Your data never leaves your hands. By design.
Morph generates the migration; you run it. We never ask for production credentials, never connect to your databases, and never see the rows inside them. The safety isn’t a policy bolted on — it’s the shape of the product.
Four commitments we built the product around
We never touch your production database
Morph generates scripts. You run them, in your environment, on your schedule. There is no agent to install and no path from our servers to your data.
We never ask for production credentials
Connection strings, passwords and keys stay with you. The product has no field to paste them into, because it never needs them.
Data movement runs inside your network
The bulk-copy and CDC scripts execute between your source and target. Your rows travel your own wire — they are never proxied through Morph.
Analysis works from metadata you provide
The AI reasons about schema and shape — table and column definitions, types, sizes, counts, constraints — not the contents of your tables.
A clear ledger of what we touch
No ambiguity. Here is precisely what Morph receives to do its job — and the larger list of what it is built never to see.
What Morph receives
- Source & target engine and version
- Table count, approximate data volume
- Column names, types and constraints you share
- Downtime tolerance & host environment notes
- Your questions in the per-migration chat
Metadata and structure — the facts a migration architect would ask for. You choose exactly how much detail to share.
What Morph never sees
- Production credentials, passwords or keys
- The actual rows and values in your tables
- A live connection to your databases
- Anything we weren't explicitly given
If we don’t need it to generate your migration, we don’t collect it.
How we protect the little we hold
Encrypted in transit
Every request to Morph is served over TLS. The metadata you submit and the artifacts we return travel encrypted end to end.
Least-privilege by design
Generated scripts request the narrowest grants that work — a migration role, not your superuser — and the runbook tells you exactly what each step needs.
Scoped account access
Your projects, artifacts and migration history are bound to your account. Authentication gates every page and every download.
Transparent by construction
The model is powerful, but the inputs are deliberately narrow. It reasons from structure, proposes a plan, and writes code you read before anything runs.
Pricing is computed server-side and deterministically — never taken from the model’s output. The AI advises; it doesn’t set your bill.
You describe the shape
Engines, versions, breadth, volume, constraints and goals — the facts a migration architect would ask for first.
The model reasons over metadata
It builds a type map, a dependency graph and a risk register from structure alone. No table contents are required or used.
It writes artifacts you review
DDL, data scripts, validation, rollback and runbook come back as readable files. Nothing executes until you decide to run it.
You hold the only connection that matters
Because every script runs in your environment, your existing controls already apply — network policy, secrets management, audit logging and change review. Morph slots into the safeguards you trust instead of asking you to trust new ones.
Security questions, answered honestly
No hedging, no badge wall — just how it actually works.
Confidence, not credentials
Pay once. Keep control of your data and your execution. Let the AI do the analysis, pricing and generation.