AI-Powered Data Migration Planning

MapFlow

The sovereign-secure alternative to failed "lift and shift" cloud migrations — an AI-driven ETL gateway that cleanses, maps, and pipes any legacy database asset directly into the council's Salesforce or Microsoft Dynamics PaaS.

The only UK sovereign data-migration platform that combines AI field mapping with zero CLOUD Act exposure.

From Birmingham's £140m Oracle collapse to Powys's failed planning archive, the public record is the failure. MapFlow exists to give councils the best engineering the politics will finally allow.

MapFlow sovereign AI data migration workspace

The Problem

UK local government is living through a documented failure pattern — councils that have lost the in-house capacity to specify, procure, and deliver complex data migrations, then settle for the cheapest "lift and shift" bid.

  • Field mapping documents live in disconnected spreadsheets no-one keeps up to date.
  • Developers build migrations from verbal briefs — specs are ambiguous and subject to change.
  • No clear audit trail of who approved what and when.
  • PII fields are discovered in production rather than during design.
  • UAT test scripts are written ad-hoc, missing critical edge cases.
  • When a consultant leaves, institutional knowledge of the mapping logic leaves with them.
  • Documents are uploaded uncompressed — the 'Salesforce Storage Tax' silently inflates storage costs every month, forever.

Why MapFlow

Measurable impact from day one.

95%+

Reverse-engineering confidence with candidate record pairs

Weeks → Minutes

Screen Grab → Mapper pipeline for field mapping generation

100%

Traceability — every mapping version permanently stored

Zero CLOUD Act risk

UK-sovereign staging DB + RelaxAI (UK) + ciphertext-only-in-volatile-memory on Base44 — nothing for a US order to see

Zero data

Shared with AI providers by default — non-AI algorithmic mapping engine; when on, RelaxAI (UK-sovereign) only

0 code

Required to define, document and export a complete SQL view

£0 net cost

Local Proxy compression + SharePoint hybrid savings offset the Mapflow licence — kills the Salesforce Storage Tax

24/7

Slack & Teams bot auto-replies to @Mapflow mentions — AI-powered, real-time

Real Postgres 16

In-browser WASM pipeline engine — no 2GB ceiling, no corruption, no Access runtime, concurrent tabs

Unique AI

Fine-tuned LoRA adapters on proprietary migration data — a model no competitor can reproduce without your corpus

Feature Pillars

Integrated modules covering the full migration lifecycle — plus companion tools.

Visual Field Mapping

Drag-and-drop canvas connecting source to destination fields. Add transformations, SQL joins, pivot operations, and row-level filters — export a complete SQL CREATE VIEW instantly.

Reverse-Engineering with Candidate Records

Supply matched source↔destination record pairs and the engine compares actual values side-by-side for 95%+ confidence mappings. The 'follow me' approach — show the system how to map by example. Runs as the non-AI algorithmic default with zero data shared with any AI provider.

Schema Catalogue

Import and document your entire source database schema. Define relationships, annotate fields, and visualise the ERD interactively. Supports SQL Server, Oracle, Salesforce, and MS Access.

AI-Powered Intelligence (Opt-In)

AI auto-suggests field mappings, infers joins, flags PII, generates UAT plans. The non-AI reverse-engineering engine is the default — zero data shared with any AI provider. When AI is on, inference routes to RelaxAI (UK-sovereign LLM) or a locally-hosted model (Ollama: Llama-3 / Phi-3 on the operator's own Windows machine) via the Sovereign Inference Shuttle — prompts and keys never transit the US-parent platform. The local-LLM path means true LLM reasoning with zero internet egress and absolute data residency. The AI engine is admin-gated (off by default) with mandatory InfoSec warnings when enabled. Screen Grab → Mapper pipeline generates confidence-scored mappings in minutes.

Governance & Sign-Off

Semantic versioning, structured sign-off workflow, merge review with per-diff accept/decline, per-mapping confidence validation, and a comprehensive Client Management Report (PDF) per mapping.

Audited Change Control (No Hot Fixes)

Every production data correction flows through one governed path: propose → second-admin approve → overnight apply inside an audited transaction. Each fix is captured in an immutable ledger with before/after snapshots and a SHA-256 integrity hash, and is reversible with one click. Direct in-line edits are disabled. Fixes are gated on a successful overnight Salesforce→Postgres copy so they can't be silently overwritten, and can optionally dual-push to Salesforce to keep both systems in sync.

Risk & Issue Log

Integrated risk register tracking risks, issues, tasks, and to-dos against specific mappings and data objects. Severity ratings, planned fix dates, and file attachments.

Data Profiler

AI-driven table and field quality analysis with live database connectivity. Scan for PII, flag poor-quality data, analyse cardinality, and score migration readiness 0–100%.

Live Database Connectivity

Connect directly to Azure SQL, Oracle, MS Access, and Salesforce. A lightweight local proxy bridges on-premise databases to the cloud — no firewall changes required.

Local Tables & Postgres Staging

Intermediate staging tables with a PGLite in-browser engine and Postgres push. Postgres integration provides environment-tiered schema copies (dev/test/live), full CRUD table management, and overnight automation. MS Access export retained for legacy handoffs — but no longer the engine.

PGLite In-Browser Pipeline Engine

Real PostgreSQL 16 compiled to WebAssembly, running in the browser tab — full SQL surface (CTAS, window functions, CTEs, JSON, regex), transactional BEGIN/ROLLBACK, and zero install. Declarative PglitePipeline entities with ordered steps, declared depends_on, a topological graph runner, per-step run logs, and auto-dispose of transient tables. Replaces the 2GB-corruption-prone, single-writer, file-locked MS Access Jet/ACE engine entirely — and is strictly stronger on every dimension except one (Access still wins for genuinely air-gapped engagements with no first-load connection).

AI Learning & Fine-Tuning — A Model No One Can Match

Every accepted mapping, PII label, purpose statement, and screenshot correction is captured from day one as a de-identified training pair. Fine-tune task-specific LoRA adapters (field mapping, PII classification, schema-purpose, screenshot detection) on MapFlow's proprietary council-migration corpus — an adapter no competitor can reproduce without your data. Served via Civo Project Mercury (client-provisioned UK GPU) or local Ollama on a sovereign host. The base model is public; your adapter is not — that is the moat.

Document & Note Loaders

Hybrid document loading: upload to SharePoint then sync to Arcus via Public_Share__c, or send directly to Salesforce ContentVersion — up to 2 GB per file. The Local Proxy compresses the ~85% case files up to 90% in-memory inside the council network before upload — eliminating the Salesforce Storage Tax with no third-party sub-processor. Document Audit identifies document tables and verifies file existence with SZDD decompression and OLE2 CLSID detection.

Multi-Project Workspaces

Full tenant isolation across client engagements. Admins create projects, assign team members, and each project maintains its own isolated mappings, schemas, connections, and risk logs.

Zero-Trust Security & Compliance

UK-only data residency end-to-end. TOTP MFA, automatic session timeout, RBAC with row-level security, full audit trail, PII scanning at design time, AES-256-GCM encryption for Postgres PII fields, blind-index encrypted search, per-environment key lifecycle, council-held Master recovery key, GeoIP enforcement with Council IP allow-list, and weekly automated InfoSec posture monitoring with admin email alerts.

Proactive Threat Monitoring & Remedial Action Log

A live, database-backed Security Threat Register documents every threat to the platform with a full remedial action log — identified → authorised → applied — plus a per-threat audit trail. An event-driven sweep fires immediately on every app publish (code push / deploy, new endpoints, dependency changes) so newly-exposed surfaces are scanned without waiting for the weekly cadence; the weekly AI web-search sweep is a structural / deep review (attack-surface mapping, brand protection, compliance benchmarking). Residual risks and their remediation status are surfaced continuously, not just at periodic review.

Roboshadow — Proactive Endpoint & App Monitoring

Roboshadow continuously monitors operator endpoints and the MapFlow application for vulnerabilities, patch status, and configuration drift — detecting and remediating weaknesses before they can be exploited. Combined with the weekly InfoSec posture runner and the Independent Security Audit page, MapFlow's security is continuously verified across three tiers: Roboshadow (endpoint/app), Base44 (platform), and VGT/MapFlow (app-layer code). No legacy tool has an equivalent — a corrupted .accdb file or an unpatched laptop is a silent risk until something breaks.

Tiff Flow — TIFF to PDF Converter

Combines single-page TIFF files into a merged PDF with quality scoring. Drag-and-drop ordering or batch folder processing.

PDF Merger — Single-Page Combiner

Merges multiple single-page PDFs into a combined file. Supports drag-and-drop ordering and batch folder processing.

FlowVault — SFTP Transfer Audit

Lists your source folder, connects to Arcus SFTP, retrieves the destination file listing, and verifies each file is present. Scales to millions of documents.

Training Environment

Hands-on training with dummy data across four role tracks. 13 interactive sandbox modules — no live data touched, everything persists in the browser.

Migration Flow Diagram

Interactive 14-step automated lifecycle vs 8-step manual process. Each step is clickable and navigates to the actual screen where that task is performed.

Screen Grab Session

Captures bookmarklet field extraction results and screenshots, then sends the complete package to the AI Mapping Assistant for automated mapping generation.

IDOX Uniform Tools

Four tools for IDOX Uniform migrations: Screen Capture, DB Schema Scraper, PDF Documentation Scraper, and Uniface Parser — replacing weeks of manual schema discovery.

SQL Server Utilities

AI-powered File Exporter (binary column detection, magic-byte file-type detection) and RTF Extractor (magic-byte verification, inline preview, SQLite/Excel/Access/CSV output).

Slack & Microsoft Teams Bot Integration

AI auto-replies to @Mapflow mentions in Slack (real-time webhooks) and Teams (channel polling). Support ticket notifications and connector onboarding conversations routed to both platforms.

Support Tickets & Connector Onboarding

In-app support ticket system with real-time Slack notifications. Structured connector onboarding conversations with credential purging on close. Admin-managed with full audit trail.

Script Builder — No Vendor Lock-In (Exit Strategy)

Export every mapping's conversion logic as a standalone Python or Node runner — modern CLI with the SQL embedded, runs against the source DB from the command line. No MapFlow account, no API, no runtime dependency. A bus-factor safeguard: the data and the logic leave with the client — exercises the UK GDPR Article 20 right to data portability, no vendor lock-in.

Who Is It For

Built for every stakeholder in a data migration project.

Data Migration Consultant

Central workspace for all mapping logic. AI handles the boilerplate; you focus on the decisions that matter.

Business Analyst / SME

Review and sign off mappings in a structured, role-based workflow. No need to interpret raw SQL.

Project Manager

Real-time visibility of mapping progress, risk log, sign-off status, and version history across the migration.

QA / Test Engineer

AI-generated UAT plans with positive, negative, and edge-case tests ready to execute and evidence.

Architect / DBA

Schema catalogue, ERD diagrams, and AI join analysis give instant command of complex legacy schemas.

How It Works

A structured workflow from discovery to production sign-off.

1

Discover

  • Import schema from live DB or DDL SQL
  • AI infers table join relationships
  • Annotate fields with purpose descriptions
  • Profile tables for quality & PII risks
2

Design

  • Supply candidate record pairs for 95%+ confidence mappings (non-AI default)
  • Screen Grab → Mapper: generates from captured UI fields + PII + Postgres data
  • AI engine opt-in (admin-gated, off by default, InfoSec warnings)
  • Add joins, filters, pivots visually
  • Export complete SQL CREATE VIEW
3

Govern

  • Create versioned mapping snapshots
  • Business, DBA, PM sign-off workflow
  • AI-generated UAT test plans
  • Data profiler scans for quality & PII

Security & Compliance

Secure by design — mapping to recognised industry frameworks.

Two-Factor Authentication (MFA)

TOTP-based MFA compatible with Google Authenticator, Microsoft Authenticator, and Authy. Admins enforce per user. Backup recovery codes provided. Users who don't complete setup within 24 hours are locked out.

Automatic Session Timeout

Idle sessions terminated after a configurable period (default 30 min, range 10 min–2 hrs). Mouse, keyboard, scroll, and touch events reset the timer.

RBAC & Row-Level Security

Every entity enforces RLS. Admin and user roles gate administrative operations. Multi-project workspaces ensure full tenant isolation per project.

Audit Trail, PII Scanning & Backup

Full change history and execution logs on every mapping version. AI PII scanning on schema metadata and Local Table row data at design time. Full backup & restore for disaster recovery.

Data Encryption, Key Lifecycle & Sovereign Custody

Citizen data is staged in a UK-sovereign cloud Postgres database. Every PII field is AES-256-GCM encrypted on the operator's Local Proxy before it reaches the database, so the database itself only ever holds ciphertext. The encryption key is TPM-bound (TPM 2.0) to the proxy host via Windows Credential Guard and never reaches the US-parent Base44 platform. A raw Master Recovery Key is escrowed to the council's own corporate vault as the break-glass DR path.

Per-environment key lifecycle: a real PII key only exists during an active transfer/UAT window — Test1, Test2, and Live each use a dedicated key destroyed after its stated use. No long-lived key to compromise. Blind-index search: HMAC-SHA256 search columns enable exact-match lookups on encrypted audit data without exposing plaintext to the database. Sovereign custody: the Council retains the Master (archive) recovery key in its own corporate vault — the Council can restore its own backups without depending on VGT or the Base44 platform. The sovereign database is never accessed via the postgres superuser — a least-privilege role is provisioned server-side and the superuser password is burned post-setup so no human holds it.

Proactive Monitoring, MFA Hardening & Independent Audit

MapFlow's security is continuously verified across three tiers: Roboshadow (proactive endpoint and application vulnerability monitoring — CVE scanning, patch tracking, remediation workflow), Base44 (platform infrastructure, SOC 2 Type II / ISO 27001), and VGT/MapFlow (app-layer code). On 2026-08-27, an internal security audit identified three MFA findings — plaintext TOTP secrets, base64-encoded backup codes, and no rate limiting — all of which have been fixed: secrets are now AES-256-GCM encrypted at rest, backup codes are SHA-256 salted-hashed, and 5-attempt lockout with 15-minute cooldown is enforced. The full audit reference — including the three-tier ownership model, all findings with fixes, and OWASP ZAP scan results — is published on the Independent Security Audit page. A detailed Salesforce vs MapFlow InfoSec comparison is also available.

UK Data Residency, AI Gating & Posture Monitoring

End-to-end UK data residency with zero CLOUD Act exposure on citizen data. The staging database and the AI inference layer are both UK-sovereign — UK-registered, UK-owned, with no US operations — bound only by UK domestic law. The only US-parent platform (Base44) is the UI/orchestration layer; it never persists client data — ciphertext transits volatile memory (RAM) only and a US production order returns app metadata only, so there is nothing for it to disclose. AI inference routes exclusively to RelaxAI (UK data centres, ISO 27001, Cyber Essentials, SOC 2) via the Sovereign Inference Shuttle; prompts and LLM keys stay on the Local Proxy and never transit Base44. The default field-mapping engine is non-AI (algorithmic, zero data shared). The AI engine is admin-gated (off by default) with mandatory InfoSec warnings when enabled.

GeoIP enforcement: admin-configurable policies for non-UK IPs, VPN/datacenter detection, timezone mismatch, and FireHOL blocklists — with a Council IP allow-list option for office CIDR ranges. Deep PII access grants: viewing decrypted citizen data requires an explicit, audited per-user permission grant with mandatory reason — self-grants email all other admins automatically. Weekly posture monitoring: automated InfoSec checks run every Monday and on-demand, emailing all admins on Critical/High violations and recording every finding in an auditable log.

Industry Standards Complied With

NIST SP 800-63B

AAL2 — TOTP-based multi-factor authentication meets Authenticator Assurance Level 2.

NIST SP 800-53

AC-12 session termination, AC-2 account management, SC-8 transmission security, SC-13 cryptographic protection.

ISO/IEC 27001:2022

A.5.16/5.17 identity & authentication, A.5.15 access control, A.8.7 malware, A.8.13 backup, A.5.34 encryption.

UK GDPR Article 25

Data Protection by Design — PII scanned and flagged at design time; non-AI default mapping engine ensures zero citizen data shared with AI providers.

UK GDPR Article 20

Right to data portability — the Script Builder exports every mapping's conversion logic as a standalone Python/Node runner or plain .sql the client can run against the source DB without MapFlow; the data and the logic leave with the client at any time. No vendor lock-in.

UK GDPR Article 28

Processor obligations — MapFlow processes data only on documented client instructions; no sub-processor outside the UK is in the citizen-data path. The only US-parent platform (Base44) carries ciphertext in volatile memory only and never persists client data.

UK GDPR Article 32

Security of processing — AES-256-GCM encryption at rest, TLS 1.3 in transit, TPM-bound master keys, per-environment key lifecycle, council-held Master recovery key.

UK GDPR Article 44

International transfers — no restricted transfer occurs. The staging DB and AI inference are UK-sovereign (no US operations); the only US-parent platform carries ciphertext in volatile memory only and never persists client data, so there is nothing to transfer.

GDPR Article 30

Records of Processing — full audit trail and execution logs.

SOC 2

Security & Availability — RBAC, MFA, session timeout, audit logging, backup, zero-trust architecture.

PCI DSS v4.0

Requirement 8 — MFA, session timeout, unique user IDs.

Note: These mappings represent the security controls implemented in the software. Formal certification requires an independent audit of the hosting environment and organisational processes.

Roadmap

All core capabilities are live and operational.

Mapping & Schema

  • Visual Field Mapper with SQL Export
  • Schema Catalogue & ERD Diagram
  • AI Field Mapping Proposals
  • AI Join Relationship Inference
  • Multi-table source mapping
  • Server-side AI analysis caching
  • Mapping Tagging & Filtering
  • Per-mapping confidence validation
  • Mapping lifecycle timestamps
  • Script Builder — standalone Python/Node runner + plain .sql export (no vendor lock-in client handoff / exit strategy)

AI & Intelligence

  • AI UAT Plan Generator
  • AI Data Quality Profiler
  • Deep PII Scan on schema metadata (admin-gated, off by default)
  • AI PII Scan on Local Table data
  • AI Mapping Assistant (NLP)
  • Non-AI reverse-engineering engine (default — zero data sharing)
  • AI field mapping engine (opt-in, admin-gated, InfoSec warnings)
  • Screen Grab → Mapper pipeline
  • Reverse-engineering with candidate records
  • Data fingerprinting & delta-checked analysis
  • Validation AI Assistant

Data & Staging

  • Local Tables with intermediate staging
  • Export Local Tables to MS Access
  • Postgres integration (dev/test/live)
  • Postgres Table Viewer with full CRUD
  • Postgres Schema Integrity Checker
  • CDC diff reports with email delivery
  • Document Library
  • Real-time data profiling

Salesforce Loaders

  • Salesforce Table Loader with DT_ID writeback
  • Salesforce Document Loader (2 GB streaming)
  • Hybrid document loading: SharePoint → Public_Share__c → Arcus, or direct to ContentVersion
  • Salesforce Notes Loader
  • Salesforce Document Bulk Loader
  • Salesforce Document Relink
  • SharePoint document sync with source metadata embedding
  • Schema Refresh Tool
  • Transformation Scheduler
  • Scheduled unattended Postgres → Salesforce loads (taskRunner-driven)
  • End-to-end overnight data transfer scheduling (refresh → transform → load)
  • Transfer modes: pre-go-live (replace), go-live (insert), post-go-live (upsert)
  • Pre-load SF metadata toggle (validation rules, Apex triggers, flows)
  • Batch failure review with per-record error drill-down
  • Admin email notifications on load failures
  • Post-Go-Live delta-only loading via watermark (no full table reload)
  • Dual-side reconciliation (source vs Salesforce change detection)
  • Reconciliation reports saved to Document Library + emailed

Document & File Tools

  • Document Audit (v5.0 with SZDD)
  • Hybrid SharePoint / Salesforce document loading with Public_Share__c
  • Local Proxy in-network compression — kills the Salesforce Storage Tax (PDFs up to 90%, images 70%+), no third-party sub-processor
  • SQL Server Utilities (File Exporter & RTF Extractor)
  • IDOX Uniform Tools (Schema Scraper, PDF Scraper, Uniface Parser, Screen Capture)
  • Tiff Flow companion tool
  • PDF Merger companion tool
  • FlowVault SFTP transfer audit
  • CLOB / large-text viewer

Security & Governance

  • Two-factor authentication (TOTP MFA)
  • Automatic session timeout
  • RBAC with row-level security
  • Audit trail & PII scanning
  • UK-sovereign end-to-end residency (staging DB + RelaxAI UK; Base44 carries ciphertext in volatile memory only)
  • AI inference routed to RelaxAI (UK-sovereign) via the Sovereign Inference Shuttle — no US AI provider
  • Zero persistence of client data on the US-parent orchestration platform
  • Zero CLOUD Act exposure on citizen data
  • Data encryption in UK-sovereign cloud database (AES-256-GCM on the Local Proxy before it reaches the DB)
  • TPM-bound master keys (TPM 2.0 via Windows Credential Guard) with corporate-vault escrow
  • Blind-index encrypted search (HMAC-SHA256)
  • Per-environment PII key lifecycle (destroyed after each phase)
  • Council-held Master recovery key (sovereign custody)
  • Least-privilege database role provisioning (superuser burned post-setup)
  • Council-provisioned sovereign database option (Council IT controls staging)
  • GeoIP enforcement with Council IP allow-list
  • Deep PII decrypted-access grants (audited, self-grant notified)
  • Weekly automated InfoSec posture monitoring with admin email alerts
  • Backup & restore (cross-app restore via Council-held key)
  • Version control & sign-off workflow
  • Merge Review system
  • Risk & Issue Log
  • Kanban Board — Trello-style drag-and-drop tracking for risks, issues, tasks & to-dos
  • Automated admin failure email alerts for unattended loads
  • SF metadata snapshot & restore (validation/triggers/flows)
  • Audited data-change control — staged, approved, overnight-applied, immutable ledger, one-click revert (no hot fixes)
  • Proactive Security Threat Register with remedial action log (identified → authorised → applied) + event-driven threat sweep on app publish + weekly structural AI review (attack-surface / brand / compliance)

Platform & Training

  • Multi-project workspace / tenant isolation
  • Live Database Connectivity (SQL Server, Oracle, SF, Access)
  • Local Proxy Agent
  • Training Environment (4 role tracks)
  • Training Sandbox (13 modules)
  • Migration Flow diagram
  • Route Analysis
  • Task Scheduler / Automations
  • Webhook / API trigger

Integrations & Support

  • Slack bot — AI auto-replies to @Mapflow mentions (real-time webhooks)
  • Slack bot — AI auto-replies to direct messages
  • Microsoft Teams bot — AI auto-replies to Mapflow mentions (scheduled polling)
  • Microsoft Teams — channel listing & message sending
  • Support ticket system with Slack notifications
  • Connector onboarding conversations with credential purging
  • Admin failure email alerts for unattended loads

Pipeline Engine (PGLite / WASM Postgres)

  • In-browser PostgreSQL 16 (WASM) — full SQL: CTAS, window functions, CTEs, JSON, regex, typed casts
  • Transactional BEGIN/ROLLBACK, atomic COPY — no corruption
  • PglitePipeline entities — ordered steps (mapper / SQL / push / drop)
  • Declared depends_on + topological graph runner (parallel waves)
  • Per-step run log (status / rows / duration)
  • Drag-to-reorder, auto-dispose of transient tables
  • Push to Postgres Postgres as the persistent store
  • Query Console with SchemaExplorer, saved snippets, PGLite/admin/REST modes
  • Deterministic profiler + PII twins run as REAL full-table SQL (no 25-row sample)
  • Replaces MS Access Jet/ACE — 2GB ceiling, single-writer, corruption-prone

AI Learning & Fine-Tuning

  • Day-one capture of de-identified training pairs (field names, types, labels — never raw citizen values)
  • Four task-specific adapters: Field Mapping, PII Classification, Schema→Purpose, Screenshot Field Detection
  • LoRA / QLoRA fine-tuning on proprietary council-migration corpus
  • Export JSONL (unsloth / axolotl / llama.cpp format) from the corpus panel
  • Serve via Civo Project Mercury (client-provisioned UK GPU) or local Ollama (air-gapped)
  • Adapter never published — base model is public, your adapter is not (the moat)
  • Idempotent capture job — re-run any time as data accumulates
  • Quality flags: gold (human-corrected) / accepted / review
  • Sovereign posture: adapter, key, and prompts all on the same host — MapFlow backend is relay only

What MapFlow Replaces — Brutal but Fair

An honest assessment of what dies, what lives, and where the legacy tools still genuinely win.

MS Access — retired

A 30-year-old single-writer, file-locked, 2GB-ceiling engine that corrupts on network shares and requires compact-and-repair as a ritual. Credentials live in plaintext connection strings inside the file. There is no upgrade path to AI — Jet/ACE and VBA predate modern integration entirely. MapFlow's in-browser PGLite gives real Postgres 16 with no ceiling, no corruption, concurrent tabs, and a declarative pipeline graph. Access is strictly weaker on every dimension except one (below).

Where the legacy tools still win

MS Access runs fully offline on a laptop with zero network — genuinely air-gapped engagements are its native strength. PGLite closes most of this gap (transforms run in-browser with no server round-trips) but the app shell and auth need a connection on first load. For a truly never-connected site, Access remains a defensible fallback — and MapFlow's offline Script Builder runner exports the logic so the client is never locked in either way. Fair is fair.

Spreadsheets — retired

Un-diffable, un-versioned, merge-conflict-prone. "Versioning" is dated file copies on a share. No audit trail — institutional knowledge leaves with the consultant. MapFlow stores every mapping as a structured, versioned, signed-off record with a tamper-evident ledger and one-click revert. There is no scenario in which a spreadsheet is the right tool for a production data migration.

The compounding moat

Every accepted mapping, PII label, and screenshot correction captured from day one feeds a fine-tune corpus that no competitor holds. The base model is public (anyone can download Llama 3); the adapter is not — it encodes thousands of council-migration patterns that only MapFlow has accumulated, on a sovereign host that never publishes it. The longer MapFlow runs, the wider the gap. This is not a feature; it is a structural advantage that compounds.

Ready to map smarter?

The core mapping, schema, AI, and governance features are fully operational. Jump in and start documenting your migration today.