Find your PII. Prove your controls. Never move your data.
Multi-org Salesforce estates hide PII in fields, files, and attachments. The tools built to find it either miss half of what's there or ingest your data to work. Org Warden runs inside every org you have. Values never leave. You get one ledger of where PII lives, who can see it, and what changed.
Three questions your estate can't answer today.
Every quarter, some combination of these three questions lands on the desk of the person responsible for Salesforce PII. Answering them today means spreadsheets, custom Apex, or a six-figure consulting engagement. Org Warden makes them a report you can run before lunch.
counts · classes · telemetry
Where is PII in our estate?
Who can effectively see it?
What has changed?
Every category default asks you to move your data first. That is the failure mode Org Warden refuses.
- Data leaves the org. Add another processor to your DPA.
- Copies age. Findings drift from the source of truth.
- Security review is about the vendor's environment, not yours.
- Priced like a platform. Six-figure floor.
- Values never leave. No new processor, no new DPA line item.
- Findings live where the data does. Zero staleness.
- Security review is about absence, not architecture.
- Priced per org, predictably, no seat maths.
An audit-ready ledger. Not a dashboard.
Every finding is a row. Every row references a snapshot hash and the rule that produced it. This is the same evidence you would hand a DPO or a regulator, exportable as CSV or PDF. Audit prep measured in minutes rather than months.
| Rule | Field | Records with hits | Check |
|---|---|---|---|
| Contact.Email | 12,481 | format only | |
| CREDIT_CARD | Case.Description | 47 | Luhn |
| UK_NHS_NUMBER | ContentVersion.triage_form.docx | 6 | MOD 11 |
| PHONE | Lead.MobilePhone | 3,190 | format only |
You cannot encrypt what you cannot enumerate. A finding is the first time a control has something to bite on.
Security teams are rarely short of controls. Salesforce already ships encryption at rest, field audit history, field-level security, and event monitoring. What is missing is the list to point them at. Encrypting everything is unaffordable and breaks filtering and sorting; encrypting a guess is a control you cannot defend in a review. Once PII is enumerated per field, per file, per org, with the rule and check that found it and a snapshot hash behind it, the mandate becomes writable: these fields, these orgs, this quarter.
The governance layer Salesforce should have built. And nobody has, yet.
Salesforce ships four discrete tools that touch this problem: Data Detect, Data Mask, Shield, Privacy Center. Each works inside one org. Data Detect scans structured fields, so files and attachments (the biggest blind spot) sit outside it. Shield is an org-level product, and not every org in an estate has it. And none of the four maps PII to who can actually see it across the estate.
Third-party alternatives are worse for a different reason. Varonis and Odaseva ingest your data to work, run in the low six figures, and take months to deploy. AppOmni secures the container without looking inside. Blackthorn masks a single org with no discovery loop. Org Warden sits in the gap the rest describe by their absence.
Scan one org free. See where your PII lives.
No install-to-buy. You get a Baseline Report (the same artefact paying customers get) for one Salesforce org. Metadata-only, always. Your data never leaves your org.