
Data sovereignty without compromise: in migRaven.MAX, data protection does not conflict with functionality — it is part of the design. This document explains in understandable terms which information can be transferred to the configured AI provider while working with migRaven.MAX.
The basic principle
migRaven.MAX uses AI as an assistance layer on top of a controlled knowledge graph. The AI receives only the necessary work instructions and the current context. If data is required, it requests it specifically through controlled tools; the backend executes these queries and returns limited results.
Important: the AI does not work directly on the target systems. Changes in production run through migRaven.MAX processes with authorization, justification, approval and audit.
What is never sent to the AI
No stored passwords, API keys, client secrets, Windows Credential Store values, SMTP secrets, LDAP/AD service account passwords or Entra app secrets. Nor any complete database copies or a blanket full transfer of all AD, Entra, SharePoint, Teams or file server data.
Who determines the AI provider
The AI provider is configured by the customer or operator — depending on the installation and approval, for example Azure AI Foundry, Azure OpenAI, OpenAI-compatible providers, Anthropic, Z.Ai or Qwen. For productive customer scenarios, we recommend an enterprise or Azure-based deployment with clear data protection and data processing agreements.
