Snapshot 57674
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security Built for your security review Avonni installs from the AppExchange as a managed package and runs inside your Salesforce org. No Avonni server sits between your users and your records, and Salesforce reviews the package again every year. Start freeRequest a Demo Everything an Avonni component reads or writes stays inside your org. There is no Avonni backend to call. Annual AppExchange security review 0 Avonni servers in the data path 0 Sub-processors USER_MODE On every query, by default AppExchange security review Reviewed by Salesforce, every year To stay listed on the AppExchange, a package has to pass Salesforce's security review, then pass it again every year and after any major change to its architecture. It is pass or fail. See the listing on AppExchange → What the review covers Static and dynamic analysis of all Apex and Lightning code CRUD and field-level security at every entry point SOQL, SOSL and DML injection Cross-site scripting and request forgery Open redirects and unsafe URLs Storage of secrets and personal data Named Credentials, Remote Site Settings and external endpoints Lightning Web Security compliance Clickjacking, framing and Content Security Policy Need the latest pass confirmation? Write to security@avonni.app. Your data Nothing goes to Avonni Components read and write through Salesforce itself: Apex, Lightning Data Service and the User Interface API. There is no telemetry, no licensing check at runtime, and no Avonni database holding your records. Traffic outside Salesforce exists only when you set it up. Apex callout from an Interaction Goes from → to Salesforce → your endpoint What controls it Named Credential or Remote Site Setting External Object as a data source Goes from → to Salesforce → your system What controls it Salesforce Connect Iframe component Goes from → to Browser → a URL you choose What controls it CSP Trusted Sites Open URL action Goes from → to Browser → a URL you choose What controls it Standard browser navigation Leaflet map Goes from → to Browser → OpenStreetMap, or the tile server you pick What controls it CSP Trusted Sites Your region stays your region. Data residency follows your Salesforce instance: an EU org keeps its data in the EU, a Hyperforce org stays in its region. Salesforce encrypts it. At rest and in transit, including Shield Platform Encryption when your org has it. Permissions Your permission model decides Every query runs as the viewing user, in USER_MODE. If a user can't see a record in a list view, they can't see it in an Avonni component either. Object access Field-level security Sharing What this user sees Field-level security A field the user can't read never reaches the browser. Salesforce refuses the query rather than return it. Object permissions Create, read, edit and delete are checked per object, on every read and every write. Sharing Org-wide defaults, role hierarchy, sharing rules, manual and team shares, Apex managed sharing. Avonni changes none of them. In a screen flow, a query can switch to system mode for reads. It is off by default, and actions that write always run as the user. Access We can't log in to your org Avonni has no credentials, no integration user and no standing access. Your users sign in to Salesforce, with your SSO, MFA, IP ranges and session rules. Grant Account Login Access, in a Salesforce org with Avonni installed. Support access exists only if you grant it. You grant it, for the time you pick, and it ends on its own. Every session shows in your Login History and Setup Audit Trail. If your policy forbids it, we work from screen shares and exported configuration. The managed package What your architect will find in Setup Three managed packages, each under its own namespace. Install one now and add the others when you need them. Setup, Installed Packages, in a Salesforce org with Avonni installed. Other packages are hidden. Package Namespace What it covers Avonni Experience Components avxp App Builder, Dynamic and Experience Sites components Avonni Flow Screen Components avcmpbuilder Screen flow components Avonni LWC Components avonni Components for your own Lightning web components Orgs still on the older standalone Dynamic Components package see it as Avonni Dynamic Component, namespace avdynamic. What it installs Lightning web components, Apex classes, custom metadata types, custom permissions and static resources. Component definitions are custom metadata records in your org, so your backup and sandbox tooling already covers them. Builders and users Builder access comes from permission sets shipped with the package. People who only use the components don't need it. Clean uninstall Uninstalling removes the package and its component definitions, so export them first. Your business records are not touched. Shared responsibility Who owns what Like every Salesforce extension, security is shared between the vendor and your team. Avonni Passing the AppExchange security review Enforcing FLS, CRUD and sharing in the package code Flagging security fixes in the release notes Answering disclosure reports within one business day Reaching your org only through login access you grant Keeping customer data and credentials confidential Your team Configuring components, queries and actions to your policies Keeping FLS, CRUD and sharing right on the objects you use Reading release notes and upgrading on your schedule Reporting suspected issues to security@avonni.app Granting, scoping and revoking that access Users, SSO, MFA, IP ranges and session policies Compliance Your Salesforce certifications cover Avonni Avonni processes your data only inside your org, so the certifications of your Salesforce edition apply to what your users do in it. SOC 1 SOC 2 SOC 3 ISO 27001 ISO 27017 ISO 27018 FedRAMP HIPAA with Shield GDPR PCI-DSS As applicable to your edition. Current certificates are on trust.salesforce.com. Straight answer Avonni does not hold a SOC 2 report of its own. Its security is checked every year by the AppExchange review, and it runs on Salesforce, which is SOC 2 attested. Documents on request The review confirmation, a DPA, a mutual NDA, and completed questionnaires (SIG, CAIQ or your own). Write to security@avonni.app. Found a vulnerability? Email security@avonni.app rather than a public forum. We acknowledge within one business day. Avonni is a Canadian company headquartered in Quebec. Updates You decide when to upgrade No automatic updates New versions never install themselves. You upgrade from Setup, under Installed Packages, when you're ready. Security fixes They are flagged in the release notes, and admins of affected orgs get an email when it's serious. Sandbox first Sandboxes are free with unlimited users. Production is free for up to 10 users, with no time limit. Questions a reviewer asks Has Avonni passed the Salesforce security review? Yes. Avonni is listed on the AppExchange, which requires passing the review, and Salesforce reviews it again every year. Does my data leave Salesforce? Not for Avonni. Components read and write through Salesforce, and nothing is sent to an Avonni service. Traffic outside Salesforce exists only when you set it up: a callout, an external object, an iframe, a URL, or the tiles of a Leaflet map. Can Avonni see my data? No. Avonni has no standing access to your org. You can grant temporary support access through Salesforce's Grant Login Access, and revoke it at any time. Does it respect our sharing and field-level security? Yes. Queries run as the viewing user, in USER_MODE. A field the user can't read makes Salesforce refuse the query rather than return it, and records follow your sharing rules. Which namespaces does it use? avxp for Experience Components, avcmpbuilder for Flow Screen Components, avonni for LWC Components. The older standalone Dynamic Components package uses avdynamic. Why do some Apex classes run without sharing? A few internal classes read only the package's own custom metadata, the component definitions, which have no record-level access. They never read your business records. Ready for your security review Install in a sandbox and run your own checks, or send your questionnaire to security@avonni.app. Start freeRequest a Demo