Security Review

A Salesforce security audit you can run this afternoon

Fourteen modules sweep your org (privileged access, sharing model, field-level security, guest access, Apex, integrations and more) combining deterministic checks with AI analysis to produce a scored report, triaged findings with evidence, and a manual-review guide for the judgement calls. The checks are curated from a professional Salesforce security audit that cost over A$10,000 — the same ground, on demand, as often as you like.

You have been handed an org to own and asked to sign off on it, and "who can see what" has no answer anyone can evidence. A finished sweep: 43 out of 100, one critical, three high, four medium. The score is not an opinion — it is 100 − 20×critical − 8×high − 3×medium − 1×low over the findings listed underneath. Coverage says what ran and what could not: Event Monitoring is a paid add-on, so that check reports "Not licensed" instead of passing.

What you can do

  • Checks curated from a professional Salesforce security audit — a real engagement costing over A$10,000 — turned into modules you can re-run whenever you like
  • Fourteen audit modules: org baseline, authentication & SSO, users & licences, privileged access, permissions hygiene, object & field-level security, sharing model, guest & external access, Apex security, automation & flows, integrations, packages & platform, files & data egress, monitoring & audit
  • Deterministic checks find the facts; AI analysis groups the evidence and explains the risk
  • Every finding carries severity, evidence, and a link to the metadata it came from
  • A coverage matrix shows exactly which modules ran and what each one examined
  • Triage findings as resolved, accepted, or false-positive — state persists for your whole team
  • Export Markdown or CSV for stakeholders, plus an executive summary
  • A manual-review guide for the calls a tool should not make alone
  • Runs as a detached background job: start it and leave the page

How it works

1

Start a review

One click on the org’s Security Review page. The run detaches, so you can close the tab and come back to it.

2

Watch coverage fill in

The matrix ticks off modules as they complete, and findings stream in as they are discovered.

3

Triage with evidence

Findings arrive severity-ranked with the underlying metadata attached. Resolve, accept, or dismiss. Your team sees the same state.

4

Export and act

Markdown or CSV for the stakeholders who asked, and the manual-review guide for the human judgement calls.

Why it's different

Every finding shows its evidence

Salesforce Health Check gives you a percentage against a baseline. This walks fourteen modules of real metadata, has AI reason over the collected evidence in groups, and hands you findings you can act on. Each with the record, field, or profile behind it. The audit itself only ever reads: it inspects your settings, it never changes them.

Try asking

  • Audit an inherited org before you agree to own it
  • Answer “who can see what?” with evidence instead of guesses
  • Produce a security report for a client, an auditor, or a board pack
  • Catch over-permissioned profiles and stale integration users
  • Re-run quarterly and compare what changed

Security Review — questions

Read next

Put Security Review to work on your org

Every AI feature on your own provider key, from A$19.95 per user per month.

  • 14-day free trial
  • No credit card required
  • Cancel any time