Your Salesforce metadata is production data. We treat it that way.
Salesforce OAuth tokens are encrypted via Supabase Vault (pgsodium) before they hit the database. Decrypted only at the moment of an API call — never persisted in plaintext, never sent to the browser.
Every table in OrgBolt's database enforces Postgres RLS scoped to your workspace. Even with direct database access, one workspace cannot read another's data.
OrgBolt uses Anthropic's Claude on the API plan. Anthropic never trains on your data — that's contractual — and deletes API inputs and outputs within 30 days (retained longer only if flagged for usage-policy enforcement).
Tokens are revoked via Salesforce on account deletion and cleared from the database when you disconnect an org. The server decrypts tokens per-request; no token ever reaches client-side code — the database role browser sessions use is granted no access to the token vault, not even to the reference that points at it.
Production deploys default to checkOnly validation. OrgBolt refuses to deploy to production without a prior validation pass — you see every error a real deploy would hit before committing anything.
Every deploy, login, member invite, and significant action is logged and retained for 7 years. On account deletion, audit logs are anonymized (user_id nulled) but preserved for compliance.
Every paid workspace can provide its own Anthropic API key. Your key is stored in Supabase Vault (pgsodium, encrypted at rest) and used exclusively for your workspace's AI calls.
Flows deploy as Draft — OrgBolt never auto-activates a flow it creates; you review and turn it on yourself in Salesforce Setup. And nothing reaches your org without an explicit Deploy click.
OrgBolt sends your chat messages to Anthropic for AI inference. Here is exactly what that means for your data.
| Provider | Model | Training on your data | Data retention | Policy |
|---|---|---|---|---|
| Anthropic | Claude (Sonnet / Haiku) | No training on API data | Deleted within 30 days | Privacy Policy |
Every vendor that touches your data, what they access, and where they operate.
| Vendor | Purpose | Data accessed | Location |
|---|---|---|---|
| Supabase | Postgres database, Auth, RLS enforcement | All application data | US |
| Anthropic | AI inference (Claude API) | Chat messages (inference only, deleted within 30 days) | US |
| Hetzner | VPS hosting | Infrastructure — all data in transit | US (Ashburn, VA) |
| Cloudflare | DNS, tunnel routing, bot protection | HTTP requests, Turnstile tokens | Global CDN |
| Lemon Squeezy | Payment processing, subscription billing | Email, payment method (via Stripe underlay) | US |
| Resend | Transactional email delivery | Email address, email content | US |
Every request to OrgBolt passes through five layers of protection. No ports are exposed on the server — all traffic routes through Cloudflare's encrypted tunnel.
HTTPS-only, Turnstile bot protection, HttpOnly auth cookies
No exposed ports on the VPS — all traffic routes through an encrypted Cloudflare tunnel
Cookie-based session refresh, auth gates on every protected route, Server Action re-authentication
Row-Level Security on every table, workspace-scoped policies, encrypted OAuth tokens (Supabase Vault / pgsodium)
API plan — zero training, 30-day deletion. BYOK support for paid workspaces
OrgBolt uses Anthropic's Claude — primarily Sonnet for task work and Haiku for lightweight operations like title summarization. All inference is on Anthropic's API plan: your data is never used for training and is deleted within 30 days.
No. Anthropic never uses API data for model training — that's contractually guaranteed by Anthropic's commercial terms. Prompts and responses are deleted within 30 days; Anthropic retains flagged content longer only to enforce its usage policy.
Application data is stored in Supabase (Postgres) hosted in the US. The OrgBolt server runs on Hetzner in Ashburn, Virginia. All traffic is routed through Cloudflare's encrypted tunnel — no ports are exposed on the VPS.
Yes. Settings → Delete Account starts a 30-day soft delete (data hidden immediately, restorable within 30 days, then hard-deleted by a scheduled job). Salesforce OAuth tokens are revoked immediately — not after 30 days. You can also export all your data before deletion via Settings → Data Export.
Not yet. OrgBolt is a new product and has not undergone a SOC 2 Type II audit. We enforce strong defaults (RLS on every table, OAuth token encryption via Supabase Vault, 7-year audit trail, no-training AI) and document our security architecture transparently. SOC 2 is on the roadmap for when the customer base warrants the investment.
OrgBolt supports GDPR Article 15 (access), Article 17 (erasure), and Article 20 (portability). Data export is self-serve. Account deletion is self-serve with a 30-day grace period. Audit logs are anonymized (user_id nulled) after deletion.
OrgBolt connects via a standard OAuth Connected App. The OAuth scope includes API access for describe calls (reading metadata) and deploy operations. The Work phase never invokes a write endpoint — deploy is the only phase that writes, and it always asks first.
OrgBolt reads org metadata (object definitions, field descriptions, permission sets) to understand your org structure. It caches that metadata in OrgBolt's database (workspace-scoped, RLS-protected) so it isn't re-fetched on every question. Record data — Accounts, Contacts, cases, and every other business record — sits behind a separate consent gate that is off by default. Any workspace member can grant record-data access for one org from the orgs page and revoke it at any time, and every grant and revoke is written to the audit log with the actor, the timestamp, the IP address, and the user agent.
Start free — no credit card required. Questions about enterprise security? We're happy to help.