JRM Consulting
Trust Center
Our approach to product security, customer data protection,
responsible development, and vulnerability reporting.
Protecting customer data and maintaining trust are fundamental to
how JRM Consulting designs and supports Salesforce solutions. We
build our applications to minimize unnecessary access, respect the
customer’s existing Salesforce security model, and keep customer
information within the customer’s Salesforce environment whenever
possible.
Product Security
JRM Consulting applications are designed with Salesforce security
principles in mind.
-
Applications operate within the customer’s Salesforce
environment whenever possible. - Access is designed around the principle of least privilege.
-
Products respect existing Salesforce profiles, permission sets,
sharing rules, and record visibility. -
Customer data is not transmitted to external systems unless
that behavior is explicitly documented. -
Administrative and runtime responsibilities are separated where
appropriate.
Data Privacy
JRM Consulting does not sell, rent, or monetize customer
Salesforce data.
- Customer business data remains under the customer’s control.
-
Our products are designed to avoid collecting data that is not
required for their documented function. -
We do not access a customer’s Salesforce environment without
authorization. -
Any support access is limited to the scope and duration required
to resolve the customer’s request.
Secure Development
We use a structured development and release process intended to
reduce risk and maintain reliable product behavior.
- Source-controlled application metadata and code
- Testing before production release
- Documented versions and release changes
- Controlled package updates and upgrade testing
- Review of object, field, and system permissions
- Prompt investigation of reported security concerns
Salesforce Platform Security
JRM Consulting products are built on the Salesforce Platform and
rely on Salesforce’s platform-level security controls.
- Authentication and session controls
- Profiles and permission sets
- Object-level and field-level security
- Organization-wide defaults and sharing rules
- Role hierarchy and record-level visibility
- Salesforce platform monitoring and infrastructure controls
LeadFlow Security Approach
LeadFlow is designed as a native Salesforce lead-routing
application. Its routing configuration, group membership, and
assignment audit records remain within the customer’s Salesforce
organization.
LeadFlow uses purpose-built permission sets for administrators,
routing managers, and runtime execution. These permission sets add
only the object and field access required by each role. LeadFlow
does not grant View All or Modify All access to the standard Lead
object and therefore continues to respect the customer’s existing
Lead record-sharing model.
Salesforce Security Review
JRM Consulting is committed to following applicable Salesforce
security requirements for managed packages and AppExchange
applications. Product review or certification status will be stated
accurately in product documentation and customer communications.
Responsible Vulnerability Disclosure
If you believe you have identified a security vulnerability in a
JRM Consulting product or service, please contact us with a clear
description of the issue, the affected product or page, and any
steps required to reproduce it.
Please do not include passwords, authentication codes, session
identifiers, or confidential customer data in your initial report.
We will acknowledge legitimate reports and work to investigate and
address verified issues.
Security Contact
For security questions, privacy concerns, or vulnerability reports,
contact JRM Consulting.
Last updated: July 2026