Adept Apps Security Standards
Last updated: 30 September 2026
This page describes how Adept Apps LLC ("Adept Apps", "we") builds, tests, releases and supports the applications it publishes on the Salesforce AppExchange, and how we handle security issues. It applies to every Adept Apps product. Product-specific details, such as exactly what an application stores, are in that product's documentation and privacy policy.
1. Who we are
Adept Apps is a small, independent software vendor organized as a limited liability company in Michigan, United States. We build applications for the Salesforce platform and distribute them through the AppExchange. We do not hold any security certification such as SOC 2 or ISO 27001, and we do not claim to. What follows is what we actually do.
2. How we build
- Native only. Our applications are built entirely from Salesforce platform technology: Lightning Web Components, Apex and platform metadata. They run inside the customer's own Salesforce organization ("Org") and nowhere else.
- No infrastructure of our own. We operate no servers, databases, APIs or hosted services that our applications depend on. There is nothing outside Salesforce to breach, and nothing that goes down when we are unavailable.
- No third-party code. Our packages contain no external libraries or frameworks beyond what Salesforce provides. This keeps the code reviewable and free of inherited vulnerabilities.
- No callouts. Our applications make no network calls to any service outside the customer's Org.
- Least privilege. Access to an application's features is granted through permission sets that the customer's administrator assigns. Nothing is granted to users by default beyond what the customer chooses.
- Server-side enforcement. Any rule that matters for privacy or access, such as who may see what, is enforced in Apex on the server, never only in the browser.
3. How we handle data
- Customer data stays in the customer's Org. Our applications do not transmit customer data, user data or usage data to Adept Apps or to anyone else.
- We have no access to customer Orgs. Adept Apps holds no credentials, tokens or connections to any customer environment. We cannot see what an application is doing in a customer's Org, and we cannot reach into it.
- We store as little as the job needs. Where an application needs to keep information at all, it keeps it inside the customer's Org, for as short a time as the feature requires, and the product documentation says exactly what and for how long.
- Sharing and access rules are respected. Our applications never show a user information about records that user could not already see.
- What Salesforce shares with us. When a customer installs one of our applications, Salesforce's License Management Application gives us basic installation information (the installing Org's identifier and edition, the version installed, and the name, email address and company of the installing administrator). Each product's privacy policy describes this in full, along with how long we keep it. We do not sell or share it.
4. How we test and release
- Automated scanning on every release. Every version is scanned with Salesforce Code Analyzer, including the AppExchange security rule set, and with the Partner Security Portal's source scanner, before it is promoted for release. We do not release a version with an unresolved high-severity finding.
- Automated tests. Apex and component tests run on every build, with coverage above the level Salesforce requires for a managed package.
- Install testing. Every release is installed as a real package in a fresh Salesforce environment and checked before it is published.
- AppExchange security review. Every application we list on the AppExchange goes through Salesforce's AppExchange security review process, and we resubmit when Salesforce asks us to.
- Updates are package upgrades. New versions reach customers only through Salesforce's managed package upgrade mechanism. We never modify anything inside a customer's Org directly.
- No secrets in the code. Our packages contain no credentials, keys or tokens.
5. Vulnerability reporting and incident response
We want to hear about any security problem in our applications.
- Report it by email to support@adeptapps.net with "Security" in the subject line. Include the product and version, what you observed and how to reproduce it. Please do not post details publicly before we have had a chance to fix the issue.
- We acknowledge every report within three business days and keep the reporter informed until the issue is resolved.
- We notify Salesforce of any confirmed security vulnerability in one of our applications within 24 hours of confirming it, as the AppExchange Partner Program requires, and we work with Salesforce on any customer communication that concerns their platform.
- We fix and release. A confirmed vulnerability is fixed in a new package version. Customers learn of a security fix through the AppExchange listing's release notes and through the package upgrade itself, and the fix is described in the product's documentation.
- We keep records of which Orgs have our applications installed, so that affected customers can be identified and informed.
6. Who has access
Adept Apps has no employees or contractors with access to customer information. Installation information received from Salesforce is held in Adept Apps' own Salesforce Org, protected by Salesforce's security controls and by multi-factor authentication, and accessible only to the company's principal.
7. Support
Support is provided by email at support@adeptapps.net on a best-effort basis. Support never requires access to a customer's Org; if we need information to diagnose a problem, we ask the customer to describe or screenshot it.
8. Changes
We may update these standards as our practices develop. The current version is always published at https://adeptapps.net/security with its date.
How this applies to Wingman
Wingman is our record presence indicator for Salesforce. It shows which users currently have a record open. It holds only a record identifier and the viewing users' names, inside the customer's Org, for minutes at a time; it writes nothing to the database, makes no callouts, and shows presence only on records the user can already read. Its optional hidden-viewing feature is off until an administrator assigns it and is enforced on the server. Full details are in the Wingman Privacy Policy and the Wingman Terms of Use.
Contact
Adept Apps LLC
support@adeptapps.net
https://adeptapps.net