Compliance and disclosure · Migratrix
Sign in
Trust center

Compliance, without inventing a certificate

A DPA is available on request. Customer-side logging, access control, and data handling are designed so you can map the product into frameworks you already run. This page does not claim a specific SOC 2 or ISO attestation.

Paper you can actually request

Item How to get it
Data processing agreement legal@migratrix.com
Terms /terms
Privacy policy /privacy
Vulnerability report Email security@migratrix.com with details and reproduction steps. Do not attach customer data.

What you configure versus what we operate

Access

SSO, MFA through your identity provider, and per-environment RBAC. You decide who may approve production and who may only read.

Evidence

The audit ledger records approvals, executions, queries, and integrity seals. Export of a signed bulk dump is not a one-click UI feature yet.

Data residency of contents

Database contents never leave the Executor host as a retained copy. Control-plane metadata is hosted on reputable cloud providers with certified data centers.

Subprocessors

Select third-party providers for cloud hosting, email, payments, and OpenAI for NL SQL. A named current list is provided during security review. See subprocessors.

How we look for our own holes

Continuous scanning

Dependency, code, and container scans, with high and critical issues remediated first.

Penetration testing

Periodic third-party testing, with findings tracked to closure.

Legal and privacy