We don’t just integrate platforms. We build them.
Avalon is a services-and-products firm. The engineering discipline we sell in engagements — non-destructive by default, governed, audit-friendly — also ships in our own tools: open-core where it makes sense, self-hostable always.
EMaigrator
- Open-core · Apache-2.0
- Available now
- Self-hostable
A non-destructive, streaming, self-hostable engine for migrating mailboxes between AWS WorkMail, Microsoft 365, and Google Workspace. It copies a mailbox provider-to-provider — folder structure, flags, and original dates preserved — without ever modifying the source or writing message bodies to disk.
Built for the people who run migrations: IT admins consolidating or replatforming one organization, and MSPs and consultants moving hundreds of mailboxes across clients — batch mapping, CSV import, and bring-your-own OAuth included. There is no separate “pro” mode.
Design guarantees
- The source mailbox is opened read-only. Nothing on it is ever deleted, moved, or rewritten.
- Body persistence is structurally impossible: the message envelope has no body field, and a schema test fails the build the moment a forbidden column appears.
Spec sheet
- Read-only source — nothing at the origin is deleted, moved, or rewritten
- Streaming pipeline — message bodies are never persisted to disk
- Idempotent & resumable — a per-message identity ledger means re-runs never duplicate
- Reconcile mode — diffs source against destination and copies only what's missing
- Read-only preflight scan — credentials, connectivity, and structural limits checked before data moves
- IMAP, Microsoft Graph, and Gmail API connectors
- Live progress dashboard (SignalR) and a CLI for headless runs
- Per-tenant provider rate limits and a downloadable PDF migration report
- One docker-compose stack: Postgres, RabbitMQ, Redis, API, workers, web UI
.NET 10 · MassTransit + RabbitMQ · PostgreSQL · Redis · React 19 · Apache-2.0 (open-core engine)
Prebuilt images: Docker Hub
Open source · Apache-2.0/available now, self-hostable
Mirsat
- Private beta · invite-only
- In active development
- Managed service
A multi-cloud container console that replaces tab-juggling between the AWS, Azure and GCP consoles with one interface for discovery, logs, deploys, env vars, rollback and container exec. Every change is written as a commit to a state repository the customer owns, so rollback is a git revert and the audit trail exists by construction rather than by discipline.
Built for small engineering teams — roughly one to ten people — running containerized workloads on managed cloud runtimes who would rather not learn three cloud consoles to ship, and who need a junior engineer to be able to deploy without holding console credentials.
Design guarantees
- Onboarding is least-privilege: the starting policy lets Mirsat verify identity, list services and read logs. No write, deploy, or secret access is granted.
- The customer's state repository is never force-pushed. Every write takes an advisory lock and writes an audit row, and CI fails the build if a force-push appears.
- Manual edits to committed state are detected and held for review in the dashboard before anything is applied.
- Exec shipped with recording and RBAC together — there is deliberately no mode that execs without recording.
Spec sheet
- Discovery and live log tail across six runtimes — ECS, Azure Container Apps, Container Instances, ACA Jobs, Cloud Run and Cloud Run Jobs
- Deploy, roll back and edit environment variables on AWS ECS; Azure and GCP write support is roadmap, not shipped
- Browser exec into a running ECS task, owner/admin only, with full session recording and replay
- Every change committed to a customer-owned GitHub state repo — rollback is git revert plus apply
- Brownfield adoption of workloads that already exist, plus read-only drift detection against the last commit
- Multi-tenant isolation enforced at the database by Postgres row-level security
- Audit log of every write action, filterable, with streaming CSV export
- Deploy API tokens for CI/CD, with a worked GitHub Actions example
- Cloud credentials envelope-encrypted at rest under a per-org data key sealed by KMS
.NET 10 · React 19 · PostgreSQL 16 + RLS · SignalR + Redis · Auth0
Proprietary · closed beta/invite-only while we harden it
Tell us what'skeeping you upat night.
Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.