Customer-controlled authorization
Customer administrators authorize Microsoft, Google or Zoho access through the provider’s supported consent flow. ElephantsData does not grant provider permissions to itself and cannot bypass tenant policy or administrator approval.
Credentials and secrets
Stored provider credentials and sensitive connection configuration are encrypted before database storage and are not returned to the browser as plaintext. Password-based access should use scoped app passwords where the provider supports them.
Role and tenant boundaries
Authenticated operations are tenant scoped and restricted by application roles. Administrative activity and migration changes generate audit records so operators can review who performed an action and when.
Transfer and staging
Migration jobs use checkpoints and encrypted staging controls where temporary storage is required. Temporary migration storage is operational working space, not a customer backup. Data-retention requirements should be agreed for each deployment and migration engagement.
Shared responsibility
- Customers control provider consent, licenses, destination accounts and tenant policy.
- Customers must protect administrator identities and review requested permissions.
- ElephantsData reports known readiness and transfer exceptions; it does not redefine unsupported provider behavior as successful.
- Security or privacy questions should be resolved before production authorization.