SECURITY & TRUST

A trust boundary, not just a permissions toggle.

Built for migrations where neither party fully trusts the other with their credentials — carve-outs, tenant separations, and MSP engagements with sensitive end-customers.

Split-credential isolation
Each organisation creates and manages its own app registration. Neither side ever sees the other’s client secret, tenant ID, or anything beyond a display name.
Modern, scoped API access
Every operation runs through Microsoft Graph REST or the Gmail REST API with narrowly scoped application permissions — no legacy EWS, no basic auth, no standing mailbox impersonation beyond what’s required.
Scoped guest access
MSPs can invite an end-customer’s IT contact to view or manage just their own migration batch — never another client’s data, credentials, or billing.
How the trust boundary actually works
1
Each org connects its own tenant
In a two-organisation migration, the inviting org sends an email invite — not an access request. The invited admin logs in, registers their own app registration or Gmail OAuth, and attaches it on their side. It’s never transmitted to the other party.
2
Scope is matched and approved by both sides
Mailboxes are matched source-to-destination and reviewed independently. Both organisations must explicitly approve the scope — any change to a connection or a match resets both approvals — before a single item moves.
3
Runs equally well fully owned or fully split
The same product handles a single admin managing both tenants directly, all the way to a fully split two-organisation setup where neither side has any visibility into the other’s environment. You choose the model per migration.
Built for the modern world
Folder enumeration, message export/import, calendar, delta sync, and deletion all go through Microsoft Graph REST or the Gmail REST API — nothing relies on legacy protocols. Most competitors in this space still lean on EWS, which Microsoft has been deprecating and which requires broader, more static credentials than a scoped Graph app registration.
Microsoft Graph REST
Gmail REST API
Legacy EWS
Questions from your security or legal team?