Salesforce MCP security
ApexGenius is an authenticated API and MCP gateway. The ordinary MCP path does not intentionally retain Salesforce record results or AI conversation content. Credentials are encrypted, and operational, usage, security, audit, staging, and error records support the service. Authenticated Salesforce LWC Chat is a separate supported path with encrypted conversation history.
Transient Results
Ordinary MCP record results are not intentionally retained
MCP Client Routing
Ordinary MCP results return to the AI agent you connect
Encrypted Credentials
Supported connection secrets are encrypted at rest
Tenant Controls
User, organization, project, and Salesforce permissions apply
How We Protect Your Data
Security controls are applied across the supported service paths, with scope and evidence reviewed as the platform changes.
Your AI, Your Data Path
On the ordinary MCP path, tool results return to the AI agent you connect, such as Claude or ChatGPT, under your agreement with that provider. Authenticated Salesforce LWC Chat is separate and uses a Company-configured server-side AI provider.
Transient Record Results
The ordinary MCP path does not intentionally retain Salesforce record results or AI conversation content. Metadata, files, or configuration that you explicitly stage, sync, or save are retained for that selected feature.
AES-256-GCM Encryption
Salesforce OAuth tokens and supported credentials use encrypted vault or credential paths. New supported LWC Chat writes require AES-256-GCM envelopes, and historical encrypted web Chat records keep their compatible decryption path. Supported web, API, database, and provider connections use TLS; HSTS applies on configured ApexGenius responses.
Salesforce Connection Controls
New connections can use each team member's own Salesforce OAuth 2.0 authorization. Some supported legacy projects still use a project-shared connection. Data access follows the effective Salesforce permission model, and tokens are stored as encrypted vault references.
Tenant-Scoped Access
Supported customer data is scoped by user, organization, project, role, and database row-level policies. Access also follows the effective permissions of the connected Salesforce credential.
Content-Minimized Audit Logging
Permission changes, deployment actions, selected access and RPC events, and errors can produce content-minimized operational records. The documented RBAC retention target is 365 days, but schedule execution and audit completeness still require operating evidence. Runtime logs are not yet proven to sanitize every structured field, so sensitive logging remains an open risk.
Network Intrusion Detection
Suricata is documented on the production host for network intrusion detection. Current alert-delivery and review evidence must still be verified as part of the SOC 2 readiness program.
Retention and Deletion
Account, credential, staging, usage, security, audit, error, LWC Chat, and encrypted historical web Chat data follow documented retention, deletion, backup, contractual, and legal requirements.
Authenticated Salesforce LWC Chat
Public and legacy web Chat are retired. The Salesforce LWC project remains a supported authenticated surface with a separate server-side AI and storage path.
- Authentication: Access is limited to the supported Salesforce project and /api/lwc/* routes.
- AI processing: ApexGenius sends the LWC message, relevant Salesforce context, and tool output to the configured server-side AI provider.
- Storage: Messages, responses, relevant tool output, and conversation state are stored encrypted for continuity and authorized history access.
- PHI boundary: Salesforce LWC Chat is not an approved PHI path. The separate authenticated API or MCP requirements in the Privacy Policy apply to any approved PHI use.
Need our full security documentation?
We provide available security architecture, control, and infrastructure documentation to enterprise customers and security teams on request.
Infrastructure and Sub-Processors
The infrastructure providers that support the authenticated API, MCP gateway, Salesforce LWC Chat, account, billing, and public website.
| Provider | Purpose | Data Accessed |
|---|---|---|
| Supabase (AWS) | Database, auth, vault encryption | Account, configuration, credential, operational, audit, staging, and stored LWC or historical Chat records used by the service |
| DigitalOcean | Backend hosting | Application runtime (encrypted in transit) |
| Vercel | Frontend hosting + CDN | Static assets, IP addresses |
| Upstash | Redis caching + rate limiting | Rate limit counters, metadata cache (no secrets) |
| Stripe | Payment processing | Billing info, subscription status (no full card numbers) |
| Configured AI providers | Authenticated Salesforce LWC Chat response generation | LWC messages, relevant Salesforce context, tool output, and generated responses needed for the request |
Security FAQ
Answers to the questions security teams ask before approving new tools.
Ready to see it in action?
Start with a free account. No credit card required. Connect an authorized Salesforce sandbox, review the current controls and open gaps, and verify a narrow read before expanding access.