Don't miss our next webinar on migration

View the webinar
Start for free now

Information and data transfer to the AI providers used

Information and data transfer to the AI providers used

Data sovereignty without compromise: in migRaven.MAX, data protection does not conflict with functionality — it is part of the design. This document explains in understandable terms which information can be transferred to the configured AI provider while working with migRaven.MAX.

The basic principle

migRaven.MAX uses AI as an assistance layer on top of a controlled knowledge graph. The AI receives only the necessary work instructions and the current context. If data is required, it requests it specifically through controlled tools; the backend executes these queries and returns limited results.

Important: the AI does not work directly on the target systems. Changes in production run through migRaven.MAX processes with authorization, justification, approval and audit.

What is never sent to the AI

No stored passwords, API keys, client secrets, Windows Credential Store values, SMTP secrets, LDAP/AD service account passwords or Entra app secrets. Nor any complete database copies or a blanket full transfer of all AD, Entra, SharePoint, Teams or file server data.

Who determines the AI provider

The AI provider is configured by the customer or operator — depending on the installation and approval, for example Azure AI Foundry, Azure OpenAI, OpenAI-compatible providers, Anthropic, Z.Ai or Qwen. For productive customer scenarios, we recommend an enterprise or Azure-based deployment with clear data protection and data processing agreements.

Auszug aus dem Dokument

Which data is transferred from migRaven.MAX to the AI, and when? The document answers this question in terms that IT, security, data protection and the works council can understand — including practical examples and a clear list of what is never transferred.

MR

migRaven Team

IT-Governance Experten

Wichtigste Funktionen

  • Basic principle: the AI works as an assistance layer on top of a controlled knowledge graph

  • Which types of data are transferred and when — with four examples from practice

  • What never goes to the AI: no passwords, secrets, API keys, no database copies

  • The knowledge graph is never sent to the AI provider as a whole

  • Data protection and works council perspective, including a recommendation before going into production