Our security approach
Migo is designed to handle identity, professional and mobility information with care. Our security programme uses layered technical and organisational controls proportionate to the sensitivity of the service and the risks involved.
This page describes our approach without disclosing information that could weaken security. It does not claim a certification unless Migo explicitly identifies a current certification.
Platform and access controls
- encrypted network connections for supported web and API traffic;
- role-based access and least-privilege controls for authorised personnel;
- separation between customer experiences and internal operations tools;
- authentication, session protection and security monitoring;
- audit records for sensitive actions and human interventions;
- backups, recovery planning and controlled software change processes; and
- regular dependency, configuration and vulnerability review.
AI and human oversight
AI components are limited to the information and tools needed for an authorised task. Important submissions, permissions and credit actions are designed to require explicit approval or authorised review. Internal operators have role-based access, and their interventions are logged.
We review providers and configurations used for AI processing and limit retention or secondary use where our contracts and technical options allow.
Suppliers and incident response
Migo relies on specialist infrastructure, communications, payment and AI providers. We assess relevant security and privacy practices, limit access to what is needed, and use contractual safeguards appropriate to the service.
We maintain processes to investigate, contain and recover from security incidents. If an incident creates a legal notification obligation, we will notify affected people and regulators within the applicable period.
How you can protect your account
- Use a unique password and enable additional verification when available.
- Never share verification codes or approve an action you do not understand.
- Check the destination and recipient before approving document sharing.
- Keep your email account, phone and device secure.
- Tell us promptly if you see an unfamiliar session, message or transaction.
Report a security concern
If you believe you found a vulnerability or security incident, do not access more information than needed to demonstrate it. Do not disrupt the service, use social engineering or publish sensitive details before we have had a reasonable opportunity to investigate.
