KEELCADENCE
| Automation Inventory

DATA HANDLING & SECURITY

READ ME.

How Automation Inventory handles your Salesforce session, what it reads, and how your data is stored.

HOW AUTHENTICATION WORKS

Automation Inventory uses a browser bookmarklet to read your active Salesforce session cookie. When you click the bookmarklet from a Salesforce page, it extracts your session identifier and sends it to this server via an HTTPS POST. The server validates it against Salesforce’s own identity endpoint and stores the result in a signed, tamper-resistant server-side cookie for the duration of your browser session.

Your Salesforce Session ID is never written to our database. It exists only in the signed browser session and in memory during audit execution. It is discarded immediately when the audit completes.

There is no OAuth flow, no Connected App, and no persistent token. Your session expires naturally when your Salesforce session ends (typically ~2 hours). Disconnecting from the app clears the session cookie immediately.

WHAT THIS AUDIT READS

The Automation Inventory reads metadata only: flow definitions, Apex class metadata, trigger metadata, validation rule definitions, and approval process configurations. It does not read record data, field values, user data, or any business information stored in your org.

  • Flow and process builder definitions (metadata, not execution logs)
  • Apex class and trigger metadata (names, API versions, line counts — not code content)
  • Validation rule names and active status
  • Approval process names and step counts
  • No record-level data is read at any point

KeelCadence reviews Salesforce metadata and aggregate configuration signals. It does not export customer records, files, attachments, emails, Chatter content, or transactional data.

WHAT WE STORE

We store a minimal audit run record in a local SQLite database containing:

  • Your Salesforce Org ID (not your Session ID)
  • The audit options you selected
  • Aggregate automation counts and category totals
  • The generated XLSX report file on the server filesystem
  • Your Stripe transaction ID if you purchase a report (no card data)

We do not store: your Salesforce Session ID, usernames, individual automation names in the database (only in the report file), or any record-level business data.

REPORT RETENTION

Audit reports are retained for 90 days from the date of the audit. After 90 days, the report file and associated run record are permanently deleted. You can request deletion of your report at any time by contacting support@keelcadence.com with your Report ID.

ANALYTICS

This site uses Google Analytics 4 (GA4, ID: G-EK6W2D5FH5) to understand how visitors use the product. GA4 is loaded only with your consent in restricted regions (EU, EEA, UK, Switzerland, Brazil). In other regions, it loads by default with an opt-out option available.

We never send audit data, Salesforce session information, Org IDs, Report IDs, or payment information to GA4. All page paths containing audit run IDs are sanitized before being sent to analytics.

PAYMENT

Report downloads are gated by a one-time payment processed through Stripe. We do not store credit card numbers or payment details. Stripe sends a webhook to confirm payment server-side before download access is granted. Your Stripe transaction ID is stored in our database for payment verification purposes only.

SECURITY REVIEW FAQ

Does KeelCadence export Salesforce records or files?
No. KeelCadence does not export customer records, files, attachments, emails, Chatter content, or transactional data. Reports are based on Salesforce metadata, configuration, automation metadata, and aggregate counts used for diagnostic scoring.

What is a read-only diagnostic session?
The audit runs a read-only diagnostic against your org’s metadata using your active Salesforce browser session. No writes, no configuration changes, and no persistent access token are created. The session expires when your Salesforce session ends.

CONTACT

Questions about data handling, deletion requests, or security review: support@keelcadence.com

For IT and security review information, see the IT Review page and Security page on keelcadence.com.