Publisher security

100 %
inside your org
0
outbound data by default
71/255
controls self-assessed
10 min
to install

The French text governs. This page is the English version of Sécurité de l'éditeur FR.

The site maps ISO 27001 and SOC 2 for your org. This page answers the symmetrical question, the one your vendor questionnaire asks: and you? Each section is dated. What is not done is written, in the last section, before you find out.

1. AppExchange Security Review —

Not submitted. The dossier is assembled (requirement-evidence matrix, Code Analyzer report, false-positive register, accessibility review), and we will not call the review passed or guaranteed before it is. About half of first submissions fail; the dossier exists so that the first one counts.

2. Secure development cycle

3. Outbound flows: none active at delivery

Four families of flows can be opened, one by one, by your administrator: health aggregates to the hosted viewer (no personal data, HMAC-signed), alert channels, ITSM integration, SIEM export. The last three go to a destination you choose, with your credentials. Consent to the first flow can only be granted inside the org, by a human: the setting is protected and cannot be reached from outside the package — we checked by trying.

4. Sub-processors and hosting —

Sub-processors, role, data location, safeguards
Sub-processorRoleLocationSafeguards
Salesforce, Inc. (Heroku platform)Hosting of the ingestion service and viewer — an option, involved only if you enable itHeroku EU regionSalesforce standard contractual clauses, Heroku DPA
Amazon Web Services, Inc. (Heroku Postgres add-on)Database of the multi-tenant viewerAWS eu-west-1 (Ireland)Via Heroku; TLS connections, encryption at rest
Infomaniak Network SAHosting of this website and the mailboxesSwitzerland (EU adequacy)Infomaniak DPA, ISO 27001-certified host

No other sub-processor accesses customer data. Any change to this list is notified to viewer subscribers thirty days ahead: this is a commitment the publisher makes here, not a clause the DPA already carries — the contractual corpus is under review, and we do not cite a contract for a period it does not yet contain. By default, no data leaves your org: this list concerns the hosted option only.

5. Reporting a vulnerability

security@orgguardian.com, or the /.well-known/security.txt file. Acknowledgement within two business days, triage within ten, fix in the next version for a confirmed defect. We do not pursue good-faith research. There is no bounty programme.

6. What is not in place —