Posture supervision · Salesforce

Your Salesforce org
isn’t telling you everything.

OrgGuardian scans your org continuously and surfaces what nobody looks at: toxic permissions, missing MFA, expiring certificates, limits hitting their ceiling. Every finding is explained, located, and delivered with the remediation step to apply — read-only, writing nothing into your configuration.

Salesforce managed package · 10-minute install · no outbound flow active at delivery

OrgGuardian Findings screen: work queue sorted by severity, each line carrying its target, its message and its occurrence count.
Screens captured on an English-language org, which is how the product ships: over 4,000 packaged labels are declared en_US, and findings are stored in English. A French language pack recomposes them at display time.
100 %
of the computation and storage inside your org. No outbound flow active at delivery.
0
secrets to enter to install and run the first scan.
71/255
controls self-assessed across 8 frameworks — the rest are procedures.
10 min
to install. A managed package: nothing to host.

The problem

Who guarantees your Salesforce configuration?

Salesforce guarantees the platform; nobody guarantees your configuration. Permissions, integrations, certificates and code are your side of the shared responsibility contract. Nothing warns you when it drifts.

1profile is enough

An invisible attack surface

An integration user combining “Modify All Data”, the API and no MFA: the combination most often cited in Salesforce incidents, and no native alert.

90days dormant

An org drifting in silence

An OAuth token dormant for three months outlives the person who authorised it. A certificate expires on a Friday evening. Nothing says so before the outage.

0€ estimated

Risk that is never costed

“How bad is it?” has no answer until the risk has an amount. Without a figure, the trade-off is made on instinct, and the budget goes elsewhere.

The console

Who reads what, and on which screen?

Three readings: executive, CISO, admin. A 100% native managed package: nothing to host, nothing to connect. Each screen answers one precise question, without jargon.

  • Every finding says what is wrong, where, why it matters, and how to remediate.
  • The work queue is sorted by severity.
  • The product invents no amount: you enter your own weights per severity, and until you do it shows “risk cost not defined” rather than a figure.

Ask to see the console

OrgGuardian Compliance screen: the frameworks and the number of self-assessed controls per article.

Compliance

How do DORA and NIS2 become measured gaps?

Every regulatory article is attached to the detectors that instruct it. What is not measurable is declared as such, control by control.

8

Frameworks mapped

DORA, NIS2, ISO 27001, SOC 2, NIST CSF, NIST 800-53, SOX, GDPR — each with its real count.

SOX 12/15 · NIS2 6/10 · SOC 2 10/36

71

Controls self-assessed

Out of 255 catalogued. The rest are procedures a package installed in an org cannot observe — and the catalogue says so line by line.

Small business tier

1

Attestation to hand over

Signed, dated, with the exact scope of what was measured. Not a screenshot of a dashboard.

Small business tier

Trust

What data leaves your org?

None, by default. The product's non-negotiable principle: the analysis lives with you, under your access rules.

100% inside your org

Scan, findings, history: everything is computed and stored in your Salesforce org, in user mode — the package never reads more than the person running it.

Fail-closed by design

An unconfigured feature never degrades silently: it switches off and says so. A collector that hits its ceiling writes it into its finding.

Four possible flows, none active

EU-hosted viewer, alert channels, ITSM, SIEM export: each opens separately, by your administrator, to a destination you choose.

Pricing

What does OrgGuardian cost for your size of org?

One offer per size of organisation. The price follows your number of Salesforce users, never the value of your data.

Discovery

1 org, to evaluate

€0

permanent

  • Limits, health, failed logins
  • 7-day retention
  • 30-day trial of the full plan

Free forever, no credit card

Small business

up to 15 Salesforce users

€49

/ month (1 to 5 users)

  • 6 to 15 users: €99
  • Security posture, code quality
  • E-mail alerts, web viewer

No commitment, cancellable monthly

Recommended

Mid-market

16 to 250 Salesforce users

€249

/ month (16 to 40 users)

  • 41 to 100: €499 · 101 to 250: €1,490
  • DORA / NIS2 compliance pack
  • Multi-org aggregation

The tier we recommend

Enterprise

beyond 250 users

€2,490

/ month (251 to 600 users)

  • 601 to 1,500: €4,990
  • Dedicated DPA, fleet of up to 5 orgs
  • Assisted onboarding

Annual billing

Compare the offers in detail — 138 capabilities, one tick per cell

Questions

What people ask us.

Does OrgGuardian send data outside my org?

Not by default: no outbound flow is active at delivery. All computation and storage live inside your org. Four families of flow can then be opened, one by one, by your administrator: health aggregates to the external viewer — no personal data, hosted in the European Union — alert channels to Slack, Teams, PagerDuty or webhook, ITSM integration to ServiceNow or Jira, and SIEM export to Splunk or Microsoft Sentinel. Each one goes to a destination you choose, and each is revocable at any time.

What language is the product in?

The interface is in English: over 4,000 packaged labels are declared en_US. Finding messages are now stored in English and recomposed at display time from a 697-phrase language pack (version 2026.09.1): 109 classes set a message key rather than a sentence, and rendering picks the user’s language. Two reservations, and we would rather write them down: the pack currently carries French only, and a sentence translates all or nothing — if one fragment is missing, the stored English sentence comes out, never a blank and never a mix. If you need another language, say so when you request the trial.

What happens to the history if you stop?

Uninstalling a managed package destroys its objects and all their data: findings, handling history, metrics, signed attestations. Salesforce keeps neither a recycle bin nor a restore. Before uninstalling, export what you want to keep from the console — findings and attestations as CSV, configuration as JSON — and rehearse once on a sandbox to measure what you actually get back. Nothing is retained on our side: by default, no data ever left your org.

What if the publisher disappears?

The installed package keeps running inside your org: it depends on no external service to scan, alert and export. Only the optional hosted viewer would go dark — and it only holds aggregates your org already owns. The licence stops being renewed, not being executed. A source code escrow is not in place today; if your procurement policy requires one, say so — it is a clause we know how to write.

How long until the first results?

Ten minutes to install. The recurring scan schedules itself the first time you open the console, and the first findings arrive within the hour that follows: on an org that has never been audited, there are always some.

Is it suited to an SME with 20 users as well as to an account with 10,000?

Yes. The collectors are designed for Salesforce limits (bulkified mode, circuit breakers, quotas) and bounded by construction: COUNT and GROUP BY aggregates rather than row-by-row reads, explicit row ceilings per collector, and a collector that hits its ceiling says so in its finding instead of going quiet. We have not yet published a measurement on an org of several million records: if that is yours, say so when you ask for the trial. Pricing follows size: each tier has its own single price, detailed in the pricing table above.

Does OrgGuardian replace Salesforce Security Center or Health Check?

No — OrgGuardian is a complement, not a replacement. It goes far beyond Health Check, which is point-in-time, technical, and carries no financial exposure — its only native alert is a weekly notification when the score drops. Against Security Center, it brings what that product does not cover: DORA/NIS2 compliance article by article, monitoring of integrations and limits, risk quantified in euros, and the external viewer. The two complement each other; we publish no price comparison, as Salesforce does not make its own public.

What happens at the end of the 30-day trial?

You choose a plan, or you fall back to Discovery (free, 7-day retention). Export your posture BEFORE falling back to Discovery: beyond 7 days the history is purged, and that purge is permanent — taking a paid plan again does not restore it. The export stays available at any time while you are on a plan.

Is the DORA/NIS2 mapping a guarantee of compliance?

No, and be wary of anyone who promises it. OrgGuardian measures the technical posture of your org and produces the evidence. Compliance remains a company-wide effort, with your DPO and your counsel. The trickiest NIS2 points of interpretation were, moreover, settled by a compliance expert’s verdict, displayed in the product itself.

Ready in 10 minutes

How do you get your first posture report?

Install OrgGuardian on your org, let the first scan run, and look at what nobody had shown you yet.

Or by e-mail: contact@orgguardian.com

reply within one business day · guided installation offered during the launch phase