Skip to content
Security

What we can reach, and what we do not claim.

Know how we access your CRMs, where your data is stored and when it is deleted. If your security reviewer needs more detail, contact us.

Connections

You control access to your CRMs.

Connect without sharing passwords.

Connect through OAuth or, for Freshsales, provide an API key and account address. Migratez never receives your password. You can revoke access from either application at any time. If an admin needs to connect it, send them a connection link. They need no Migratez account and see only the app, access requested and who asked, not the migration.

OAuth tokens are encrypted before storage.

OAuth access tokens are encrypted before we store them in the database. Freshsales API keys are stored as connection data and do not receive that application-level encryption.

We never write to your source CRM.

We request read-only access where the application supports it. Some applications grant broader permissions by default. Even then, we only read your source and never write back to it.

The destination needs read and write access.

Connect the destination after the source. We need permission to create fields and write the migrated records.

Where it runs
Migratez is operated from India by Upper Cap Software Solutions LLP. The service is hosted in the United States.

Your migration data is hosted in the United States.

These providers process data on our behalf and under our instructions. Each has a different role.

DigitalOcean

Hosts the service and managed databases in the United States, including your data during migration.

Google

Provides sign-in and reCAPTCHA. Migratez sign-in is passwordless.

PostHog

Product analytics.

Skydo

Handles invoicing and payments. Skydo receives billing details, not your migrated data. Migratez has no card form and does not receive your card or bank details.

Your data
Each migration has its own database in a shared managed cluster. The hardware is shared.

Your migration has its own database.

During migration: We keep a working copy of your records in your migration's database. If the run pauses, this copy lets us resume and explain what happened.

After migration: The working copy is deleted when the run completes, is undone or you ask us to delete the migration. A run that stops partway keeps its copy until one of those happens. We keep a record of what was written and where so you can undo a completed migration.

On an erasure request: We delete the entire migration database. Backup copies expire as described below.

Backups
Deleting the database removes it from the live service immediately. Backup copies expire within seven days.

Daily backups, retained for seven days.

DigitalOcean backs up the databases daily and retains backups for seven days. We can restore to a chosen point within that window. After an erasure request, the final backup copy expires within seven days.

There is no live standby. If the database fails, recovery requires restoring a backup.

Breach notification

We notify you of a personal data breach within 72 hours.

If a breach affects your personal data, we will tell you within 72 hours of becoming aware of it, at the address on your account.

Paperwork

We will sign a data processing agreement.

Request a data processing agreement before connecting customer data. Email support@migratez.com and we will send it over.

What we do not claim

Our certification and staffing limits.

Migratez has no SOC 2 report or ISO 27001 certification. Our providers’ certifications do not certify Migratez. One person operates the service and runs every migration. If your review requires independent certification or a larger operations team, we do not meet those requirements.

Next step

Assess your data without changing it.

Connect your source CRM to see your record count and price. The assessment writes nothing to either CRM. Nothing moves until you ask.