Salesforce architecture and security assessment
Cubic Compass provides structured Salesforce assessment services for organizations that need evidence-based review of production and sandbox environments.
The assessment focuses on data exposure, access pathways, sandbox replication, integration boundaries, metadata, governance, and auditability. It is designed for decision support, remediation planning, and partner or executive review.
Assurance Level framework
Level A - Targeted containment
High-level review of key and critical security points, sandbox types, access hardening, and development environment boundaries.
Level B - Data and access pathways
Structured review of objects, fields, permissions, integration identities, sandbox replication, and evidence-backed exposure mapping.
Level C - High assurance
Deeper assessment across metadata, automation, files, free-text content, audit posture, and data pathways across Salesforce environments.
High assurance gets into metadata and data. Lower assurance focuses on a high-level review of key and critical security points and configuration.
Assessment process
Review modules
- Production and sandbox environment inventory.
- User, profile, permission set, and administrative access review.
- Object, field, file, and unstructured content exposure review.
- Connected apps, named credentials, API identities, and integration boundaries.
- Metadata, Apex, Flow, managed package, and automation review when included by Assurance Level.
- Logging, monitoring, access governance, and evidence retention posture.
Deliverables
- Architecture and data exposure summary.
- Access pathways and control summary.
- Environment strategy options for development, sandbox, and constrained access models.
- Findings register with severity, evidence, and recommended control direction.
- Executive readout for leadership or partner review.
AI-assisted evidence review may use leading model providers, including OpenAI and Anthropic, while keeping conclusions tied to documented Salesforce evidence.
We have signed data processing agreements with leading AI providers to ensure that Salesforce evidence is not used for model training or other purposes outside of the assessment engagement.