Safety & accessibility
TITLE IV – ACCESSIBILITY & SECURITY
Last updated: September 18
DIGITAL ACCESSIBILITY
The goal is to provide a user experience accessible to the widest possible audience and takes WCAG Level AA as its improvement objective. The platform includes, in particular, a controlled heading structure, keyboard navigation on the tested paths, measured contrast, form labels, error messages, layouts adapted for small screens, and support for Arabic reading direction.
This approach does not constitute a full statement of conformance or the result of an independent certification audit. Third-party documents, video content, complex tables, imported files, or external functions may present limitations. No exhaustive testing with all screen readers on the market is claimed.
A problem can be reported to contact@mijaygroup.com with "Accessibility" in the subject line. Mijay Group will seek a reasonable alternative solution or format based on the content and available resources.
2. TECHNICAL AND ORGANIZATIONAL MEASURES
The implemented and verifiable measures include, but are not limited to:
- HTTPS communications and HSTS headers in production;
- Security headers against certain risks related to content loading, integration, and interpretation, including a Content Security Policy;
- Server validation, CSRF protection, output escaping, and hashed passwords;
- Access controls based on role, permission, project, folder, and conversation;
- Two-factor authentication required for administrators;
- Retrieval limiting and anti-bot control when configured;
- Secure sessions and cookies in the production environment;
- Private storage of sensitive documents and signed temporary links for certain shares;
- Logging of administrative operations and certain sensitive events;
- Automated backups, integrity checks, and backups prior to deployment;
- Automated testing of permissions, restricted access, dependencies, builds, and migrations.
Some antivirus analysis, OCR, conversion, and detection functions rely on a third-party provider and only run if the necessary configuration is enabled. A file accepted by the platform should never be considered inherently secure.
3. USER ACCOUNTS
Each user must use a unique password, protect their authentication methods, not share their account, verify authorized individuals in their projects, and promptly report any suspicious activity. Mijay Group can impose a reset, suspend access, or request verification when a risk is detected.
4. PAYMENTS
Card payments offered by the platform are processed through Stripe. Full card details are not stored by Mijay Group. Additional checks, authentication, and potential refusals depend on Stripe, the bank, the country, and the transaction's risk level.
5. FILES, MESSAGES, AND AI
Files are subject to size, type, and visibility limits. They may be rejected, isolated, analyzed, or converted. Participants must not post unnecessary secrets, malicious code, illegal data, or information they are not authorized to share.
The messaging system uses segregation rules and an anti-circumvention filter. Translations and responses from the AI assistant are automated, may contain errors, and must be validated by a human before any decision is made.
6. INCIDENT MANAGEMENT
Mijay Group analyzes reported or detected incidents, mitigates their impact, retains relevant information, and takes appropriate corrective action. The relevant authorities and individuals are notified when required by applicable law and within the timeframe stipulated by that law.
An incident or vulnerability can be reported to contact@mijaygroup.com with "Security" in the subject line. The report must describe the problem without further exploiting the system, accessing others' data, disrupting the service, or making the vulnerability public before Mijay Group has had the opportunity to investigate it.
7. PROHIBITED USE
In particular, it is prohibited to attempt unauthorized access, circumvent permissions, scan or attack the service without written authorization, introduce malicious code, collect others' data, impersonate someone else, transmit illegal content, commit fraud, circumvent applicable sanctions, or use the platform to infringe upon the rights of a third party.
Mijay Group may suspend or restrict access to protect individuals, data, the platform, or its legal obligations, without prejudice to any other available remedies.
8. CONTINUITY AND AVAILABILITY
Mijay Group implements backups, production controls, and deployment procedures designed to reduce the risk of downtime. However, dependencies on the hosting provider, network, payment services, carriers, and other external providers may affect availability.
No publicly available target, recovery time, maximum data loss, or automatic compensation is promised on this page. An SLA, RTO, RPO, or compensation is contractually binding only if expressly stated in a written agreement signed with the relevant customer.
9. COMPLIANCE, FRAUD, AND PENALTIES
Mijay Group may conduct proportionate checks on the identity, company, origin of a transaction, product, or payment when justified by law, a service provider, an authority, or the level of risk. A transaction may be refused or suspended if it appears to be illegal, fraudulent, counterfeit, prohibited, or incompatible with a service provider's rules.
This right does not imply that Mijay Group is a regulated financial institution, nor that the same procedure applies to every client.
10. APPLICABLE LAW AND HIERARCHY
This information is governed by the laws of Hong Kong. The versioned General Terms and Conditions and the accepted specific terms and conditions determine the contractual obligations. In case of conflict, a signed contractual document and the applicable mandatory rules shall prevail over this general presentation.
11. CONTACTS
General contact, data, accessibility, security and intellectual property: contact@mijaygroup.com
Address: Room 2502C, 25/F, 148 Electric Road, North Point, Hong Kong
Document updated on 19 September 2026.