    * Charge for your services

    ❌ **You may not:**

    * Resell Migma access without authorization
    * White-label Migma as your own product
    * Share proprietary Migma technology
    * Claim ownership of Migma features
  </Accordion>
</AccordionGroup>

### Data Protection for Proprietary Content

**How we protect our intellectual property:**

<Tabs>
  <Tab title="Technical Measures">
    **Security controls:**

    * 🔒 Encrypted system prompts and configurations
    * 🔐 Access controls on proprietary code
    * 🛡️ Rate limiting and abuse detection
    * 📊 Monitoring and anomaly detection
    * 🚫 Obfuscation of sensitive algorithms
  </Tab>

  <Tab title="Legal Measures">
    **Legal protections:**

    * 📄 Terms of Service enforcement
    * 🔏 Non-disclosure agreements
    * ⚖️ Copyright and trademark registration
    * 🏛️ Trade secret protection
    * 📋 Patent applications (where applicable)
  </Tab>

  <Tab title="Contractual Measures">
    **Agreement requirements:**

    * ✍️ Acceptance of Terms of Service
    * 🤝 API usage agreements
    * 🔒 Confidentiality obligations
    * ⚠️ Violation consequences
    * 📜 Dispute resolution procedures
  </Tab>
</Tabs>

### Educational Use & Research

**Academic and research exceptions:**

<Info>
  **Limited exceptions for:**

  ✅ **Academic research:**

  * Must be non-commercial
  * Requires prior written approval
  * Proper attribution required
  * Results may be published with permission

  ✅ **Educational purposes:**

  * Classroom demonstrations (with license)
  * Student projects (non-commercial)
  * Training materials (authorized only)

  **Contact:** [research@migma.ai](mailto:research@migma.ai) for approval
</Info>

***

## Need Help?

<CardGroup cols={2}>
  <Card title="Privacy Policy" icon="file-contract" href="https://migma.ai/privacy">
    Read our privacy policy
  </Card>

  <Card title="Terms of Service" icon="handshake" href="https://migma.ai/terms">
    Review terms of service
  </Card>

  <Card title="Contact Privacy Team" icon="envelope" href="mailto:privacy@migma.ai">
    [privacy@migma.ai](mailto:privacy@migma.ai)
  </Card>

  <Card title="Enterprise Security" icon="building" href="mailto:enterprise@migma.ai">
    Get SOC 2 report
  </Card>
</CardGroup>
