Live in early access. We're onboarding the first teams now — full self-service opens soon. Request access → contact@s2stools.com

Spec 00 — site-to-site migration

What arrives
is what left.

S2Stools moves SharePoint sites 1:1 — files, lists and pages arrive with their authors, timestamps, permissions, version history and attachments intact, and the notebook comes along — measured to the byte and resume-safe, never copying an item twice.

Early access · sign-in is invite-only while we onboard the first teams

/sites/marketing · source

Shared Documents 12,480 files
contract-2024.docx v1–v12
Team Lists 34 lists
Site Pages 86 pages
Permissions 14 principals
Site Notebook OneNote

/sites/marketing-new · faithful copy

Shared Documents 12,480 ✓
contract-2024.docx v1–v12 ✓
Team Lists 34 ✓
Site Pages 86 ✓
Permissions mapped ✓
Site Notebook renamed ✓
versions ✓ authors ✓ timestamps ✓ permissions ✓

Spec 01 — process

Connect once, then three steps — no surprises at either end.

01

Connect

One admin-consent click in Microsoft's own dialog connects your SharePoint — no certificate to create, no secret to paste, revocable by you at any time. Every plan, including free dry runs. Bring your own app and certificate instead if you'd rather (Pro+).

admin consent → connected · no key to enter

02

Estimate

Tell us the size of the source and the estimate sizes the job — GB, items, compute-hours — so you know which plan covers it before anything moves.

2,000,000 items · 500 GB · ~80 compute-hours

03

Dry run

The engine walks the whole site and reports the plan — lists, pages, permissions, versions — and writes nothing.

"DryRun": true — plan only, write nothing

04

Migrate & verify

Runs are resume-safe: a restart continues where it stopped, skips what's done, and never copies an item twice. Cancel is one click, cooperative.

resume=true → completed steps skipped · cost unchanged

Spec 02 — fidelity

Version history. Authors.
Permissions. Intact.

Most tools move files. S2Stools moves the record — the metadata trail your compliance team actually cares about.

Version history

Version chains on documents are replayed oldest-to-newest, each version carrying its original date and label.

File.Versions → replayed v1…vN

Authors & timestamps

Created/Modified and Created by/Modified by survive the move on every file, page and list item — not replaced by the migration account.

system fields stamped · no version bump

Item-level permissions

Broken-inheritance items keep their own grants; site groups and M365 group claims are remapped to the target.

principals mapped source → target

Attachments

List-item attachments travel with their items, added before the final metadata stamp so dates stay true.

AttachmentFiles copied per item

Navigation & notebook

Quick launch arrives without duplicate or dead links, and the site notebook is renamed for its new home.

system links stripped · notebook retitled

Managed metadata

Taxonomy columns, content types, and term groups are extracted together so nothing is silently dropped.

Fields + ContentTypes + TermGroups

Spec 03 — pricing

Priced up front,
not from a sales call.

Flat monthly plans, each with a clear allowance — GB moved, compute-hours, items. Every run's usage is measured and shown under Usage & allowance, so you always know where you stand. Resumed runs are deduplicated at two layers, so the same work is never copied or counted twice.

Free / Trial

$0/mo

  • 20 dry runs / month
  • Full site inventory
  • Exact cost estimate
  • Previews only — upgrade to migrate
Request access

Business

$199/mo

  • 500 GB included
  • 120 compute-hours
  • 5 concurrent runs
  • Priority queue · customer-managed keys
Request access

Enterprise

$999/mo

  • 2,000 GB included
  • 600 compute-hours
  • 20 concurrent runs
  • Customer-managed keys
Talk to us

Each plan's allowance covers one billing period. When a run reaches it, it pauses where it left off — add a +100 GB pack ($39) to keep going (paid plans). Dry runs are always free and never count against your allowance. Set a per-run budget and the run pauses before it passes it.

Spec 04 — isolation

Your tenant is a wall,
not a row filter.

  • We hold no keys. The default way to connect is one admin consent — we store only your tenant id and the fact of the grant, never a secret or certificate of yours, and you revoke it from your own Entra portal. Prefer your own app and certificate (Pro+)? The private key stays in a Key Vault you control.
  • One storage container per tenant. Run artifacts never share a container; isolation is enforced at the storage boundary, not just in queries.
  • Secrets never travel inline. Even on the bring-your-own path, the API rejects any spec carrying a raw secret — credentials are a Key Vault reference, never pasted.
  • Entra ID sign-in. Your directory is the front door: first user provisions the tenant, roles map to scopes, API keys are scoped and revocable.

// the API, refusing a pasted secret

POST /v1/migrations
→ 422 Unprocessable Entity

"Source.Auth.ClientSecret.ClientSecret:
 inline secrets are not accepted —
 use a Key Vault reference."

Be one of the first teams in.

We're live and onboarding early-access customers now. Estimate is free, the dry run writes nothing, and pricing is a simple monthly plan — top up with a pack only when you need more.