Trust & security

Your data never leaves your hands. By design.

Morph generates the migration; you run it. We never ask for production credentials, never connect to your databases, and never see the rows inside them. The safety isn’t a policy bolted on — it’s the shape of the product.

Principles

Four commitments we built the product around

We never touch your production database

Morph generates scripts. You run them, in your environment, on your schedule. There is no agent to install and no path from our servers to your data.

We never ask for production credentials

Connection strings, passwords and keys stay with you. The product has no field to paste them into, because it never needs them.

Data movement runs inside your network

The bulk-copy and CDC scripts execute between your source and target. Your rows travel your own wire — they are never proxied through Morph.

Analysis works from metadata you provide

The AI reasons about schema and shape — table and column definitions, types, sizes, counts, constraints — not the contents of your tables.

Data handling

A clear ledger of what we touch

No ambiguity. Here is precisely what Morph receives to do its job — and the larger list of what it is built never to see.

What Morph receives

  • Source & target engine and version
  • Table count, approximate data volume
  • Column names, types and constraints you share
  • Downtime tolerance & host environment notes
  • Your questions in the per-migration chat

Metadata and structure — the facts a migration architect would ask for. You choose exactly how much detail to share.

What Morph never sees

  • Production credentials, passwords or keys
  • The actual rows and values in your tables
  • A live connection to your databases
  • Anything we weren't explicitly given

If we don’t need it to generate your migration, we don’t collect it.

Practices

How we protect the little we hold

Encrypted in transit

Every request to Morph is served over TLS. The metadata you submit and the artifacts we return travel encrypted end to end.

Least-privilege by design

Generated scripts request the narrowest grants that work — a migration role, not your superuser — and the runbook tells you exactly what each step needs.

Scoped account access

Your projects, artifacts and migration history are bound to your account. Authentication gates every page and every download.

How the AI works

Transparent by construction

The model is powerful, but the inputs are deliberately narrow. It reasons from structure, proposes a plan, and writes code you read before anything runs.

Pricing is computed server-side and deterministically — never taken from the model’s output. The AI advises; it doesn’t set your bill.

01

You describe the shape

Engines, versions, breadth, volume, constraints and goals — the facts a migration architect would ask for first.

02

The model reasons over metadata

It builds a type map, a dependency graph and a risk register from structure alone. No table contents are required or used.

03

It writes artifacts you review

DDL, data scripts, validation, rollback and runbook come back as readable files. Nothing executes until you decide to run it.

You hold the only connection that matters

Because every script runs in your environment, your existing controls already apply — network policy, secrets management, audit logging and change review. Morph slots into the safeguards you trust instead of asking you to trust new ones.

Straight answers

Security questions, answered honestly

No hedging, no badge wall — just how it actually works.

No. Morph has no inbound or outbound connection to your databases. It produces scripts from the metadata you provide, and you execute those scripts yourself inside your own network. We deliberately have no place to enter a connection string.

Never — and we never ask for them. There is no field in the product for passwords, keys or connection strings. The artifacts we generate reference placeholders that you fill in at runtime, in your environment.

No. The analysis reasons about your schema and the shape of the move — table and column definitions, types, sizes, counts and constraints you choose to share. The contents of your rows are not needed to generate a migration, and we don't ingest them.

Directly between your source and target systems. The bulk-copy and change-data-capture scripts run inside your network; your rows are never proxied or staged through Morph's infrastructure.

The least that will work. We generate steps for a dedicated, scoped migration role rather than a superuser, and the operator runbook documents exactly which grant each phase requires so your team can review before granting anything.

No — we'd rather be precise than decorative. The honest summary is the architecture itself: we never hold your credentials, never see your rows, and never connect to your databases. If you have a specific assurance requirement, reach out and we'll answer it directly.

Confidence, not credentials

Pay once. Keep control of your data and your execution. Let the AI do the analysis, pricing and generation.