Access by firm and role
Access to protected records requires sign-in and permission for the firm or company. Application checks and database policies separate covered customer records.
Security
Access controls for company data. Approval requirements for governed execution. Clear terms for how data is processed.
Access and execution
Access to protected records requires sign-in and permission for the firm or company. Application checks and database policies separate covered customer records.
Agent notes stay with the company or target within the firm. Authorized reviewers can review or retract notes. Notes do not grant access or execution approval.
Your team reviews the proposed change and authorizes governed execution. Approval and run records remain available for review. These controls apply to supported migration paths.
Data is encrypted in transit and at rest through our infrastructure providers. Customer-supplied model credentials use protected secret storage.
AI data handling
Agent workflows send prompts and relevant context to the configured provider and receive model outputs.
MigrateForce does not use customer content to train foundation models. Provider data use and retention depend on the service and contract.
Configured workflows send prompts and relevant tool context to Anthropic and receive model outputs. Anthropic does not use commercial inputs or outputs for training by default. Explicit feedback or data-sharing permissions can change that treatment.
Anthropic data policyGoogle processes prompts and responses when a Gemini model is configured. Under Gemini API paid-service terms, this content is not used to improve Google products. Unpaid-service terms differ. Provider logging and retention still apply.
Gemini API data termsOpenAI processes prompts, relevant context, and responses when configured. API data is not used to train models unless you opt in. Abuse-monitoring logs and some API features can retain data under the provider’s data controls.
OpenAI data controlsWhen a supported customer-hosted endpoint is configured, inference requests go to that endpoint. Its operator’s contract and settings determine model-side logging, retention, and training. MigrateForce’s service data remains subject to our data agreement.
Using your own API key does not change the provider’s data terms.
Service providers
These subprocessors are listed in our Data Processing Agreement. Optional services process data when used.
Read the agreement| Provider | Purpose |
|---|---|
| Supabase Inc. | Database hosting and authentication |
| Google LLC | Cloud infrastructure and configured AI services |
| Resend Inc. | Transactional email |
| Anthropic PBC | AI processing for configured agents |
| OpenAI, L.L.C. | AI processing when configured |
| Stripe, Inc. | Payment processing when paid services are used |
Subprocessor changes follow the notice process in the data agreement.
Retention and requests
We retain data as needed to provide the service and meet legal, security, and operational requirements. Retention varies by data category, backup cycle, and agreement.
Request access, correction, or deletion through our privacy contact. Legal retention requirements may apply.
privacy@sociallabs.comWe notify affected customers without undue delay after confirming a breach affecting personal data, subject to applicable law and the executed agreement.