GlobalSearch SQL Export Utility — Security Overview
Purpose
This utility is a single-purpose command-line tool used during on-premise-to-cloud migrations. It connects to a source SQL Server database and generates SQL script files (schema and data) for a pre-approved set of tables and stored procedures, which are then used to populate the destination environment.
The utility is a narrowly scoped, ephemeral, offline export tool: no persistent service, no stored credentials, no external network calls beyond the customer's own database connection, and no data leaves the customer's control except through steps the customer explicitly performs. The main security consideration on the customer's side is protecting the intermediate SQL script files during the migration window.
Execution model
-
Runs as a standalone console process — it is not a service, does not listen on any network port, and has no persistent background presence.
-
It is invoked manually or as part of a controlled migration run, executes once, and exits.
-
No installation footprint beyond the executable itself; no registry or system-level changes.
Authentication & credentials
-
The tool does not store, cache, or transmit credentials. A connection string is supplied by the operator at runtime as a command-line argument and used only for the duration of that single execution.
-
It supports whatever authentication mode the customer's SQL Server connection string specifies (SQL authentication or Windows integrated authentication), so existing credential and identity policies apply unchanged.
-
We recommend customers use a least-privilege, read-only account scoped only to the objects being migrated.
Data in transit
-
All communication with the source database uses the standard Microsoft SQL Server client protocol (via Microsoft's official SqlClient library). Encryption in transit is governed by the connection string settings the customer provides, consistent with normal SQL Server client behavior and the customer's existing network security controls.
Data at rest
-
Output is written as local SQL script files on the machine running the utility. These files are plain text and, depending on the tables in scope, may contain sensitive business data.
-
The tool does not transmit these files anywhere itself — movement to the destination cloud environment is a separate, customer-controlled step.
-
We recommend customers run the export on a hardened, access-controlled host, apply disk encryption, transfer the output over an encrypted channel, and securely delete the local files once the migration is verified.
Scope control
-
The tool only exports tables and stored procedures that have been explicitly approved for inclusion. This prevents accidental export of unrelated or out-of-scope database objects.
Logging & error handling
-
Console output is limited to progress/status messages and, on failure, a local error trace for troubleshooting. No telemetry, usage data, or diagnostics are sent to any external service.