Trust
What this scan reads, and what it never touches
You are being asked to connect a production Salesforce org to a third-party tool. That deserves a straight answer about what happens next, not a privacy policy.
What we read
Configuration metadata about how your pricing is set up — not the prices themselves, and not who you sold to:
- Price rules, their conditions, and their actions
- Product rules and their error conditions
- Discount schedules and their tiers
- Your own Apex classes, triggers, and Flows, to find references to the CPQ (
SBQQ) namespace
What we never touch
- Quotes, quote lines, orders, contracts, and subscriptions
- Accounts, contacts, opportunities, and customer records
- Actual prices, discounts given, or amounts on any deal
- Users, permissions, and login history
The scanner is read-only by construction, not by policy. Our Salesforce client has exactly one HTTP verb — GET. There is no create, update, or delete helper anywhere in it, so no code path exists that could write to your org.
The OAuth scopes we request
Two, and no more:
api— permission to call the Salesforce REST API as you.refresh_token— permission to keep working during a scan that outlives a short-lived access token.
For the skeptical reader: in Salesforce's consent screen the apiscope is labelled “Manage user data via APIs.” That wording sounds like write access. It is the standard REST/SOQL scope, and Salesforce does not offer a read-only variant — every integration that reads anything requests it. What constrains us is not the scope, it is that we only issue GET requests. You can verify that from your side: Setup → Connected Apps OAuth Usage shows every API call we make.
What we keep
The generated report, and nothing else. Raw API responses exist only in memory on our server for the duration of one scan and are discarded when it finishes.
This is enforced structurally rather than by intention. The collector reduces every record as it reads it — condition values, formula text, and Apex source are dropped and replaced with their shape (“has a formula, 340 characters”; “matched on line 87”). The report tables in our database have no column capable of holding a raw payload, so there is nowhere for one to be written even by mistake.
What is stored: rule names, counts, field API names, line numbers, and our findings. If you consider your rule names sensitive, that is the thing to weigh.
Your API limits
A scan uses a few hundred to a few thousand API calls depending on org size, counting against your daily allocation. Scans are capped at 3 per org per 60 minutes, and we back off rather than retry hard when Salesforce pushes back. If your org is already near its limit, the scan stops and says so instead of consuming the rest.
Revoking access
You can cut us off at any time, without asking us, from inside your own org:
- Setup → search for “Connected Apps OAuth Usage”
- Find CPQ Migration Scanner
- Click Revoke
That immediately invalidates our tokens. The Disconnect button in this app does the same via Salesforce's revocation endpoint and additionally deletes our stored copy — but your org's own controls are the authority, and they work whether or not we cooperate. The same screen shows every API call we have made, so you can audit these claims rather than take them on faith.
Payments
Checkout is hosted by Stripe. Card details are entered on Stripe's domain and never pass through this application — we receive a payment confirmation, not a card number.