Security
Controls you can inspect.
See how we isolate each tenant, what data goes to which subprocessor, and how approval gates keep agents from acting alone.
Tenant model
Customer workspaces stay isolated. Access is denied by default.
Tenant isolation
Customer workspaces are logically isolated. Covered portfolio data is scoped to the authenticated organization, and privileged access paths require an explicit authorization decision before they run.
Authorization
Every sensitive operation authenticates the caller and enforces role and organization boundaries before data is returned or changed. Access is denied by default outside those checks.
Encryption
Data is encrypted in transit (TLS) and at rest via our infrastructure providers. Customer-supplied LLM credentials are encrypted at rest when BYOK is configured.
Hosting and region
Application and data processing currently run in the United States. EU data residency is not a product option today — we state that plainly in diligence rather than implying otherwise.
LLM data handling
What leaves the tenant, and whether it trains a model.
Bring-your-own-key is supported for commercial providers. Bring-your-own open-weight model is supported on customer-controlled neoclouds. In both cases, the endpoint you configure — and its contract — governs the call.
Anthropic
- Data that may leave the tenant
- Prompts, tool context, and model outputs for configured agent workflows.
- Used for model training?
- No. Under Anthropic commercial API terms, API inputs are not used to train foundation models by default.
- Data that may leave the tenant
- Prompts and outputs when a Google / Gemini model is the configured provider.
- Used for model training?
- No. Under Google Cloud / Gemini API commercial terms applicable to paid API use, customer prompts are not used to train Google foundation models by default.
OpenAI
- Data that may leave the tenant
- Prompts and outputs only when an OpenAI model is explicitly configured.
- Used for model training?
- No. Under OpenAI API data-usage defaults for paid API customers, API inputs are not used to train models by default.
Open-weight models (customer neocloud)
- Data that may leave the tenant
- Prompts, tool context, and outputs are sent only to the inference endpoint you designate. MigrateForce does not retain a parallel copy for model training.
- Used for model training?
- No by MigrateForce. Weights, logs, and retention stay under your neocloud / self-hosted contract — you control whether any telemetry is retained or used to fine-tune.
MigrateForce does not train foundation models on customer content. Customer content is not used to improve a MigrateForce-owned model. Provider defaults above reflect commercial API terms as of publication; enterprise contracts can tighten further.
Compliance status
SOC 2
Planned
ISO 27001
Planned
We honor applicable data-subject rights and publish a Data Processing Agreement. That is not the same as a completed SOC 2 or ISO certification.
Subprocessors
| Subprocessor | Role | Region |
|---|---|---|
| Supabase Inc. | Database hosting and authentication | United States |
| Google LLC | Cloud infrastructure and optional AI services | United States |
| Resend Inc. | Transactional email | United States |
| Anthropic PBC | AI model processing for configured agents | United States |
| OpenAI, L.L.C. | Optional AI model processing when configured | United States |
| Stripe, Inc. | Payment processing when paid services are used | United States |
Changes follow the notice process in the DPA. Full legal terms: Privacy Policy.
Retention, deletion, incidents
What we keep, what you can delete, who to call.
Retention
Account and engagement data is retained while needed to operate the service and meet legal obligations. Enterprise retention can be scoped in the executed agreement.
Deletion
Request deletion via privacy@sociallabs.com (Social Protocol Labs operates MigrateForce). We honor applicable legal rights subject to retention requirements.
Incidents
Confirmed breaches affecting your personal data are notified without undue delay per the DPA. Contact privacy@sociallabs.com.
Next step
Run an assessment on your own context, or book a security walkthrough for enterprise diligence.