Language:English·Français
Security and trust

Your data, protected by design.

aprity reads your Salesforce metadata, never writes to it, and does not keep the raw metadata after a scan completes. Analysis is deterministic first; the AI narrates on top. Everything below is stated plainly and is verifiable.

Salesforce Security Review passed — July 2026
Read-only access
Connector cannot write or change schema
Purged after every scan
Raw metadata is not retained
Azure-only AI routing
EU and US data regions
Multi-tenant isolation
Tenants are hard-isolated
Salesforce Security Review

Reviewed by Salesforce. Passed.

The aprity managed package passed the Salesforce AppExchange Security Review in July 2026. Salesforce audits the package against its own security standards — authentication, data handling, sharing and CRUD/FLS enforcement, API usage and outbound calls — before a solution is allowed to list. Passing it is a precondition for distribution on AppExchange, and it applies to the package installed in your org.

Passed — July 2026
Audit readiness

Documentation that keeps pace with your audits.

ISO 27001, HDS and SOC 2 all require organizations to keep their documentation continuously up to date. aprity refreshes your Salesforce documentation on every scan, so it directly supports those audits. It enables your compliance and audit-readiness — aprity does not itself hold these certifications.

Audits we help you prepare for
ISO 27001
HDS
SOC 2
Deterministic first, AI second

The LLM narrates. It never decides.

Dependencies, impact and the execution graph are computed deterministically from your metadata — reproducible and verifiable. The model explains results and answers questions with citations; it is never in the path that produces the graph.

See the platform

Read-only Salesforce access

  • JWT Bearer authentication — no user password is stored or transmitted
  • Connected App with read-only permissions
  • Zero footprint on your Salesforce org
  • We access structural metadata only — object definitions, field schemas, automation configuration
  • We do not access and do not store your business data

Source metadata purged after every scan

  • Metadata is processed in isolated per-tenant partitions for the duration of the scan
  • Once the documentation is produced, the source metadata is deleted
  • Only the derived documentation is retained
  • You control your data lifecycle — deletion within 30 days of termination

Multi-tenant isolation

  • Strict multi-tenant architecture with per-tenant data partitions
  • Partition keys enforced at the database level (Azure Cosmos DB)
  • Every API request is cross-checked against the tenant's installation record
  • No cross-tenant data leakage — enforced at the infrastructure layer
  • Tenant context propagated through every log line for auditability
  • Agent context is scoped to a single tenant — an assistant can never retrieve another tenant's documentation

Language models — routed exclusively through Azure

  • aprity calls no model provider directly — all AI inference goes exclusively through Microsoft Azure (Azure OpenAI Service and Azure AI Foundry)
  • No training: under the Microsoft Product Terms, your prompts and outputs are never used to train or improve foundation models
  • Regional pinning: prompts and outputs are processed and stored in the Azure region you choose
  • The Microsoft EU Data Boundary commitment applies to EU-region deployments
  • Model licensors (OpenAI, Anthropic) have no access to your data — the models are hosted and operated by Microsoft
  • Abuse monitoring is encrypted and region-bound, and a Limited Access exemption can be requested for sensitive customers
  • Intelligence plan: with bring-your-own-LLM, inference goes to your own endpoint instead, under your contract with that provider

Content security

  • Prompt-injection patterns are detected and blocked on both the input to the model and its output
  • Every AI response is sanitized before it is returned
  • Input validation on all user-supplied content
  • Rate limiting on every API endpoint
  • No arbitrary code execution from LLM output

Azure-hosted infrastructure

  • Data residency region chosen by the customer at subscription — France Central (EU) or East US
  • EU deployments are available to customers in the financial and insurance sectors and to any customer subject to an EU-residency requirement
  • Azure Cosmos DB with encryption at rest (AES-256, Azure-managed keys)
  • Encryption in transit (TLS 1.2+)
  • Azure Key Vault for secret management — Salesforce tokens are never stored in clear text
  • Azure Container Apps for compute isolation
  • Role-based access control, MFA on administrative access, and audit logging

Continuity and incident handling

  • Daily encrypted database backups with a 30-day restore window
  • Recovery objectives: RTO 4 hours, RPO 24 hours (V1)
  • Personal data breaches are notified to affected customers without undue delay and in any event within 72 hours of qualification
  • Documented incident procedure: detection, qualification, notification, remediation, post-incident report
  • Azure-native resilience (availability zones, multi-AZ managed services)

Compliance and privacy

  • GDPR-compliant processing with full exercise of data-subject rights
  • DORA-compatible: ICT-provider assistance, audit rights and exit strategies for customers in the financial sector
  • EU AI Act: qualified as a limited-risk AI system — transparency and human oversight by design
  • Strictly necessary cookies, plus Google Analytics subject to your explicit consent (IP anonymised) — no advertising, no cross-site behavioural tracking
  • Sub-processors are contractually bound (list on request)
  • No personal data is sold or shared for prospecting purposes
  • Data deletion within 30 days of account termination
  • French law applies (courts of Paris)
Sub-processors and incident response

Sub-processors and incident handling.

aprity runs on Microsoft Azure (EU and US regions). The complete, current sub-processor list is available on request. If a security incident affects your data, we notify you without undue delay and in any event within 72 hours of qualifying the breach, and we support your own regulatory reporting.

Documentation

Security and contractual documentation

A complete set of security and contractual documents is made available to prospects under evaluation. They are shared on request as part of a security review or a procurement process.

Security dossier

Technical and organisational security measures, architecture, sub-processors, DORA and EU AI Act compliance.

General Terms of Service

Contractual terms governing paid subscriptions: licence, liability, warranties, reversibility.

Service Level Agreement (SLA)

Availability commitments, support tiers, response times, continuity and recovery objectives.

Request the security documentation

Company and legal information

Company

aprity SASU — France, EU

RCS Paris 105 405 138

Salesforce ISV Partner

Jurisdiction

French law

Courts of Paris, exclusive jurisdiction

Contact

security@aprity.ai

dpo@aprity.ai

Response within 24 hours

Privacy policyTerms of serviceLegal noticeCookie policy
Responsible disclosure

Report a vulnerability.

Found a security issue in aprity? Report it privately to security@aprity.ai. Please do not open a public issue or disclose the details before we have shipped a fix. We acknowledge reports within 2 business days, triage within 5, and target a fix or mitigation plan for High and Critical issues within 30 days. Good-faith research is covered by our safe-harbor policy, and we are happy to credit reporters with their consent.

Questions about security?

We are happy to walk you through our security architecture or answer any specific question about how data is handled.