This page explains exactly what DeployEzee can and cannot access in your Salesforce org. Share it with your IT security team or DPO — that's why we wrote it.
We use Salesforce's standard OAuth 2.0 Connected App flow. We never ask for your Salesforce password. You authorise us directly on Salesforce's own login page.
DeployEzee reads and deploys metadata — Apex classes, Flows, custom objects, field definitions. We have no access to your Account, Contact, Opportunity, or any record data.
Every deployment is logged with timestamp, user, components deployed, and result. The audit log is immutable — entries cannot be edited or deleted, even by DeployEzee.
Disconnect DeployEzee from your Salesforce org at any time, directly from your org's Connected App settings. Access is immediately revoked — no waiting period.
All data in transit is encrypted via TLS 1.3. Your OAuth tokens are stored encrypted at rest. We follow OWASP top-10 guidelines in our application security practice.
We request the smallest set of OAuth scopes required to do the job. We never request permissions to read or modify your business data, users, or financial records.
Transparency matters. Here is the complete list of what we ask Salesforce for when you connect an org, with a plain-English explanation of why.
The Salesforce API gives us access to far more than we use. Here's what we explicitly do not request or access.
DeployEzee is a metadata management tool — it processes configuration code, not personal data. Here's how that maps to your GDPR obligations.
Because DeployEzee only touches metadata (code definitions, field schemas, layout configurations), we do not process personal data as defined under GDPR Article 4. Your customer names, emails, and records stay entirely inside Salesforce.
DeployEzee's immutable deployment audit log is useful for demonstrating change management controls — a common requirement in ISO 27001 and SOC 2 Type II audits. Export any deployment record as PDF for your compliance file.
We store: your Salesforce org URLs, your OAuth tokens (encrypted), your deployment history, and your account email address. We do not store any metadata content (Apex code, Flow definitions) beyond what's needed to display the comparison.
For enterprise customers and EU-based teams who need a formal DPA for their records, we provide a signed Data Processing Agreement on request. Contact us at contact@cloudezee.tech and we'll send one within one business day.
Request DPAOur team is happy to speak with your IT security team, share our security questionnaire responses, or arrange a technical call.