Skip to content
Digadop

Security and trust

Built to be safe to say yes to.

Digadop is AI-first, and we hold it to a security bar that lets an enterprise Salesforce, security, and compliance team connect us with confidence. Here is how our products reach your org and handle your data.

How we handle access and data

The commitments behind every product

Connect through Salesforce OAuth

You authorize access through Salesforce OAuth and can revoke it at any time. Access and documentation analysis never change your configuration. Digadop Help installs as a managed package with a single Apex trigger that writes only that one-time provisioning record; it adds no other automation and changes no business data.

Read-only where it can be

Access analysis is read-only. Who Sees What reads your access configuration, security metadata (profiles, permission sets, sharing, roles), and your user directory (names, usernames, profiles). It does not read your business field values; for a record-specific audit it reads only the record name, ownership, and sharing metadata needed to explain access.

Least privilege by design

Each product requests only the access it needs to do its job, and we say plainly what it reads and writes, so your security team can scope and approve it with confidence.

Encrypted in transit and at rest

Your data is encrypted in transit and at rest. Stored credentials such as Salesforce refresh tokens are encrypted with AWS Key Management Service.

Per-tenant isolation

Your data is isolated per tenant with organization-scoped access and PostgreSQL row-level security. One customer's configuration, content, and analysis are never visible to another.

We are specific about where AI runs

The Who Sees What access audit is deterministic and uses no AI on your data. Clionyx uses AI on your org configuration to write documentation. The assistants (Diana, Horton) answer only from public product documentation and are never sent your org data. Your data is never used to train models.

Transparent that it is AI

Every Muse is an AI agent, clearly labeled and never presented as a person. Ask Diana on this page: she is AI, and she says so.

Documents and where to learn more

The specifics of what we collect, how long we keep it, and who processes it on our behalf live in our legal documents. Our Privacy Policy describes data handling and processors, and our Terms govern use of the products. Each product's Product Schedule is the authoritative description of how that product handles your data. For privacy questions, contact privacy@digadop.com.

A full trust center, with a current subprocessor list, data-retention schedule, and compliance status, is being formalized. If your security review needs details we have not published yet, send us the questionnaire: you will get an acknowledgement, and a documented answer from our team, typically within one business day.