A DPA is available on request. Customer-side logging, access control, and data handling are designed so you can map the product into frameworks you already run. This page does not claim a specific SOC 2 or ISO attestation.
| Item | How to get it |
|---|---|
| Data processing agreement | legal@migratrix.com |
| Terms | /terms |
| Privacy policy | /privacy |
| Vulnerability report | Email security@migratrix.com with details and reproduction steps. Do not attach customer data. |
SSO, MFA through your identity provider, and per-environment RBAC. You decide who may approve production and who may only read.
The audit ledger records approvals, executions, queries, and integrity seals. Export of a signed bulk dump is not a one-click UI feature yet.
Database contents never leave the Executor host as a retained copy. Control-plane metadata is hosted on reputable cloud providers with certified data centers.
Select third-party providers for cloud hosting, email, payments, and OpenAI for NL SQL. A named current list is provided during security review. See subprocessors.
Dependency, code, and container scans, with high and critical issues remediated first.
Periodic third-party testing, with findings tracked to closure.