Trust & Privacy.

This page is OrgGuard's data boundary disclosure: what stays inside your Salesforce org, and the short list of license metadata that does not. If a future release changes what leaves your tenant, this page changes with it.

Your business data stays in your org.

Your asset data, configurations, findings, dependency mappings, and audit logs never leave your Salesforce tenant. OrgGuard is a Salesforce-native managed package: discovery, policy evaluation, dependency mapping, and alerting all run inside your org against your org's metadata. The only data that crosses the tenant boundary is the standard License Management App (LMA) license metadata enumerated below, which Salesforce itself synchronizes between Aetrum's packaging org and yours.

Any future feature that would send additional data outside your tenant, specifically opt-in anonymous usage telemetry (planned for all tiers (Free, Pro, Pro+, Max), opt-in, default-off) and optional AI-assisted finding explanations (Max only), will be strictly opt-in, configurable per-org by an admin, and fully disclosed on this page before it ships. We will never send your asset inventory, findings, or audit logs outside your tenant.

What about license management?

OrgGuard uses Salesforce's License Management App (LMA), the standard mechanism every AppExchange ISV uses to manage licenses for their managed packages. LMA is a Salesforce-managed platform feature that synchronizes a small, specific set of license metadata between Aetrum's packaging org and your org via Salesforce's own infrastructure.

Exactly what LMA shares with Aetrum:

  • Org ID (15-character Salesforce org identifier)
  • Org name (the name of your Salesforce org)
  • Package version (OrgGuard package version installed)
  • License tier (Free / Pro / Pro+ / Max)
  • Active user count (per Salesforce LMA standard)
  • Install date (when you first installed OrgGuard)
  • Uninstall events (timestamp if you uninstall OrgGuard)
  • License expiration date (where applicable)

And nothing else. No asset data, no policy definitions, no findings, no user activity, no field content, no other org metadata is shared. LMA is the only mechanism by which any metadata leaves your org in Pro 1.0.

This is consistent with how every AppExchange ISV manages licenses. What's different about OrgGuard is that LMA is the only thing leaving your org. Most competitors continuously pull your business data into their cloud for analysis. OrgGuard does not.

Can I see my license tier in my org?

Yes. License tier is visible as a PackageLicense record in your Salesforce Setup. OrgGuard reads platform-managed feature parameters (set by Aetrum via LMA) to determine your tier. The record is managed by Aetrum via LMA; OrgGuard's code does not modify license state.

What about Pro+ and future features?

Pro+ (planned) will keep its core features inside your org: field-level data access monitoring, Log Analyzer, and compliance reporting all execute against your org's metadata without sending it outside your tenant. Optional opt-in telemetry will be available across all tiers; optional AI augmentation will be available on the Max tier only. When those features ship:

  • They will be off by default.
  • You will opt in per-feature; consent is not bundled.
  • The exact data sent will be disclosed before you opt in.
  • You can opt out at any time.
  • Existing customers will never have these features auto-enabled on a version upgrade.

You decide what we see. The default is what LMA syncs and nothing else.

How does OrgGuard compare to other SaaS governance tools?

Many third-party SaaS governance platforms operate as separate applications that continuously pull data from your Salesforce org into their cloud for analysis. Your business data flows to them by default.

OrgGuard is a Salesforce-native managed package; your business data stays in your tenant. The only metadata that leaves your org is the standard LMA license sync that every AppExchange ISV uses. Your configuration, your findings, your asset details, your audit logs all stay where they belong.

Read more

  • Pricing and tier comparison (Free, Pro, Pro+, Max with the founding-customer offer)
  • Roadmap (Pro 1.1, Pro+, Max with opt-in callout commitments)
  • Privacy (what this site collects)
  • Terms
  • Security whitepaper: published with Pro+ launch