OrgRecon
Privacy notice

Customer record contents do not become OrgRecon data.

This notice explains the limited information OrgRecon uses to operate its closed-beta service and deliver owner-authorized security assessments.

Effective August 3, 2026 · Last updated August 4, 2026

OrgRecon keeps the evidence needed to support a finding, not a copy of customer Salesforce data. Questions can be sent to privacy@orgrecon.com.

1. Information we collect

OrgRecon may collect information you provide when requesting access or using the service, including your name, work email, company, role, communications, authorized hosts, and assessment requests.

We also generate limited account, authentication, Salesforce OAuth-authorization, scan, report, request, and security-log metadata needed to operate and protect the service. Please do not submit passwords, authentication tokens, private keys, customer records, or other sensitive content through general forms.

2. Authorized assessment data

Assessments run only within an owner-authorized scope. Reports may retain normalized security evidence such as finding details, object and field names, aggregate counts, value-presence classifications, evidence provenance, and coverage outcomes.

OrgRecon does not retain Salesforce field values, record contents, record IDs, raw response bodies, access or refresh tokens, collected cookies, or session secrets as report evidence. Information received during a check is processed only as needed to classify the result.

3. Report assistant

The report assistant receives only selected, redacted evidence from the report. It explains existing findings and does not access Salesforce, detect exposures, assign severity, or change scanner conclusions.

Question text is not retained in the product database. OrgRecon stores a one-way question digest and may cache the generated, evidence-bound explanation with the associated report for reliability and cost control.

4. How information is used

We use information to review beta requests, manage accounts, verify authorization, run assessments, deliver reports, provide support, prevent abuse, maintain reliability, improve deterministic checks, and meet applicable legal obligations.

A beta request does not automatically subscribe you to promotional email. OrgRecon does not sell personal information or use customer assessment data for advertising.

5. Service providers and disclosure

OrgRecon uses managed hosting, storage, identity, email, web-security, monitoring, and AI-inference providers as service providers and subprocessors. These providers process only the information needed to perform their contracted role. You may contact us for the current categories of providers used for the service.

Information may also be disclosed when required by law, to investigate abuse or a security incident, to protect OrgRecon or its users, or as part of a business transaction subject to appropriate confidentiality safeguards.

6. Retention and deletion

Information is retained only while needed to operate the beta, provide the requested service, protect the platform, or satisfy applicable legal obligations. Reports can be deleted from the authenticated service, and account holders may request account deletion. Associated report-assistant records are removed with the owning report or account.

Limited security or audit records may be retained after account deletion when reasonably necessary to prevent abuse, investigate incidents, or comply with law.

7. Cookies and analytics

OrgRecon uses essential cookies and related browser storage for authentication, security, request integrity, and abuse prevention. The service does not use advertising cookies, cross-site behavioral profiling, or session-replay software.

Privacy-preserving aggregate measurements may be used to understand public-site availability and performance. Form contents, authorized hosts, report IDs, findings, and evidence are not analytics fields.

8. Your choices and safeguards

Email privacy@orgrecon.com to request access, correction, deletion, restriction, objection, or a copy of information you submitted where applicable. We may verify control of the relevant email address or account before fulfilling a request.

OrgRecon applies reasonable administrative and technical safeguards, but no online service can promise perfect security. Information may be processed in the United States and other locations where service providers operate under applicable contractual and legal safeguards.

OrgRecon is a business security service and is not intended for children or anyone under 18.

9. Changes and contact

Material changes will be posted here with an updated date. When appropriate, active users will also receive an in-product or email notice.

Privacy questions and requests: privacy@orgrecon.com. Security vulnerabilities should be reported through the Responsible Disclosure Policy.