Metadata-only, drawn.
Two lists. The first is everything a result row or an Evidence Pack may carry. The second has no code path out of the org.
Three layers of write control. If any layer fails, the next one stops the write.
Distribution is not the control. Neither is the runtime check on its own. The write gate is the third and last line. All three are asserted by tests.
Eight testable claims. Every one has a corresponding test suite. If a test breaks, the release does not ship.
These are not marketing copy. They are the sentences a security reviewer can grep for in the codebase.
We will not publish an unverifiable statistic. We will not put a badge-wall on this page. We will not imply a certification we do not hold. Every claim on this site has a corresponding test, a corresponding line of code, or a linked artefact.
If you spot something on this page you would like to reproduce yourself, email security@orgwarden.co.uk and we will walk you through the assertion in the code.
Scan one org free. See where your PII lives.
No install-to-buy. You get a Baseline Report (the same artefact paying customers get) for one Salesforce org. Metadata-only, always. Your data never leaves your org.