Security at OrgBolt

Your Salesforce metadata is production data. We treat it that way.

Vault
Encrypted at Rest
Zero
AI Training
Every Table
Row-Level Security
7 Years
Audit Trail

How we protect your data

Encryption at rest

Salesforce OAuth tokens are encrypted via Supabase Vault (pgsodium) before they hit the database. Decrypted only at the moment of an API call — never persisted in plaintext, never sent to the browser.

Row-Level Security on every table

Every table in OrgBolt's database enforces Postgres RLS scoped to your workspace. Even with direct database access, one workspace cannot read another's data.

No AI training, short retention

OrgBolt uses Anthropic's Claude on the API plan. Anthropic never trains on your data — that's contractual — and deletes API inputs and outputs within 30 days (retained longer only if flagged for usage-policy enforcement).

OAuth token security

Tokens are revoked via Salesforce on account deletion and cleared from the database when you disconnect an org. The server decrypts tokens per-request; no token ever reaches client-side code — the database role browser sessions use is granted no access to the token vault, not even to the reference that points at it.

Validate-first deploys

Production deploys default to checkOnly validation. OrgBolt refuses to deploy to production without a prior validation pass — you see every error a real deploy would hit before committing anything.

7-year audit trail

Every deploy, login, member invite, and significant action is logged and retained for 7 years. On account deletion, audit logs are anonymized (user_id nulled) but preserved for compliance.

Bring Your Own Key

Every paid workspace can provide its own Anthropic API key. Your key is stored in Supabase Vault (pgsodium, encrypted at rest) and used exclusively for your workspace's AI calls.

Non-destructive defaults

Flows deploy as Draft — OrgBolt never auto-activates a flow it creates; you review and turn it on yourself in Salesforce Setup. And nothing reaches your org without an explicit Deploy click.

AI provider transparency

OrgBolt sends your chat messages to Anthropic for AI inference. Here is exactly what that means for your data.

ProviderModelTraining on your dataData retentionPolicy
AnthropicClaude (Sonnet / Haiku)No training on API dataDeleted within 30 daysPrivacy Policy

Infrastructure & sub-processors

Every vendor that touches your data, what they access, and where they operate.

VendorPurposeData accessedLocation
SupabasePostgres database, Auth, RLS enforcementAll application dataUS
AnthropicAI inference (Claude API)Chat messages (inference only, deleted within 30 days)US
HetznerVPS hostingInfrastructure — all data in transitUS (Ashburn, VA)
CloudflareDNS, tunnel routing, bot protectionHTTP requests, Turnstile tokensGlobal CDN
Lemon SqueezyPayment processing, subscription billingEmail, payment method (via Stripe underlay)US
ResendTransactional email deliveryEmail address, email contentUS

Security architecture

Every request to OrgBolt passes through five layers of protection. No ports are exposed on the server — all traffic routes through Cloudflare's encrypted tunnel.

Browser

HTTPS-only, Turnstile bot protection, HttpOnly auth cookies

Cloudflare Tunnel

No exposed ports on the VPS — all traffic routes through an encrypted Cloudflare tunnel

Next.js Proxy

Cookie-based session refresh, auth gates on every protected route, Server Action re-authentication

Supabase (Postgres + RLS)

Row-Level Security on every table, workspace-scoped policies, encrypted OAuth tokens (Supabase Vault / pgsodium)

Anthropic API

API plan — zero training, 30-day deletion. BYOK support for paid workspaces

Security FAQ

Which AI models does OrgBolt use?

OrgBolt uses Anthropic's Claude — primarily Sonnet for task work and Haiku for lightweight operations like title summarization. All inference is on Anthropic's API plan: your data is never used for training and is deleted within 30 days.

Does Anthropic train on my data?

No. Anthropic never uses API data for model training — that's contractually guaranteed by Anthropic's commercial terms. Prompts and responses are deleted within 30 days; Anthropic retains flagged content longer only to enforce its usage policy.

Where is my data stored?

Application data is stored in Supabase (Postgres) hosted in the US. The OrgBolt server runs on Hetzner in Ashburn, Virginia. All traffic is routed through Cloudflare's encrypted tunnel — no ports are exposed on the VPS.

Can I delete my data immediately?

Yes. Settings → Delete Account starts a 30-day soft delete (data hidden immediately, restorable within 30 days, then hard-deleted by a scheduled job). Salesforce OAuth tokens are revoked immediately — not after 30 days. You can also export all your data before deletion via Settings → Data Export.

Is OrgBolt SOC 2 certified?

Not yet. OrgBolt is a new product and has not undergone a SOC 2 Type II audit. We enforce strong defaults (RLS on every table, OAuth token encryption via Supabase Vault, 7-year audit trail, no-training AI) and document our security architecture transparently. SOC 2 is on the roadmap for when the customer base warrants the investment.

How does OrgBolt handle GDPR?

OrgBolt supports GDPR Article 15 (access), Article 17 (erasure), and Article 20 (portability). Data export is self-serve. Account deletion is self-serve with a 30-day grace period. Audit logs are anonymized (user_id nulled) after deletion.

What Salesforce permissions does OrgBolt need?

OrgBolt connects via a standard OAuth Connected App. The OAuth scope includes API access for describe calls (reading metadata) and deploy operations. The Work phase never invokes a write endpoint — deploy is the only phase that writes, and it always asks first.

Can OrgBolt access my Salesforce record data?

OrgBolt reads org metadata (object definitions, field descriptions, permission sets) to understand your org structure. It caches that metadata in OrgBolt's database (workspace-scoped, RLS-protected) so it isn't re-fetched on every question. Record data — Accounts, Contacts, cases, and every other business record — sits behind a separate consent gate that is off by default. Any workspace member can grant record-data access for one org from the orgs page and revoke it at any time, and every grant and revoke is written to the audit log with the actor, the timestamp, the IP address, and the user agent.

Ready to get started?

Start free — no credit card required. Questions about enterprise security? We're happy to help.