Skip to main content

Legal · Trust

Security Overview

Effective October 3, 2026

1. Architecture in one paragraph

Your Salesforce token is held in your browser tab (sessionStorage + page memory) and sent only to this app's server-side API routes, which forward your authorised request to the Salesforce org URL you supplied and return the response. Tokens are never written to server disks, never logged, and never sent anywhere except your org. Your designs persist in your browser's IndexedDB.

2. Platform controls

  • HTTPS-only transport; strict Content-Security-Policy (font-src 'self', no external fonts or scripts), framing denied, no-sniff, strict referrer.
  • Self-hosted fonts (Inter + JetBrains Mono bundled locally) — zero calls to font CDNs or Google APIs at build or runtime.
  • Server-side rate limiting on Salesforce proxy routes (200 requests/minute per IP, HTTP 429 beyond).
  • Schema writes are create-only and always confirmed: Author mode deploys one change at a time through the Tooling API, with an explicit confirm on production-like orgs and no delete path.
  • No cookies, no analytics beacons, no third-party trackers — there is nothing to steal a session through on our side.

3. Your part (shared responsibility)

  • Use least-privilege, short-lived tokens; prefer sandboxes for exploration and rotate production sessions after use.
  • Never paste a production session into a shared or recorded machine; always Disconnect when finished.
  • Review generated payloads before executing them — the tool drafts, you decide.

4. Reporting an issue

Found a security concern? Email kuldeep@coffeediscussions.com with steps to reproduce. Please do not include live production tokens in the report.