Our clients give us access to their customer records, their Salesforce orgs, and their data platforms. This page describes the standards we follow to protect that access and that data.
Overview
Security is part of how we deliver every engagement. We work inside our clients' environments whenever we can, give each person and system only the access the work needs, and remove that access when the work ends. The contract for each engagement sets out the specific security, confidentiality, and data protection terms that apply, and those terms take precedence over this page.
How we handle client data
- We process client data only on the client's instructions and only for the purposes of the engagement.
- We work in client-provided environments, accounts, and tools wherever possible, so client data stays under the client's own controls.
- We do not copy client data to personal devices, personal accounts, or tools the client has not approved.
- We use the minimum data needed for each task, and use masked, sampled, or synthetic data for development and testing where possible.
- At the end of an engagement, we return or delete client data as the contract requires.
Salesforce and platform delivery
- We build and test in sandboxes and promote changes to production through a controlled release process agreed with the client.
- We do not load unmasked production data into lower environments without the client's approval.
- Each team member uses a named account. We do not share logins.
- Integration users and connected apps get the narrowest permissions that work, and their credentials are stored in the client's approved secret store.
- Before go-live, we review profiles, permission sets, sharing rules, and field-level security with the client.
- The same practices apply to data platforms, warehouses, and integration tools we work on.
Access control
- Datagist staff sign in to company systems through Microsoft 365 single sign-on with multi-factor authentication.
- Our internal applications are protected by Cloudflare Access and are available only to authorized staff.
- Access to client systems is requested per engagement, limited to the people working on it, and removed when they roll off.
- We remove all access promptly when someone leaves Datagist.
Use of AI tools
- We do not enter client data into public AI tools. AI tools are used with client data only when the client has approved the tool and its data terms.
- AI assistants and agents we build for clients use the client's existing access rules, so users see only what they are already permitted to see.
- Each agent is limited to the data and actions it needs, and its activity is logged.
- We test AI systems for quality and safety before launch and after changes.
Our people
- Everyone who works on client engagements signs a confidentiality agreement before they start.
- Staff receive security and data protection training when they join and periodically after that.
Infrastructure and vendors
We run our business on established providers that maintain their own independent security certifications, including Microsoft 365 for email, documents, and identity, and Cloudflare for our website, internal applications, and storage. Data is encrypted in transit, and storage that holds documents or personal information is private and not exposed to the internet. We review the security and data terms of the tools we adopt.
Our Privacy Policy lists the service providers that handle personal information from this website.
Subcontractors
When we use subcontractors on an engagement, they are bound by written agreements with confidentiality and security obligations at least as protective as ours, and they follow the client data practices on this page. We tell clients when subcontractors will have access to their systems or data.
Incident response
If we become aware of a security incident affecting client data or systems, we act to contain it, investigate it, and notify the affected client without undue delay and within the time set by our contract. We work with the client on remediation and share what we learn.
Security reviews and documentation
We complete client security questionnaires and vendor due diligence reviews as part of onboarding, and can share further detail on these practices under a non-disclosure agreement. Contact us to request it.
Reporting a security issue
If you believe you have found a security vulnerability in our website or applications, or have a concern about how we handle data, email [email protected] with the subject line "Security." Please give us a reasonable time to investigate and fix the issue before disclosing it publicly.
Datagist LLC, Attn: Security11720 Amber Park Drive, Suite 160
Alpharetta, GA 30009, United States
[email protected] · (888) 843-2680