Security
Migration evidence should not become a second credential vault.
Movetali is designed around credential non-custody for the migration engine: secret-like fields are excluded from migration evidence, production connections are rebound in the n8n environment the customer controls, and production activation requires human approval.
Checked 2026-10-01 · This page describes Movetali's current supported process. It does not claim that every workflow is migratable.
Credential boundary
- Do not submit passwords, tokens, API keys, seed phrases, or production credentials in the Fit Check.
- Secret-like fields are rejected or redacted from migration evidence.
- Customer-controlled credential rebind remains explicit.
Production boundary
- Generated n8n candidates are inactive by default.
- Importability is not treated as cutover approval.
- Production cutover is human-approved and rollback guidance is prepared first.
Data and operations
- Public intake and owner operations are separated.
- Owner access is protected separately from the public site.
- Money, credential, and production-state changes are fail-closed by design.
Related
Next step
The Fit Check is free and comes before paid migration work. Do not send passwords, API keys, tokens, seed phrases, or production credentials.