Skip to content
SFADDON
Trust & security

Enterprise-grade from day one

SFADDON's security posture and legal documentation in one place.

Data handling

Read. Scan. Wipe.

We never persist raw SuccessFactors data. We read what we need, scan it in memory, and discard the source the moment a scan completes.

Read

OData read access with the scope you define. Standard SF APIs only, never direct DB access.

Scan

All rule evaluation happens in memory. No raw employee records touch persistent storage.

Wipe

Raw data is discarded at scan completion. Only health scores and issue summaries remain.

Security posture

Security is the foundation, not a feature

Data minimization

We process only what is needed and retain only operational results — never raw SuccessFactors PII.

Encrypted at every layer

AES-256-GCM at rest, TLS 1.3 in transit, and encrypted SuccessFactors credentials that are never logged or returned.

Privacy by design

EU-region hosting, MFA enforced, an append-only audit trail, and a published sub-processor list.

Documents

Legal & compliance documentation

Privacy Policy
EU · GDPR-aligned

How we collect, use, and protect personal data across all SFADDON products.

View
Terms of Service
incl. Commercial Terms

The terms governing use of SFADDON products and services, with refund and cancellation detail.

View
Data Processing Agreement
with SCCs

Data-processing terms for GDPR-compliant use; includes Standard Contractual Clauses for transfers.

View
Subprocessor List
30-day change notice

Every third party that may process customer personal data on behalf of SFADDON.

View
Security Whitepaper
on request

Technical description of SFADDON's security controls, encryption, and authentication.

Request
Security certifications
SOC 2 Type IIn preparation · Target 2026
SOC 2 Type IIPlanned · Target 2027
ISO 27001Planned · Target 2027
Questions about our compliance posture?

Security research is welcomed under a 90-day coordinated-disclosure policy with safe harbour for good-faith research.