OrgRecon
Trust document

Security boundaries

How OrgRecon authorizes customer-requested assessments, protects targets, and limits retained data.

Authorization

OrgRecon is owner-authorized and invite-only. Each assessment is limited to an exact approved host; any path on that approved host can be selected as its entry point. Discovery of a related hostname does not authorize it.

Salesforce Authorization

A customer explicitly authorizes the Salesforce relationship through Salesforce OAuth. The OrgRecon Trust Connector exists to establish that authorized relationship and requests only the scopes needed for its documented purpose.

Assessment and scanner logic execute in OrgRecon, not inside Salesforce. The Trust Connector does not grant Salesforce privileges by itself, expand the approved host scope, or authorize an assessment without the customer’s separate authorization.

Scanner safety

Checks are deterministic, bounded, read-only, and non-mutating. OrgRecon does not execute exploits, submit forms, click through workflows, or invoke actions whose read-only behavior cannot be established.

Data handling

Reports retain normalized observations, field names, counts, hashes, and evidence provenance. Raw Salesforce record values, record IDs, Salesforce access tokens, Salesforce refresh tokens, cookies, and response bodies are not retained or sent to the report assistant. WorkOS application-session refresh credentials are held only in a secure HTTP-only browser cookie to rotate the signed-in session.

Acceptable use

Use OrgRecon only for assets you own or are explicitly authorized to assess. Internet-wide or arbitrary third-party scanning is not supported.

Responsible disclosure

Report a security concern privately to security@orgrecon.com. Do not include customer data or credentials.