Skip to main content
Trust & Data Protection

Trust & Data Protection

Transparency about which data we read, how it is handled, and your GDPR rights.

Consistent & Repeatable

The assessment is powered entirely by our analysis framework. No AI writes the scores and no subjective judgment changes the outcome. Every criterion is rule-based, so the same org produces the same result when analysed under the same conditions. That keeps findings transparent, auditable, and comparable over time.

We read metadata and platform configuration: data model, Apex code, flows, automation, and permissions, not your business records. Field fill rates are calculated using aggregate COUNT queries; no individual record values are ever retrieved.

Full scope: What we review

Transparency note: The User Health module reads user account records, which are personal data under GDPR, covering identity, login-activity, and security-setting fields such as name, email, last login date, and MFA status. If your Data Protection Officer objects to it, the User Health module can be excluded from the analysis on request.

  • Your access token is held in memory only during the analysis, never written to disk or transmitted elsewhere
  • Your metadata is only read through read-only API calls and processed in memory, never stored on our side

Processing is based on Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in providing the contracted service). Data minimisation is applied throughout: only the metadata necessary for the analysis is queried.

A Data Processing Agreement (AVV/DPA) is available on request. Contact us before we begin if your organisation requires one.

If your DPO objects to the inclusion of user personal data, the User Health module can be excluded from the analysis scope.

Metadata is processed locally in our analysis environment and never uploaded to cloud services, third-party APIs, or external servers.

We only issue read-only GET requests against the Salesforce REST and Tooling APIs. We never create, update, or delete any records, metadata, or configuration in your org.

The External Client App requires only two OAuth scopes:

  • api: read-only access to REST and Tooling API endpoints
  • refresh_token: ensures the analysis can be completed without session timeout interruption

No deploy, write, or admin scopes are requested.

We read the configuration behind every screen: layouts, Lightning pages, flows, and permissions, directly through Salesforce's official APIs. Reading the metadata is more complete and more objective than clicking through the interface, so a read-only integration user with no interactive login is all the analysis needs. The lack of UI access is intentional, not a gap in coverage.

You maintain full control over the connection at all times. Revoke access from Setup → External Client Apps whenever you choose. We recommend keeping access until we have reviewed the results together; in rare cases a follow-up review may be useful at no additional cost. After that, you can deactivate or delete the integration user to remove all access permanently.