SECURITY

Built for your security review

Avonni installs as a managed package from the Salesforce AppExchange and runs entirely inside your org. It passed Salesforce's security review and is checked again every year.

Annual
Security review
0
Data leaving your org
100%
Salesforce native
APPEXCHANGE REVIEW

Passed the Salesforce Security Review

Reviewed and listed

Avonni is a listed AppExchange package. Passing the security review is a condition of that listing.

Reviewed every year

As a listed package, Avonni goes through the security review annually, not just once at launch.

Native to the platform

Every component is a Lightning Web Component running on Salesforce's own security model. No outside framework sits between your data and your users.

DATA RESIDENCY

Your data stays in your org

No vendor access

Avonni Labs does not have access to your Salesforce data. The components run inside your instance.

No outbound calls

The base package makes no outbound network calls. There is no Avonni-hosted API, no telemetry endpoint, and no CDN dependency. Static assets ship inside the package.

Stays in your region

Data residency follows your Salesforce instance. An EU org keeps EU data. Sub-processors for the package: none.

Support access is temporary and granted by you, through Salesforce's standard Grant Login Access.

Read the security details in the docs
PERMISSION MODEL

It respects your permission model

Avonni runs in the user's context. Queries execute in USER_MODE, so every component honors the access the running user already has.

Field-Level Security

Users see only the fields they are permitted to view. Restricted fields never render.

CRUD permissions

Create, read, update, and delete are checked per object, so no component reaches past a user's object access.

Your sharing model

Role hierarchy, sharing rules, and Apex sharing are all respected. Avonni does not change your sharing rules.

THE MANAGED PACKAGE

What the package installs

Namespaces

Avonni ships as managed packages under these namespace prefixes. You can confirm every installed package and its version in Setup, under Installed Packages.

avonnidc
Dynamic Components
avcmpbuilder
Flow Screen Components
avxp
Experience Cloud Components
ddbuilder
LWC Components
Builders and users are separated

Builder access is gated by permission sets that ship with the package. Standard end users do not need builder access to view components.

What it adds to your org

The package installs Lightning Web Components, Apex classes, custom metadata types, custom permissions, and static resources. Component definitions live in your org in custom metadata. No Avonni package creates custom business objects or modifies your standard objects.

Clean uninstall

Removing the package removes its own records and metadata. Your business records are left untouched.

Outbound traffic only when you configure it

The package itself calls nothing outside your org. Any outbound traffic exists only when you set it up: Named Credentials or Remote Site Settings for an Apex callout in an Interaction, Salesforce Connect for external objects, or an Open URL action. You control each one.

Attestations and compliance

Avonni does not hold an independent SOC 2 report as a vendor. The runtime is Salesforce, which is SOC 2 attested, and Avonni's posture is validated every year by the AppExchange security review. Compliance you already hold on your Salesforce edition, such as SOC 1, 2, and 3, ISO 27001, GDPR, HIPAA through Shield, and PCI-DSS, applies to Avonni components because they run on that platform. A DPA, a mutual NDA, and completed security questionnaires such as SIG and CAIQ are available on request. Avonni is a Canadian company headquartered in Quebec.

Security questions from a reviewer?

Write to security@avonni.app for questionnaires, the DPA, or a responsible disclosure report.

UPDATES AND ENVIRONMENTS

Sandbox and production

You control upgrades

Avonni ships updates as new managed-package versions. You choose when to upgrade in Setup, under Installed Packages. Security fixes are flagged in the release notes, and admins get a direct email when a fix is severe.

Test before you roll out

Sandbox orgs are free with unlimited users, so you can install and validate before production. Production is free for up to 10 internal users, with no time limit.

Read all our AppExchange reviews →
FAQ

Questions a reviewer asks

Has Avonni passed the Salesforce security review?

Yes. Avonni is a listed AppExchange package, which requires passing the review, and it is re-reviewed every year.

Does my data leave Salesforce?

No. The base package makes no outbound calls and reads and writes through Salesforce's own data layer. Your data stays in your instance.

Can Avonni see my data?

No. Avonni Labs has no standing access to your org. You can grant temporary support access through Salesforce's standard Grant Login Access and revoke it at any time.

Does it respect our sharing and field-level security?

Yes. Components run in the user's context and honor Field-Level Security, CRUD, role hierarchy, sharing rules, and Apex sharing. Avonni does not change your sharing rules.

What namespaces and permissions does it use?

The packages install under the prefixes avonnidc, avcmpbuilder, avxp, and ddbuilder. Builder access is gated by permission sets that ship with the package, and standard end users do not need builder access.

Ready for your security review

Install from the AppExchange, or reach our team with any questions from your security team.