Skip to content

Trust Center

JRM Consulting

Trust Center

Our approach to product security, customer data protection,
responsible development, and vulnerability reporting.

Protecting customer data and maintaining trust are fundamental to
how JRM Consulting designs and supports Salesforce solutions. We
build our applications to minimize unnecessary access, respect the
customer’s existing Salesforce security model, and keep customer
information within the customer’s Salesforce environment whenever
possible.

Product Security

JRM Consulting applications are designed with Salesforce security
principles in mind.

  • Applications operate within the customer’s Salesforce
    environment whenever possible.
  • Access is designed around the principle of least privilege.
  • Products respect existing Salesforce profiles, permission sets,
    sharing rules, and record visibility.
  • Customer data is not transmitted to external systems unless
    that behavior is explicitly documented.
  • Administrative and runtime responsibilities are separated where
    appropriate.

Data Privacy

JRM Consulting does not sell, rent, or monetize customer
Salesforce data.

  • Customer business data remains under the customer’s control.
  • Our products are designed to avoid collecting data that is not
    required for their documented function.
  • We do not access a customer’s Salesforce environment without
    authorization.
  • Any support access is limited to the scope and duration required
    to resolve the customer’s request.

Secure Development

We use a structured development and release process intended to
reduce risk and maintain reliable product behavior.

  • Source-controlled application metadata and code
  • Testing before production release
  • Documented versions and release changes
  • Controlled package updates and upgrade testing
  • Review of object, field, and system permissions
  • Prompt investigation of reported security concerns

Salesforce Platform Security

JRM Consulting products are built on the Salesforce Platform and
rely on Salesforce’s platform-level security controls.

  • Authentication and session controls
  • Profiles and permission sets
  • Object-level and field-level security
  • Organization-wide defaults and sharing rules
  • Role hierarchy and record-level visibility
  • Salesforce platform monitoring and infrastructure controls

LeadFlow Security Approach

LeadFlow is designed as a native Salesforce lead-routing
application. Its routing configuration, group membership, and
assignment audit records remain within the customer’s Salesforce
organization.

LeadFlow uses purpose-built permission sets for administrators,
routing managers, and runtime execution. These permission sets add
only the object and field access required by each role. LeadFlow
does not grant View All or Modify All access to the standard Lead
object and therefore continues to respect the customer’s existing
Lead record-sharing model.

Salesforce Security Review

JRM Consulting is committed to following applicable Salesforce
security requirements for managed packages and AppExchange
applications. Product review or certification status will be stated
accurately in product documentation and customer communications.

Responsible Vulnerability Disclosure

If you believe you have identified a security vulnerability in a
JRM Consulting product or service, please contact us with a clear
description of the issue, the affected product or page, and any
steps required to reproduce it.

Please do not include passwords, authentication codes, session
identifiers, or confidential customer data in your initial report.
We will acknowledge legitimate reports and work to investigate and
address verified issues.

Security Contact

For security questions, privacy concerns, or vulnerability reports,
contact JRM Consulting.


security@jrmcloud.net

Last updated: July 2026