Salesforce MCP security

ApexGenius is an authenticated API and MCP gateway. The ordinary MCP path does not intentionally retain Salesforce record results or AI conversation content. Credentials are encrypted, and operational, usage, security, audit, staging, and error records support the service. Authenticated Salesforce LWC Chat is a separate supported path with encrypted conversation history.

Transient Results

Ordinary MCP record results are not intentionally retained

MCP Client Routing

Ordinary MCP results return to the AI agent you connect

Encrypted Credentials

Supported connection secrets are encrypted at rest

Tenant Controls

User, organization, project, and Salesforce permissions apply

How We Protect Your Data

Security controls are applied across the supported service paths, with scope and evidence reviewed as the platform changes.

Your AI, Your Data Path

On the ordinary MCP path, tool results return to the AI agent you connect, such as Claude or ChatGPT, under your agreement with that provider. Authenticated Salesforce LWC Chat is separate and uses a Company-configured server-side AI provider.

Transient Record Results

The ordinary MCP path does not intentionally retain Salesforce record results or AI conversation content. Metadata, files, or configuration that you explicitly stage, sync, or save are retained for that selected feature.

AES-256-GCM Encryption

Salesforce OAuth tokens and supported credentials use encrypted vault or credential paths. New supported LWC Chat writes require AES-256-GCM envelopes, and historical encrypted web Chat records keep their compatible decryption path. Supported web, API, database, and provider connections use TLS; HSTS applies on configured ApexGenius responses.

Salesforce Connection Controls

New connections can use each team member's own Salesforce OAuth 2.0 authorization. Some supported legacy projects still use a project-shared connection. Data access follows the effective Salesforce permission model, and tokens are stored as encrypted vault references.

Tenant-Scoped Access

Supported customer data is scoped by user, organization, project, role, and database row-level policies. Access also follows the effective permissions of the connected Salesforce credential.

Content-Minimized Audit Logging

Permission changes, deployment actions, selected access and RPC events, and errors can produce content-minimized operational records. The documented RBAC retention target is 365 days, but schedule execution and audit completeness still require operating evidence. Runtime logs are not yet proven to sanitize every structured field, so sensitive logging remains an open risk.

Network Intrusion Detection

Suricata is documented on the production host for network intrusion detection. Current alert-delivery and review evidence must still be verified as part of the SOC 2 readiness program.

Retention and Deletion

Account, credential, staging, usage, security, audit, error, LWC Chat, and encrypted historical web Chat data follow documented retention, deletion, backup, contractual, and legal requirements.

Authenticated Salesforce LWC Chat

Public and legacy web Chat are retired. The Salesforce LWC project remains a supported authenticated surface with a separate server-side AI and storage path.

  • Authentication: Access is limited to the supported Salesforce project and /api/lwc/* routes.
  • AI processing: ApexGenius sends the LWC message, relevant Salesforce context, and tool output to the configured server-side AI provider.
  • Storage: Messages, responses, relevant tool output, and conversation state are stored encrypted for continuity and authorized history access.
  • PHI boundary: Salesforce LWC Chat is not an approved PHI path. The separate authenticated API or MCP requirements in the Privacy Policy apply to any approved PHI use.

Need our full security documentation?

We provide available security architecture, control, and infrastructure documentation to enterprise customers and security teams on request.

Infrastructure and Sub-Processors

The infrastructure providers that support the authenticated API, MCP gateway, Salesforce LWC Chat, account, billing, and public website.

ProviderPurposeData Accessed
Supabase (AWS)Database, auth, vault encryptionAccount, configuration, credential, operational, audit, staging, and stored LWC or historical Chat records used by the service
DigitalOceanBackend hostingApplication runtime (encrypted in transit)
VercelFrontend hosting + CDNStatic assets, IP addresses
UpstashRedis caching + rate limitingRate limit counters, metadata cache (no secrets)
StripePayment processingBilling info, subscription status (no full card numbers)
Configured AI providersAuthenticated Salesforce LWC Chat response generationLWC messages, relevant Salesforce context, tool output, and generated responses needed for the request

Security FAQ

Answers to the questions security teams ask before approving new tools.

Ready to see it in action?

Start with a free account. No credit card required. Connect an authorized Salesforce sandbox, review the current controls and open gaps, and verify a narrow read before expanding access.

Start Free Trial