Security, privacy & compliance
How we safeguard your database, protect your backup archives, and comply with GDPR regulations to keep your sites secure.
Trust Center Sections
Security contact
Found a vulnerability or have security concerns? Contact our designated security response team directly.
[email protected]1. Data Encryption & Transmission
All communication between your sites, our MigraSync Plugin, and the MigraSync SaaS dashboard is encrypted using TLS 1.3. Any transient database transfer packages created during migrations are deleted from our servers immediately upon successful synchronization, leaving no trace behind.
- AES-256 database compression encryption
- Forced HTTPS/SSL validation on all endpoints
- Automated local cleanup of temp migration folders
2. Backup Storage Safety
Your site backups are stored inside heavily protected, isolated MigraSync Managed Cloud storage. We enforce write-once protections on backup snapshots, helping guard against ransomware and accidental modification.
- Ransomware protection via Object Lock
- Server-Side Encryption (SSE) enabled by default
- 99.999999999% cloud storage durability guarantees
3. GDPR & Privacy Compliance
We strictly adhere to the General Data Protection Regulation (GDPR). Since we function as a data processor during migrations, we only store personal metadata required to execute support requests or invoices. We do not inspect, log, or commercialize database contents or client records contained inside your WordPress files.
- Right to be forgotten: request total account deletion
- No analytics or tracking cookies inside backups
- Data processing agreements (DPA) available on request
4. Secure REST API Handshake
To connect your WordPress site to the MigraSync SaaS backend, our MigraSync Plugin uses a secure, tokenized cryptographic handshake. This method prevents your WordPress credentials (usernames and passwords) from ever being stored on our servers, ensuring your dashboard credentials remain strictly private.
- Tokens expire automatically upon disconnection
- 0 storage of WordPress admin credentials
- Signed requests verify integrity of migrations
5. SaaS Dashboard Security
Access to your MigraSync subscription and backups is protected by modern industry standards, including two-factor authentication, secure session tokens, and strict account login rate limiting.
- Optional 2FA protection via Authenticator Apps
- Rate limiting and IP blocking on authentication portals
- GDPR cookie compliance widgets