Security Policy

Micro Aegis International Technologies LLC (MAIT) Last Updated: July 2026

1. Our Commitment to Security

Micro Aegis International Technologies LLC (“MAIT,” “we,” “our,” or “us”) is a UAE-based technology company headquartered in Abu Dhabi, providing smart, scalable, and secure IT solutions to businesses across Dubai, Abu Dhabi, Sharjah, and the wider UAE — with delivery operations extending to Pakistan and Australia.

Our service portfolio spans custom app development, web design and development, search engine optimization, POS software, virtual reality solutions, application performance monitoring (APM) as an authorized eG Innovations partner, AI-powered platforms as an authorized Connectnow.ai distributor, enterprise systems including award management, event management, learning management, and exam software, and the full suite of Real Variable industry platforms (Real Collab, Real Traceability, Real Demand, Real Warranty, Real Green).

Given the breadth of systems we build, deploy, and manage on behalf of our clients, security is not an afterthought — it is a fundamental part of how we operate. This Security Policy describes the technical and organizational measures we apply to protect our website, client data, internal systems, and the platforms we develop and maintain.

This policy applies to our corporate website (mait.ae), all client-facing project portals, our internal systems and tools, our employees, contractors, and overseas delivery partners, and any third-party vendors who process data on our behalf.

2. Data We Collect and Protect

In the course of delivering our IT services and managing client engagements, MAIT may collect and process the following categories of data:

  • Business contact and account information (name, company name, email, phone number)
  • Project briefs, technical specifications, and deliverable materials shared by clients
  • Inquiry and lead data submitted through our website contact form
  • Billing, invoicing, and payment records for services rendered
  • Website visitor and analytics data (page views, session data, referral sources)
  • Communications exchanged via email and business messaging channels
  • Employee and contractor records for internal HR and project management purposes
  • Access credentials for client systems managed or supported by MAIT’s delivery teams

We collect only the information necessary to deliver our services, fulfill contractual obligations, and maintain business operations. We do not sell client or contact data to third parties.

3. Data Protection Measures

  • Encryption in Transit: All data exchanged between users and mait.ae is encrypted using industry-standard TLS/SSL protocols. Communications involving client system credentials, project specifications, and sensitive engagement details are handled over encrypted channels.
  • Encryption at Rest: Sensitive data stored within our internal systems and client project environments is protected using encryption at rest where technically applicable.
  • Access Controls: Access to client data, project repositories, and internal records is restricted to authorized MAIT personnel on a strict need-to-know basis, governed by role-based access controls aligned to project responsibilities.
  • Password & Authentication Policies: All MAIT team members are required to use strong, unique passwords for internal and client-facing systems. Multi-factor authentication is enforced on critical tools including code repositories, project management platforms, server control panels, and cloud environments.
  • Device & Endpoint Security: Personnel accessing client environments are required to maintain up-to-date operating systems and endpoint security on their devices.
  • Regular Backups: Project files, databases, and business-critical records are backed up on a regular schedule to secure, redundant locations to protect against data loss and support business continuity.

4. Infrastructure & Application Security

As a software development company, we apply secure development practices internally and recommend them to clients across every platform we build:

  • Our servers and hosting environments are protected by firewalls and monitored for unauthorized access attempts and anomalous activity.
  • Server infrastructure, web server components, CMS installations, plugins, and third-party libraries are kept up to date with the latest security patches to address known vulnerabilities.
  • Web applications developed by MAIT follow secure coding guidelines, including input validation, output encoding, parameterized queries to prevent SQL injection, and protection against Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).
  • API integrations — including those developed for POS software, LMS platforms, exam systems, and AI services — use token-based authentication with credentials stored securely and rotated periodically.
  • New features and application modules undergo internal quality assurance and security review before client delivery.
  • We employ safeguards against Distributed Denial of Service (DDoS) attacks and other common web-based threats across our hosted platforms.
  • Database credentials, API keys, and integration secrets are managed separately from application source code and are never committed to public repositories.

5. Access Control & Privileged Access

  • Access to client systems — including server environments, CMS backends, and cloud infrastructure managed by MAIT on behalf of clients — is limited to the specific team members assigned to that engagement.
  • Remote access to client environments is conducted over secure, authenticated connections.
  • Upon project completion or team change, access credentials for client environments are reviewed and rotated as appropriate.
  • MAIT’s overseas delivery team (Lahore, Pakistan) operates under the same access control policies and security standards as the UAE headquarters.
  • Administrative access to MAIT’s own infrastructure is limited to designated senior personnel and governed by the principle of least privilege.

6. APM & Performance Monitoring Security

As an authorized eG Innovations partner delivering Application Performance Monitoring (APM) services, MAIT implements and manages monitoring solutions across client IT infrastructures. In this capacity:

  • Monitoring agents and data collectors are deployed with minimal necessary permissions scoped to performance metrics only.
  • Performance data collected through eG Innovations platforms is handled in accordance with both eG Innovations’ own data handling policies and MAIT’s confidentiality obligations to the client.
  • Access to monitoring dashboards is configured with role-based access so that only authorized client personnel and MAIT support engineers can view infrastructure telemetry.
  • No client infrastructure data collected through APM engagements is shared with third parties outside the scope of the service engagement.

7. AI Services & Connectnow.ai Security

As an authorized distributor of Connectnow.ai and provider of AI-powered workflow automation through 3Aflow, MAIT handles deployments that may involve business process data, document content, and conversational data. In these engagements:

  • AI platform deployments are configured to minimize the retention of sensitive business data within AI processing pipelines wherever possible.
  • Client data processed through AI services is not used to train third-party AI models without explicit client consent.
  • All AI service integrations are delivered with clear documentation of data flows so clients understand exactly what data each component handles.

8. Client Project Confidentiality

MAIT routinely receives sensitive business information as part of client engagements, including business strategies, product plans, financial data, proprietary source code, and internal process documentation. We treat all client project materials as confidential by default. Non-Disclosure Agreements (NDAs) are available and can be executed prior to project commencement upon client request.

9. Incident Response

In the event of a suspected or confirmed security incident affecting client data or MAIT’s internal systems, we will:

  1. Promptly identify, investigate, and contain the incident.
  2. Assess the nature, scope, and potential impact of any data exposure or unauthorized access.
  3. Notify affected clients without undue delay, along with guidance on any immediate protective steps they should take.
  4. Cooperate fully with relevant UAE authorities as required by applicable law.
  5. Conduct a post-incident review and implement corrective measures to prevent recurrence.
  6. Maintain an internal record of the incident, response actions taken, and lessons learned.

10. Third-Party & Vendor Security

MAIT works with select third-party technology providers — including cloud hosting providers, domain and email services, payment processors, software development tools, and authorized technology partners (eG Innovations, Real Variable, Connectnow.ai) — to deliver our services. We:

  • Evaluate third-party providers for appropriate security practices before engaging them in any capacity that involves client or company data.
  • Share only the minimum data necessary for each provider to perform their function.
  • Do not authorize third-party vendors to use client or contact data for their own marketing or commercial purposes.
  • Review third-party relationships periodically to confirm they remain appropriate.

11. Vulnerability Disclosure

We welcome responsible security disclosures from clients, partners, and the broader security research community. If you believe you have identified a vulnerability in mait.ae or any system managed or operated by MAIT, please contact us at:

Email: security@mait.ae

Please include a description of the issue, the affected URL or system component, and steps to reproduce it where possible. We kindly ask that you refrain from publicly disclosing any vulnerability until we have had a reasonable opportunity to investigate and address it. We are committed to acknowledging valid reports promptly and resolving confirmed issues in good faith.

12. Employee & Contractor Responsibilities

All MAIT team members — including full-time employees, part-time contractors, and overseas delivery staff — are required to:

  • Handle client data and project materials with strict confidentiality at all times.
  • Use secure, approved channels for all client and inter-team communications.
  • Adhere to MAIT’s password, authentication, and device security requirements.
  • Report any suspected security incident, data breach, or policy violation immediately to MAIT management.
  • Complete security awareness orientation as part of their onboarding process.

13. Compliance

MAIT operates in accordance with applicable UAE data protection regulations, including the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL). We strive to align our data handling and security practices with recognized international frameworks, including ISO 27001 information security principles, which inform the way we design and deliver secure software and IT infrastructure for our clients.

Where MAIT delivers services to clients operating under specific regulatory frameworks — such as PCI-DSS for payment systems, healthcare IT regulations, or UAE NCEMA requirements for critical infrastructure — our development and delivery teams take those requirements into account throughout the project lifecycle.

This policy does not constitute legal advice and does not represent a guarantee of specific regulatory certification. Clients with specific compliance requirements should consult their own legal or compliance advisors regarding their use of MAIT’s services.

14. Policy Updates

We may update this Security Policy periodically to reflect changes in our services, practices, technology, or applicable legal requirements. The “Last Updated” date at the top of this page reflects the most recent revision. We encourage clients and website visitors to review this page from time to time. For material changes affecting active client engagements, we will make reasonable efforts to communicate updates directly.

15. Contact Us

If you have questions, concerns, or requests related to this Security Policy or MAIT’s data security practices, please reach out to us:

Micro Aegis International Technologies LLC (MAIT) Address: 16 Al Isayfir 2 St, Musaffah – M33, Abu Dhabi, UAE Phone: +971 58 897 9925 Email: info@mait.ae Website: https://mait.ae

Scroll to Top