Civis Analytics civis.ai migration · Findings
Civis Analytics

Moving Civis to civis.ai

The reconnaissance is done. Eleven systematic sweeps across DNS, email, Pardot, the live site, our code, public registries, and three weeks of meetings. This page is what we found, what it means, and the two decisions that size the whole project.

Prepared forLeadership review
StatusReconnaissance only. Nothing in any live system was changed
DateAugust 26, 2026
Reading timeAbout ten minutes, scanning
1. Summary

This is four projects wearing one name

They run at four different speeds, and the plan has to respect that. Every number on this page traces to a named source; anything unverified says so and is listed in section 14.

The website · fast and safe

Days of work once Cloudflare is stable

The Cloudflare rebuild approved on August 10 does most of the work. Pointing civis.ai at it and running permanent redirects from civisanalytics.com is configuration, and every step of it can be undone. Google already shows the query "civis ai" earning clicks at average position 2.0 with nothing live there.

Email · slow and dangerous

The big conversation, confirmed

Our mail stack is deeper than any plan knew: a Cloudflare Email Security gateway filters inbound mail before Google sees it, six vendors send as us, and our SPF record sits at 8 of a hard limit of 10 DNS lookups. A new domain starts with zero sending reputation and has to be warmed slowly on a protective subdomain. This lane needs weeks of calendar time and an owner it does not currently have.

The product · does not move

Customer-facing systems stay on civisanalytics.com

The platform login, the API that every customer's code calls, customer VPNs, and single sign-on all live on the old domain. The published Python SDK hardcodes the API hostname into every copy customers have ever installed. Moving any of it is an engineering project on customer calendars, and the rebrand does not require it. So the old domain never fully retires: it keeps DNS, mail authentication, and redirects indefinitely.

The paperwork · open

Two decisions size everything

First: does the legal entity name change, or only the domain? No meeting or document on record has discussed it. Second: does Google Workspace adopt civis.ai as its primary domain, or carry it as an alias? The alias path is reversible and incremental; the primary swap renames every user and everything keyed to their addresses. Both decisions belong to leadership, and both are answered "unknown" today.

8 of 10
DNS lookups already used by our SPF record. Going over the limit breaks all mail silently
DNS resolution, Aug 26
135 of 135
Pardot email templates that reference the old domain, 132 in the sender itself
Pardot API audit, Aug 26
100%
of released Python SDK copies call api.civisanalytics.com by default, forever
Published SDK source, v2.9.3
Dec 2027
civis.ai paid up through, at Namecheap. Expired .ai names go to auction fast
RDAP registry lookup, Aug 26
One collision found early, which is the good outcome. Engineering is shipping a white-label URL feature right now that changes which hostnames serve customer reports, and someone provisioned wildcard certificates for civis.ai in June that this project knows nothing about. Two domain projects are live at once with no recorded coordination. One conversation fixes it, and it should happen before any plan gets a date.
2. What moves and what does not

Every surface found, in one table

The spine of the document. Eleven sweeps produced this inventory; the risk column is about what happens if the surface is handled wrong, and "out of scope" means the recommendation is to leave it alone in this project.

SurfaceTodayTargetOwnerRisk
Marketing websiteWebflow, moving to Cloudflare Pagescivis.ai primary, old domain redirects permanentlyMarketingLow
civis.ai domainParked at Namecheap, expires Dec 2027, unexplained certificates issued in JuneLive primary domain with named renewal ownerNeeds an ownerMedium
Corporate emailOld-domain addresses, security gateway in front of Google, strictest DMARC policyAlias or primary decision, then dual domains kept for yearsLeadership + email adminHigh
Marketing email (Pardot)Sends as the old domain; two live tracker domains; all 135 templates reference itNew warmed sending subdomain, new tracker, updated templatesMarketingHigh
Third-party sendersSix vendors authorized to send as us, plus five unattributed IP blocksKeep, move, or retire decision per sender on the new domainNeeds an ownerHigh
Platform, API, VPN, SSOAll on old-domain hostnames customers have hardcodedDo not move in this projectEngineeringOut of scope, flagged
Help centerZendesk on a old-domain subdomain, years of indexed articlesLater host mapping; vendor fallback existsMarketing + supportLow
Status pageAlready broken: inactive page and a certificate error, todayFix or retire regardless of the migrationNeeds an ownerBroken now
Forms and redirects in Pardot44 form success redirects, 29 landing page redirects, 26 vanity destinations point at the old siteUpdate after web cutover; old links keep working through redirectsMarketingMedium
Analytics and consentTwo tag manager containers, one analytics property, consent tool licensed per domainNew domain added to consent license, containers audited, measurement kept clean through the moveMarketingMedium
Code and templates in our reposCanonical email wrapper, blog pipeline, about 30 send scripts, and the new site's own config stamp the old domainCutover-day sweep list, already writtenMarketingMedium
Public artifactsPython and R packages, 83-repo GitHub org with a verified domain, social profiles, Wikipedia, CrunchbaseRolling metadata updates; one package registry requires a living maintainer addressEngineering + marketingMedium
Campaign micrositesFive marketing subdomains on the old zoneCase by case; most stay or retire quietlyMarketingLow
Legal and complianceFedRAMP records, DPAs, an active procurement questionnaire, and a partner certification all name the current identityDepends on the entity-name decisionLeadershipHigh, unscoped
Brand collateralSignatures, decks, one-pagers, video bumpers, business cardsRolling refresh after cutoverMarketingLow
3. The website

Already planned. The hostname adds four items

The Webflow to Cloudflare rebuild has its own approved plan and is nearly staged. Only what changes because the hostname changes is listed here.

Good news

The SEO rewrite surface is small

A full crawl of all 131 live pages found zero structured data and zero og:url tags. The rewrite is canonicals, the sitemap, 32 absolute self-links, and 8 form redirect attributes. Social card images live on a third-party CDN and survive untouched.

Found in the new site's own code

The rebuilt site still points home to the old domain

The new site's config defaults its canonical origin to the old hostname, 78 absolute internal links carry it in content, and 92 pages still hotlink assets from the old platform's CDN, which dies if that subscription is cancelled. All three are on the written cutover sweep list.

Cleanup at the same time

Things that should not carry over

Two draft pages are publicly crawlable, three password-protected pages sit in the public sitemap, one press release still links to itself over plain http, and two different help center hostnames are used interchangeably in blog posts. The move is the moment to drop all of it.

Drift since the master plan

The apex records changed in August

The bare domain now resolves through CloudFront where the master plan recorded a single address. Someone changed apex hosting after August 3. Confirm who and why before cutover planning trusts the older document.

4. Email

The section that did not exist, and the one that can do real damage

The master plan contains zero mentions of MX, Google Workspace, SPF, DKIM, or DMARC. This section is the missing plan, built from what the mail stack actually looks like.

Discovery

A mail gateway nobody documented

Inbound mail does not go to Google first. It passes through Cloudflare Email Security, a filtering gateway confirmed from our live MX records against the vendor's own documentation. A civis.ai mail cutover has to be provisioned inside that tenant, inside Google, and in DNS, in the right order.

Discovery

Six vendors send mail as Civis

Google, the support desk, the marketing platform, the CRM, the ticketing suite, and the status page are all authorized senders on the current domain, plus five raw IP blocks nobody has attributed. Each one needs a keep, move, or retire decision on the new domain, and each costs DNS lookups we barely have.

Constraint

The SPF budget is nearly spent

The record sits at 8 of a hard limit of 10 lookups, and one provider has changed the shape of its record before, so real headroom is one. Recreating today's setup on civis.ai leaves no room for growth. The answer is the subdomain split described below.

Alias first: the recommended path

What happens
civis.ai is added to Google Workspace as a secondary domain. Every person gets a new address that delivers to their existing mailbox. Mail history, calendars, files, and logins do not move, because nothing moves.
Why it fits
It is reversible, it can be done person by person, and it satisfies the standing requirement to run both domains with everything retained: both addresses are one mailbox, so there is nothing to forward and nothing to lose.
What it defers
The primary-domain swap, which renames every account, stays available later, once someone owns email administration and the identity fallout has been inventoried.

Warm-up: the part that cannot be rushed

The problem
A brand-new domain has no sending reputation. Bulk mail from it goes to spam until mailbox providers learn to trust it. This was named in the August 10 leadership discussion as the way companies really hurt themselves.
The plan shape
Bulk marketing mail gets its own subdomain of civis.ai with separate authentication, protecting the primary domain. Volume ramps gradually, most engaged audiences first, over a period of weeks. Cold-list campaigns stay on the old, trusted identity until the new one has history.
The gate
Reputation damage does not roll back. Monitoring starts on day one, on both domains, before the first send.
What survives, stated plainly. Message history and calendars survive either Workspace path. Old addresses keep receiving for years, because customers, contracts, and package registries know them. The old domain keeps its mail authentication records permanently. The strictest-policy setting on the current domain stays untouched until the very end, and the new domain starts at the loosest policy with monitoring, tightening only after weeks of clean reports.
5. Domain and DNS

The domain is healthy. The ownership around it is not

Registry facts verified against the registry operator, registrar documentation, and a live registry lookup on August 26.

FactValueWhat it means
RegistrarNamecheap, with privacy-redacted contactsNot the same place as our DNS. Who holds the account login is unknown and needs answering this month
Registered / expiresDecember 2023 / December 2027Paid up. Renewals run on two-year cycles, the .ai minimum
RegistryAnguilla's country domain, operated since January 2025 on a standard backendTransfers, lookups, and DNSSEC now behave like mainstream domains; the manual-era quirks ended
Expiry behaviorExpired .ai names feed daily auctionsA lapsed renewal likely means permanent loss of the brand. With no IT function, renewal needs a named owner
DNSRoute 53, zone empty apart from delegationClean slate. Open choice: build the zone in Route 53 alongside our other domains, or move it to Cloudflare next to the hosting
CertificatesTwo wildcard certificates for civis.ai were issued this June via AWSSomeone with AWS access provisioned them for an unknown purpose. Identify who before assuming this project has the only hands on the domain
Before each cutover

Lower the timers

Records that will change get short lifetimes a day ahead, so a mistake reverts in minutes and the change itself lands fast.

Permanent residents

What we keep paying for

The old domain's registration, its DNS zone, and the redirect layer stay forever. The product, VPN, support desk, and historical email links all live there, so it was never a candidate for retirement.

Do not confuse

civis.io is a different thing

It is the live marketing link-tracking domain, in production, serving nearly a thousand hosted assets. It stays exactly as it is.

7. Marketing automation and analytics

Counted object by object against the live account

A read-only audit of the full marketing automation library, plus the analytics stack the crawl actually observed.

ObjectTotalReference the old domainAction
Email templates135135Update wrappers and senders once the new sending domain is live and warmed
Sent emails1,8011,772History, immutable. Their tracked links must keep resolving forever
Forms6245All 44 configured success redirects point at the old site; update after web cutover
Landing pages4729Same treatment as forms
Vanity redirects5426Update destinations; the short links themselves keep working
Hosted files9661Nearly all served from the tracker domain that is not changing. No action
Tracker domains31Add and validate a civis.ai tracker. Never delete the old ones
Blind spots

What the API cannot see

Completion actions, form error pages, automation rules, and the preference center are invisible to the API and need a by-hand audit in the marketing platform's own interface.

Surprise

Two tag containers, not one

Every page loads two tag manager containers where the plan knew of one. Both need a hostname audit before cutover, and consent-gated tags need the consent tool to cover the new domain first.

Continuity

History survives

The analytics property, search data, and sent-email statistics all stay attached to their accounts. What needs care is the overlap window: measurement configured so the two hostnames do not double-count while both are live.

8. Product, API, and customer-facing surfaces

Nothing a customer touches should move

The strongest single finding of the reconnaissance, and the recommendation that keeps this project safe.

The API hostname is baked into customer code

The published Python client defaults every request to the API on the old domain, in every version ever released, on every machine it is installed on. The R client and the MCP server inherit the same dependency. Customer scripts, scheduled jobs, VPN configurations, single sign-on setups, and login bookmarks all point at old-domain hostnames. Each breaks on a customer's calendar, and each is owned by engineering.

So the recommendation is scope discipline: the brand, website, and marketing systems move; the product does not. Anything that would require a customer to act becomes a communication project with lead time, run by engineering, on its own schedule, if it ever runs at all.

Coordination required

The white-label URL feature is a second domain project

Engineering is currently shipping a feature that serves customer reports on the customers' own domains, top of the roadmap and expected around now. It reworks the same hostname layer this migration touches, and no meeting or document connects the two efforts. One conversation aligns them; it should happen before either ships.

Already broken, found in passing

The status page is down today

The public status page serves an inactive notice with a mismatched security certificate, before any migration work. Worth fixing or retiring on its own merits, and a reminder of what unowned infrastructure looks like.

10. Brand and collateral

A rolling refresh, with one calendar constraint

None of this gates the cutover. All of it needs a checklist so nothing ships with the old name after the new one is live.

Owned surfaces

Templates and signatures

Email signatures for every person, the canonical email wrapper, the registration page template, slide decks, one-pagers, video bumpers, and business cards. The wrapper and registration templates are already on the cutover sweep list; the rest is a rolling refresh.

Public profiles

Social and reference listings

The company pages on the major networks, the video channel, the encyclopedia entry, and the business databases that feed search knowledge panels all list the old site. Handles are verified; the website fields need a by-hand pass after launch.

Calendar constraint

Certification and a possible customer summit

The partner logo work lands in the same window as this project, and a customer summit is being discussed for November or December. Anything printed or announced for either should carry whichever name will be true on the day, which argues for deciding the naming question before the fall events are locked.

11. People and communication

Who is told what, when, by whom

Roles only on this page; the named version lives in the internal findings document.

AudienceWhat they hearWhenFrom
LeadershipThis report, the two sizing decisions, and the risk registerNowMarketing
EngineeringProduct hostnames stay put; white-label coordination; the June certificate question; an inventory ask for identity and VPN surfacesBefore any plan gets a dateMarketing via leadership
Email administrationThe lane cannot start until someone owns the mail tenant and Workspace. There is no IT function today and HR is coveringA leadership decision, nowLeadership
StaffNew addresses arrive as aliases, both addresses work, signatures update on a scheduleWhen the email lane startsMarketing + HR
CustomersNothing technical changes for them. A brand announcement, with account teams briefed for named accountsCutover weekMarketing + account management
PartnersBrand change notice; the certification partner hears first, before any public changePre-launchLeadership and sales, by relationship
12. Cost

Mostly time. The cash items are small and two are unverified

No figure on this page is invented. Where the real number is not in hand, it says unverified, and pulling the invoice is the action.

One-time

Time, in the quiet window

The web lane fits the December to January window the marketing calendar already reserves. The email lane is calendar-elapsed warm-up time more than labor. Legal review, if the entity question goes anywhere, is unpriced and needs counsel.

Recurring

Renewals and licenses

The .ai renewal at two-year cycles, next due December 2027, price unverified. The old domain and its DNS zones continue indefinitely, already paid today. Whether the consent tool and the workspace plan absorb the new domain without new line items is unverified; both invoices need checking.

Offsetting

What stops being paid

The old website platform's subscription ends after the transition, per the standing decision to keep it during the overlap. Its actual cost is on record twice with conflicting units and stays unverified here. Pull the invoice before any savings figure goes in a deck.

13. Risk register and rollback

Ranked by damage. Four cannot be undone

A gate is something with no rollback: it is prevented, never repaired. The four gates shape the plan's sequencing more than any preference does.

#RiskDamageHow we detect itUndo
1New-domain sending reputation burned by warming too fast or cutting bulk mail over coldThe whole email program lands in spam for monthsMailbox-provider reputation tooling enrolled on day one, on both domains, plus bounce and open monitoringNo. Gate. Prevention is the plan
2Breaking live mail on the current domain while adding records: the lookup limit, a bad policy edit, an MX mistakeCompany-wide mail bounces silently under the strictest policyBefore-and-after record diffs, staged changes, header spot checksConfig reverts in minutes; messages rejected in the window are gone. Gate: two-person review on any mail-record change
3Certification disrupted by renaming mid-reviewLogo rights and the fall webinar anchor slipOne question to the partner manager, asked before anything public changesNo, within the window. Coordinate or wait
4Losing the domain itself: unknown registrar account owner, no renewal owner, 2027 renewalThe brand goes to auctionRegistry expiry watch; find the account owner this monthNo, after the grace period lapses
5Workspace primary-swap fallout, if that path is chosen over aliasExternal identities keyed to old addresses break piecemeal, including a package registry that can archive our client library over a dead maintainer addressIdentity inventory before any swapPartial only
6Mail lost in the MX cutover windowIndividual inbound messages vanishDual delivery verified before the change, test matrix duringNo, per message. Gate
7Collision with the white-label URL featureTwo incompatible domain architectures ship at onceThe coordination conversation, held nowYes, if caught before either ships
8SEO dip deeper than modeledBranded traffic slow to re-associateWeekly search data against the recorded baselineYes. Redirects stay, recovery is time
9Consent or measurement gap at launchCompliance exposure, and blind analytics in the one window that needs themPre-launch checklist on the staging siteYes, though lost data stays lost
10Old tracked links rot if the old tracker domain or redirect layer is ever removedLinks in 1,801 sent emails and years of collateral dieA written keep-forever listYes, by never removing them
14. Open questions and assumptions

Every gap, phrased so a human can correct it in one line

This section is a feature. Each item names the assumption made and who can settle it.

01

The legal entity stays as it is; only the domain changes

If wrong: a legal workstream appears and this report undercounts the project. Needs leadership, probably with counsel.

02

Workspace goes alias-first; a primary swap, if ever, is a later decision

Needs: a leadership yes, and a named email administrator to carry it.

03

Who holds the registrar account for civis.ai?

Why it matters: renewal and transfer control live there, the record is privacy-redacted, and the historical DNS handover was informal. Answer this month.

04

Who issued the June wildcard certificates for civis.ai, and why?

Why it matters: someone with cloud access already has plans or leftovers touching this domain. Ask engineering.

05

Who administers the mail gateway and Workspace today?

Current answer on record: nobody; HR is covering IT. The email lane has no start date until this has a name.

06

The five unattributed IP blocks in the mail record are legacy and may not need recreating

Needs: someone who remembers the history to confirm what sends from them.

07

Product hostnames are out of scope, and engineering agrees

Needs: engineering confirmation, in the same conversation as the white-label coordination.

08

Public renaming waits for, or is cleared with, the certification partner

Timing on record: mid-September and October 1, from two different meetings on the same day. Leadership owns the conversation.

09

The consent tool and workspace licenses absorb the new domain at no new cost

Action: check both invoices. Marked unverified in section 12.

10

The old website platform's real cost is still unverified

Action: pull the subscription line before any savings claim goes in front of leadership. Two conflicting figures are on record.

11

A fall customer summit, if it happens, is either the launch moment or the reason to wait

Needs: a scheduling decision once the summit itself firms up. Nobody has connected the two yet.

12

Backlink outreach is deliberately unscoped

Why: permanent redirects carry the link equity meanwhile; outreach is a post-launch nicety, done with tooling not yet authorized.