Security & data handling
What we access, how we protect it, and what we deliberately don't do.
Built on Salesforce's own security model
We connect through Salesforce's own OAuth authorization flow — the same security boundary Salesforce uses to protect every connected app. You approve exactly what's shared, read-only, and we never see or store your password. You stay in control: access can be revoked at any time from your own Salesforce Setup, independent of us.
Who can actually see your results
Your report is tied to the account that connected your org and shown only through that account's own authenticated login — never a public link, never visible to any other customer. The connection credential itself is encrypted at rest, not stored in plaintext.
What we actually store
We store the structural findings needed to build your report — configuration, metadata, and usage patterns — not your underlying business records or customer data. We don't share or sell your assessment results.
Independent assessment
This is an independent product, not affiliated with or endorsed by Salesforce, Inc.
Questions
Have a specific security or data-handling question not covered here? Contact us directly.