Revenue Assurance Security Boundaries
Security and data-handling boundaries for the Haywood Revenue Assurance public demo and guided Salesforce or approved multi-system pilots.
What can the public Revenue Assurance demonstration access?
The public demonstration accesses no customer Salesforce or NetSuite organization, credentials, or records. It uses fixed sample findings. A paid pilot still requires verified identity, approved read-only metadata access, tenant isolation, encrypted secret storage, retention controls, monitoring, and customer authorization before any connection is enabled.
Payment and application access are separate decisions. Purchasing a pilot does not grant Salesforce access, and no production write capability is enabled by default.
Pilot security gate
- 01
Verify the customer, authorized users, Salesforce organization, and environment type.
- 02
Approve read-only OAuth scopes and prohibit password collection.
- 03
Isolate tenant data, credentials, logs, evidence, and encryption keys.
- 04
Document retention, deletion, backup, incident response, and model-processing boundaries.
- 05
Test access revocation and audit logging before onboarding customer data.
Evidence that makes the result reviewable
Identity
Authorized customer sponsor, users, organization, and approved environment.
Access
Read-only OAuth scopes, token lifetime, revocation, and secret-storage controls.
Data
Allowlisted fields, redaction, tenant boundaries, retention, and deletion behavior.
Operations
Monitoring, access logs, incident handling, backup, and recovery controls.
Sample boundary: public examples are illustrative and do not represent a customer result, connected Salesforce organization, or production outcome.
Practical remediation path
- Do not connect an organization until every pilot security gate has an owner and evidence.
- Revoke access immediately when identity, scope, or retention requirements change.
- Revalidate isolation and logging after material infrastructure or model changes.
Questions teams ask during review
Does the public demo retain submitted Salesforce data?
The public demo does not accept a Salesforce connection and should not be given customer data or credentials.
Can Ollama change Salesforce?
No. Ollama explains an allowlisted, redacted finding. It has no Salesforce credentials and no write path.
Where are Azure application secrets stored?
The current Azure release references encrypted Azure Container Apps secrets. Application secrets are never sent to the browser or committed to source control; Key Vault references remain the preferred next hardening step.
Start with the business question—not a credential request.
Tell Haywood Management what decision the assessment should support. No Salesforce connection is created by contacting us.