Migratrix for security and compliance · Migratrix
Sign in
For security and compliance

The database tier should have the same story as the app tier

Named people, environment-scoped roles, approvals that bind to the SQL that ran, and an audit log you can verify rather than export from chat. Database passwords never land in the Migratrix cloud. We do not claim SOC 2 on this site.

What to put in the questionnaire

Question Answer in the product
Where are database passwords? Encrypted on the Executor host. Not stored on the control plane. Data handling.
Do customer rows hit your cloud? No. Operational metadata only. Transient results discarded after processing.
Separation of duties? Author, approver, and executor are distinct roles on an environment. Production write is not a global workspace permission.
Can we verify the audit log? Hash chain plus Merkle seals. There is no one-click export in the UI today. Audit.
SOC 2 / ISO? Not claimed here. DPA on request. Compliance.
Assistant access? MCP mutating tools require confirm:true. Token is the user's access token.