Salesforce AppExchange Partner
🛡️ Data Guardian Trust Center
Last Updated: July 2026
Our Security Commitment
Data Guardian is committed to protecting the data of our customers. We follow industry-standard security practices to ensure your Salesforce data remains private, secure, and accessible only to authorized users. This page outlines our security posture for the Salesforce AppExchange Security Review.
Data Storage & Encryption
- Encryption in Transit: All data transmitted between your Salesforce org and our backend services is encrypted using TLS 1.2+ protocols. All API calls are made over secure HTTPS.
- Encryption at Rest: We rely on Salesforce's native encryption capabilities for data stored within Salesforce objects. No sensitive data (Emails, Phones, Addresses) is persisted in external databases outside of Salesforce.
External API Integrations (Data Processing)
Data Guardian sends data to the following trusted third-party services strictly for the purpose of data validation:
- Email Validation: We send emails to HRPVerify to validate syntax, domain existence, and spam-trap risk. No emails are stored permanently.
- Address Validation: We send physical addresses to EasyPost to verify deliverability.
No data is shared, sold, or used for marketing purposes. All processing is ephemeral and occurs in real-time.
Access Control & Permissions
- All users must be explicitly assigned a Permission Set within Salesforce to use Data Guardian.
- Access to the backend API keys is stored securely using Salesforce Custom Settings (Protected) and never exposed to the client-side.
- We follow the Principle of Least Privilege (PoLP). The extension only requests the minimum permissions required to read/write Health Score fields and create Tasks.
Data Retention & Deletion
- We do not store your Salesforce data in external databases.
- If an integration is removed or uninstalled, no external data remains. You can delete all Data Guardian fields and tasks directly from your Salesforce org at any time.
- Backend logs (if any) are automatically rotated and deleted after 30 days.
Incident Response & Contact
In the event of a security incident, we will notify affected customers within 72 hours and follow the standard Salesforce AppExchange reporting procedures.