PRIVACY / FOLLOW THE DATA PATH

Your database work.
Kept close to you.

Connections, profiles, and run history stay on your computer. Database traffic goes directly to your chosen servers; local masking transforms row values without sending them to a cloud AI service.

Choose your license
14-DAY TRIAL

Meet your next workflow.

Choose the installer for your computer.

On a Mac, check Apple menu → About This Mac for your chip.

Trial installers are not available here yet. Please check back for the download.

$10.95 monthly or $99 yearly One developer, up to two devices

The local dossierWORKFLOW STUDY
The local dossierProfiles, settings, and run history remain in a local file folio. A separate direct connection leads to the chosen database server.profilessettingsrun historyYOUR DBLOCAL APP STATEDIRECT CONNECTION

App state stays local. Database traffic reaches your server.

Illustration / example workflow
Workstation-to-database connection · reference path
SECURITY PRINCIPLES

A tool built for security-conscious engineers.

In an era of cloud proxies and opaque SaaS intermediaries, dbmigrate keeps your infrastructure boundary intact.

Direct Socket Connections Only

dbmigrate connects directly from your workstation to your PostgreSQL or MySQL database servers over TLS-encrypted TCP sockets or SSH tunnels. There is no cloud gateway, proxy server, or relay node.

AES-256-GCM Encrypted Secret Storage

Database connection strings, user credentials, and SSH private keys are encrypted locally on disk using AES-256 in Galois/Counter Mode (GCM). Credentials can only be decrypted when you provide your master password.

Zero Cloud AI Ingestion

When copying data with masking rules, transformations execute strictly within local workstation RAM. No row samples, customer identifiers, or PII are ever sent to remote cloud APIs or used to train third-party AI models.

Direct Connections on Your Network

Database operations run between your workstation and the servers you configure. Confirm network reachability, installation, and version-specific licensing requirements when planning a restricted-network deployment.

PRIVACY & SECURITY FAQS

Good questions.
Clear answers.

Where are profiles and run history stored?

Application state stays in local files on your computer. Saved connections, settings, and history use a persistent local data location. Run history records SQL and results without credentials; database operations still communicate with the servers you choose.

How are database passwords and SSH secrets protected?

Saved database passwords and SSH secrets are encrypted with AES-256-GCM and protected by your master password. Protect the workstation account and review local access to the application data directory.

Does masking send row data to a cloud AI service?

No. Column inspection, local sampling, and value transformation run on your workstation. The selected masked values are written to the target database; no cloud AI service receives your row values.

Can I use dbmigrate on a restricted network?

Database work uses direct connections to your configured servers, including configured SSH tunnels. Confirm database reachability, approved installation, and version-specific licensing requirements before planning a restricted-network deployment.

EXPERIENCE LOCAL-FIRST PRECISION

Ready to take control?

Explore dbmigrate on macOS or Windows with our fully featured 14-day trial. Review schema changes and masking in a local workspace.

ZERO TELEMETRY14 days

Explore dbmigrate on your desktop.

  • Direct TCP & SSH socket connections
  • AES-256-GCM encrypted local vault
  • In-memory deterministic PII masking
  • Unlimited databases & tables
14-DAY TRIAL

Meet your next workflow.

Choose the installer for your computer.

On a Mac, check Apple menu → About This Mac for your chip.

Trial installers are not available here yet. Please check back for the download.

macOS (Apple Silicon & Intel) / Windows x64