Security First

We access your metadata.
Never your customer data.

This page explains exactly what DeployEzee can and cannot access in your Salesforce org. Share it with your IT security team or DPO — that's why we wrote it.

OAuth 2.0 Only

We use Salesforce's standard OAuth 2.0 Connected App flow. We never ask for your Salesforce password. You authorise us directly on Salesforce's own login page.

Metadata Only

DeployEzee reads and deploys metadata — Apex classes, Flows, custom objects, field definitions. We have no access to your Account, Contact, Opportunity, or any record data.

Audit Everything

Every deployment is logged with timestamp, user, components deployed, and result. The audit log is immutable — entries cannot be edited or deleted, even by DeployEzee.

Revoke Anytime

Disconnect DeployEzee from your Salesforce org at any time, directly from your org's Connected App settings. Access is immediately revoked — no waiting period.

TLS Encryption

All data in transit is encrypted via TLS 1.3. Your OAuth tokens are stored encrypted at rest. We follow OWASP top-10 guidelines in our application security practice.

Minimal Permissions

We request the smallest set of OAuth scopes required to do the job. We never request permissions to read or modify your business data, users, or financial records.

Exact Permissions

The OAuth scopes we request,
and why we need each one.

Transparency matters. Here is the complete list of what we ask Salesforce for when you connect an org, with a plain-English explanation of why.

OAuth Scope What it allows Why we need it Required?
api Access your Salesforce org's APIs Required to call the Metadata API to read and compare components Required
refresh_token Stay connected without re-authorising every time So you don't have to reconnect every session — token refreshes silently Required
metadata Read and deploy Salesforce Metadata API components Core to the product — reading org schema and deploying components Required
openid Identify who you are (your Salesforce user ID) To show your name in the deployment audit log and settings panel Required
Clear Boundaries

What DeployEzee
never touches.

The Salesforce API gives us access to far more than we use. Here's what we explicitly do not request or access.

Business data records
We cannot read Accounts, Contacts, Opportunities, Cases, Leads, or any custom object records. The Metadata API only exposes component definitions, not record data.
User credentials or passwords
OAuth means you log in directly on Salesforce's site. We never see your Salesforce username or password at any point in the flow.
Financial or payment information
We have no visibility into financial records, invoices, payment data, or any transactional information stored in your org.
User management or profile modifications
We cannot create users, reset passwords, assign profiles, or change permissions for anyone in your org. This requires separate System Administrator scopes we do not request.
Report or dashboard data
We can deploy report and dashboard definitions (the structure), but we cannot execute them or see the data they return.
Files, attachments, or documents
ContentDocument, Attachment, and file storage are inaccessible. We work entirely at the metadata layer — code and configuration, not content.
GDPR Considerations

For teams in the UK and EU.

DeployEzee is a metadata management tool — it processes configuration code, not personal data. Here's how that maps to your GDPR obligations.

Not a personal data processor

Because DeployEzee only touches metadata (code definitions, field schemas, layout configurations), we do not process personal data as defined under GDPR Article 4. Your customer names, emails, and records stay entirely inside Salesforce.

Audit log as compliance evidence

DeployEzee's immutable deployment audit log is useful for demonstrating change management controls — a common requirement in ISO 27001 and SOC 2 Type II audits. Export any deployment record as PDF for your compliance file.

What data we do hold

We store: your Salesforce org URLs, your OAuth tokens (encrypted), your deployment history, and your account email address. We do not store any metadata content (Apex code, Flow definitions) beyond what's needed to display the comparison.

Data Processing Agreement

For enterprise customers and EU-based teams who need a formal DPA for their records, we provide a signed Data Processing Agreement on request. Contact us at contact@cloudezee.tech and we'll send one within one business day.

Request DPA
Questions?

Have more security questions?
Talk to a human.

Our team is happy to speak with your IT security team, share our security questionnaire responses, or arrange a technical call.