ElephantsDataSign in
Menu
ElephantsData knowledge centre

Migration Security Questionnaire: Questions and Answers

A security questionnaire for evaluating migration platforms, covering data flow, encryption, credentials, access control, logging, retention, incident response, and audits.

By ElephantsData TeamSeptember 16, 20264 minute read

A migration security review should ask how data flows, which permissions are required, where credentials and temporary content are processed, who can operate a project, what is logged, how deletion works, and which claims have independent evidence. The following questionnaire helps buyers compare answers consistently.

Architecture and data flow

What is the data path? Document the authorized source, migration workers or temporary staging when required, and customer-selected destination. Identify hosting regions and subprocessors.

Is the service a migration pipeline or permanent storage? ElephantsData is designed to orchestrate supported source-to-destination migrations. Some workloads may use encrypted temporary processing or staging for resumability; this is different from a permanent backup repository. Confirm the applicable retention behavior for the selected route.

Encryption and transport

Ask which protocols protect data in transit, how credentials, refresh tokens, configuration, and temporary material are encrypted at rest, and how encryption keys are managed. “Encrypted” without scope, key ownership, or lifecycle detail is not a complete answer.

Authentication and provider permissions

Record delegated or application access, administrator consent, requested scopes, and revocation steps. Verify whether the permission set is limited to the selected workload. Ask what happens to active jobs when consent or a token is revoked.

Identity and access control

Confirm tenant isolation, supported roles, least-privilege administration, multi-factor authentication, session controls, account disabling, and periodic access review. Separate platform administration from migration operation and content publishing where possible.

Logging and auditability

Ask whether security-sensitive actions, authentication changes, mappings, job controls, exports, user administration, and deletion are audited. Determine who can see logs, how long they are retained, and whether customer reports expose message content or only operational metadata.

Retention and deletion

Request specific retention periods for project configuration, tokens, temporary content, logs, reports, backups, and support records. Ask how deletion is requested, verified, propagated to backups, and blocked while a job is active.

Secure development and testing

Ask about dependency scanning, secret scanning, code review, vulnerability management, penetration testing scope, remediation timelines, infrastructure hardening, and separation of test and production data. A self-scan is useful but is not equivalent to an independent penetration test.

Incident response and continuity

Request the incident-notification process, security contact, containment and credential-revocation steps, recovery objectives, backup strategy, and provider-outage handling. Migration schedules should account for external API incidents and throttling.

SOC reports and certifications

Ask for the exact legal entity, report type, audit period, system scope, exceptions, and bridge letter. Do not treat “SOC-ready,” a cloud provider's certification, or an automated scanner as ElephantsData's own SOC 1 or SOC 2 report. ElephantsData should claim third-party assurance only when a current report directly covers the service.

Evidence to request

  • Architecture and data-flow diagram
  • Permission and subprocessors list
  • Privacy, retention, and deletion documentation
  • Incident-response contact and process
  • Sanitized audit and reconciliation examples
  • Current independent assessment reports, if available

Read the current ElephantsData security overview and submit sensitive questions through the support process without including passwords or secrets.

A safer operating pattern

Start with a pilot that represents the real project: one ordinary user, one large mailbox or drive, and one account with unusual folders, labels, permissions, or item sizes. Keep the source available until the destination has been validated. A successful sign-in proves only that authentication works; it does not prove that every selected workload can be read, mapped, written, and reconciled.

Before the production run, record the agreed scope, exclusions, destination licenses, storage capacity, maintenance window, escalation contacts, and acceptance criteria. Run preflight checks again after configuration changes. During migration, review user-level progress instead of relying on a single percentage. Afterward, separate transferred, skipped, and failed items, investigate exceptions, and run an incremental pass for eligible changes created after the initial scan.

ElephantsData provides an encrypted, customer-authorized source-to-destination migration pipeline with mapping, preflight checks, checkpoints, retries, progress visibility, and outcome reporting for supported routes. Support varies by provider and workload, so confirm the current supported migration routes before committing to a project. ElephantsData is currently free to use; provider licensing, storage, API, and network charges may still apply.

Frequently asked questions

Should the source be deleted immediately after migration?

No. Retain the source according to your business, legal, and backup requirements until stakeholders approve the destination and the reconciliation evidence.

Does a completed job guarantee that every possible item moved?

No. Completion must be read together with scope, skipped items, failures, provider limitations, and destination sampling. Use the mailbox validation guide before acceptance.

Where should I start?

Review the email migration software workflow, verify the route, and run a representative pilot before expanding the batch.