Skip to content

Security

How we protect
your data.

Access controls for company data. Approval requirements for governed execution. Clear terms for how data is processed.

Access and execution

Who can see data.
Who can change systems.

01

Access by firm and role

Access to protected records requires sign-in and permission for the firm or company. Application checks and database policies separate covered customer records.

02

Company-scoped memory

Agent notes stay with the company or target within the firm. Authorized reviewers can review or retract notes. Notes do not grant access or execution approval.

03

Approval for governed changes

Your team reviews the proposed change and authorizes governed execution. Approval and run records remain available for review. These controls apply to supported migration paths.

04

Encryption and credentials

Data is encrypted in transit and at rest through our infrastructure providers. Customer-supplied model credentials use protected secret storage.

AI data handling

What goes to a model provider.

Agent workflows send prompts and relevant context to the configured provider and receive model outputs.

MigrateForce does not use customer content to train foundation models. Provider data use and retention depend on the service and contract.

AnthropicCommercial API: no model training by default

Configured workflows send prompts and relevant tool context to Anthropic and receive model outputs. Anthropic does not use commercial inputs or outputs for training by default. Explicit feedback or data-sharing permissions can change that treatment.

Anthropic data policy
Google / GeminiData use depends on the service tier

Google processes prompts and responses when a Gemini model is configured. Under Gemini API paid-service terms, this content is not used to improve Google products. Unpaid-service terms differ. Provider logging and retention still apply.

Gemini API data terms
OpenAIAPI: no model training unless you opt in

OpenAI processes prompts, relevant context, and responses when configured. API data is not used to train models unless you opt in. Abuse-monitoring logs and some API features can retain data under the provider’s data controls.

OpenAI data controls
Customer-hosted modelsYour endpoint and hosting agreement

When a supported customer-hosted endpoint is configured, inference requests go to that endpoint. Its operator’s contract and settings determine model-side logging, retention, and training. MigrateForce’s service data remains subject to our data agreement.

Using your own API key does not change the provider’s data terms.

Service providers

Who processes data.

These subprocessors are listed in our Data Processing Agreement. Optional services process data when used.

Read the agreement
MigrateForce subprocessors and their roles
ProviderPurpose
Supabase Inc.Database hosting and authentication
Google LLCCloud infrastructure and configured AI services
Resend Inc.Transactional email
Anthropic PBCAI processing for configured agents
OpenAI, L.L.C.AI processing when configured
Stripe, Inc.Payment processing when paid services are used

Subprocessor changes follow the notice process in the data agreement.

Retention and requests

Your data after the work.

Retention

We retain data as needed to provide the service and meet legal, security, and operational requirements. Retention varies by data category, backup cycle, and agreement.

Access or deletion

Request access, correction, or deletion through our privacy contact. Legal retention requirements may apply.

privacy@sociallabs.com

Incident notification

We notify affected customers without undue delay after confirming a breach affecting personal data, subject to applicable law and the executed agreement.