How we protect your data and your Salesforce org, on every engagement and in the products we ship.
VP Solutions works inside our clients' Salesforce orgs and builds Salesforce-native software. We treat the access we are given as a responsibility, and we keep our footprint small on purpose.
This page sets out how we handle data and access. If you need more detail, a data processing agreement, or a completed security questionnaire, we are happy to provide it.
Our engagement work and our native products run inside your Salesforce environment. When a project needs to move data, we scope it with you and keep what leaves to a minimum.
We request only the access a piece of work needs, scoped to it and removed when it ends. Named users with multi-factor authentication, not shared logins.
Connections to your systems use encrypted transport (TLS). Any credentials we hold are kept in a password manager, never in plain text or shared documents.
The people on your engagement are the architects and developers doing the work. We do not pass your access to undisclosed third parties.
When an engagement ends, we hand over documentation and remove our access, retaining only what we are contractually required to keep.
Our products run on Salesforce and inherit the platform's security and compliance posture. Salesforce documents its certifications and real-time system status on its trust site.
SF Cleaner runs entirely inside your org and is built to support GDPR and CCPA obligations, with a full audit trail of what was deleted or masked. For products we publish on AppExchange, we complete Salesforce's security review before listing.
If you have a security question, or want to report a vulnerability, write to us and a real person will respond.
[email protected]