Security

Your data stays yours.

AT Migrator reads your Airtable base, transforms it in memory, and writes it into the PostgreSQL database and storage you connect. We are not a host for your records.

· Privacy · Terms

Processed in memory

Records pass through working memory on the way into your database. We do not keep a standing copy of cell values.

Your infrastructure

PostgreSQL and attachments live where you host them. You hold the credentials.

Read-only Airtable

We never create, edit, or delete anything in your base. It can stay live as a rollback during cutover.

Data path

Where your data goes

Out of Airtable, through working memory, into infrastructure you own. That is the whole path.

Source

Your Airtable base

Read-only. Nothing is written back.

Processing

AT Migrator

Linked records become foreign keys. Formulas become SQL.

Destination

Infrastructure you own

  • Your PostgreSQL database
  • Your S3 bucket

What we keep

A standing copy of your base is not on our systems

We keep the setup and metrics needed to run and support a migration — not the contents of your records.

Never stored

Your records do not live here

  • Cell values from your base

    Text, numbers, dates, and the rest pass through in memory on the way into your PostgreSQL database.

  • Computed formula results

    We recreate formula, rollup, and lookup logic as SQL. We do not keep a copy of the outputs.

  • A copy of your database

    AT Migrator is not a host. When a job finishes, the working data is gone.

  • Attachment files

    They land in your storage, not on our systems.

What we keep

Only what it takes to run a migration

  • Account identity

    Sign-in is handled by our authentication provider — typically your email and session.

  • Migration setup

    Encrypted credentials, the tables and fields you choose, and the formula-to-SQL translations you accept so a run is repeatable.

  • Operational metrics

    Counts of records, fields, and attachments, plus duration and success or failure. Not the values themselves.

  • Progress logs

    Table names, counts, and errors. A failed row can mention the field and the value that could not be transformed.

How we handle it

Access and the controls in place today

What happens to your credentials, and the controls around every migration. Deeper diligence is a conversation, not a dump.

Access & credentials

Your Airtable token, database connection, and storage keys are encrypted at rest. They are unlocked in memory when needed to run or configure a migration, and you can delete them from the dashboard at any time.

  • Encrypted connections (HTTPS) to AT Migrator
  • Security headers and a production allow-list
  • Application and internal services isolated from the public internet
  • Each migration is visible only to the account that created it
  • Airtable connected with OAuth or a token you control

Sub-processors

Who else is involved

Named at purpose level. The canonical list, including any changes, is provided with our Data Processing Addendum.

ProviderPurposeWhat it sees
AirtableSource access during a migrationReads your schema and records with the token you connect. Nothing is written back.
Authentication providerSign-inVerifies your login and session. No migration records pass through it.
LLM providerFormula StudioFormula text and field names. Not your rows.
Microsoft ClarityUsage analyticsSession and usage analytics on the marketing site and in the migration app. Not migration cell values.
PostHogProduct analyticsPageviews, CTAs, and identified product events on the marketing site and migration app, plus operational API and job events. Not migrated cell values.
Cloud hosting and emailRunning the service and transactional emailThe application and support messages. Not a standing copy of your records.

Compliance

What we can share today

You own the data in your Airtable base, your PostgreSQL database, and the storage you configure. AT Migrator is a limited processor of the metadata described above.

DPA

Available on request. It applies once both parties have signed it.

SOC 2

Not yet certified. We complete questionnaires and walk through how migrations work. On request we can run the migration in your environment.

Data residency

Your PostgreSQL database and storage are wherever you host them.

Report a vulnerability to security@atmigrator.com. We investigate every good-faith report and will not pursue researchers who act in good faith and avoid privacy violations, data destruction, or service disruption.

FAQ

Security FAQ

The questions buyers ask most about how AT Migrator handles data.

Yes. It sends formula text and field names to an LLM provider to help translate formulas to SQL. It does not send your records.

Yes, available on request. It applies once both parties have signed it. Until then, the Privacy Policy and Terms describe how data is handled.

Not yet. For an enterprise review we complete your security questionnaire and walk through how migrations work. On request we can run the migration in your environment, so data stays on infrastructure you control.

Email security@atmigrator.com with details and steps to reproduce. We investigate every good-faith report and will not pursue researchers who act in good faith and avoid privacy violations or service disruption.

Need a security review before you migrate?

We will answer your questionnaire, share architecture detail, sign a DPA, and scope a migration you can verify in a sandbox before cutover.

See also our Privacy Policy and Terms of Service. Those are the binding documents.