Your public Salesforce site may reveal more than its pages show.
OrgRecon discovers public Experience Cloud surfaces, proves what anonymous visitors can access, and turns deterministic evidence into clear remediation.
Discover. Prove. Explain. Verify.
Every stage produces a distinct conclusion. Discovery is never presented as exposure, and an incomplete result is never presented as clean.
Map the public Salesforce surface.
OrgRecon first qualifies the submitted target, then follows bounded public evidence across routes, artifacts, components, actions, APIs, objects, and related Salesforce hosts.
- Provenance retainedEvery candidate records where it was discovered.
- Boundary preservedDiscovery creates inventory—not an exposure finding.
Test the observable guest behavior.
Supported, non-mutating requests run without customer credentials. Returned records, schemas, and field-value presence are classified independently.
- Evidence requiredOnly deterministic anonymous observations can confirm exposure.
- Limits statedDenied, blocked, unsupported, and inconclusive remain distinct—not clean.
Turn proof into an owner action.
Each finding traces target → route → artifact → component or action → response → object → field classification. Raw customer values are discarded.
- Scanner decidesDeterministic rules create findings and severities.
- AI explainsThe assistant cites curated report evidence and cannot invent or change findings.
Rescan the fix—not the intention.
After remediation, OrgRecon repeats the deterministic guest validation and compares the outcome with the previous immutable report.
- Same proof standardThe new scan must reach a definitive result through supported evidence.
- Resolution earnedA finding is fixed only when the new evidence supports that conclusion.
Experience the conclusion.
Use the evidence-bound AI assistant to understand each finding and get clear, step-by-step guidance for fixing it—based only on the completed report.
Northstar Partner Portal
Anonymous validation confirmed sensitive field-value presence in 5 Salesforce objects. Salesforce reported 2,188,880 matching records; OrgRecon classified presence and counts without downloading every row. Six additional public-control findings affect DNS, TLS, HTTP, mail, public files, and a dangling service binding.
Owner-authorized anonymous assessment · No customer credentials used · No raw field values, record IDs, tokens, cookies, or raw response bodies retained.
Retained for reproducibility: object and field names, Salesforce-reported counts, value-presence classifications, and evidence provenance.Five Salesforce objects returned sensitive field values to a guest context
Bounded anonymous responses reported the illustrative record totals below. OrgRecon classified schema and field-value presence; it did not download every row.
Object API names, Salesforce-reported aggregate counts, schema field names and types, value-presence classifications, and anonymous validation provenance.
Customer_Profile__c · total_count=842731 · Email__c (Email)=value_observed · aura_record_field_probeDiscarded after classification: field contents, record IDs, raw response bodies, tokens, and cookies.Selected public controls around the Salesforce host
These findings add owner-controlled DNS, mail, edge, and public-service context. Each conclusion is backed by the public signal shown below.
See the observations that produced the finding.
Each blob is a privacy-safe projection of discovery, anonymous response, schema, sensitivity, and provenance. Select one to ask AI what it proves and what to review.
Public signals behind the posture findings
Each projection retains only the observation required to reproduce the deterministic rule. Select one to see what it proves—and what it does not.
Ask AI about the selected finding.
How should I remediate anonymous access to Customer_Profile__c?
OrgRecon confirmed that anonymous Salesforce responses returned records and value-present sensitive fields for Customer_Profile__c.
- Open the Experience Cloud site’s Guest User Profile.
- Review object Read access, field-level access, sharing rules, and exposed Apex paths for Customer_Profile__c.
- Publish the change and rescan until the anonymous request is denied or no records are returned.
See what OrgRecon evaluates now—and what comes next.
Current and planned modules stay visibly separate. A future module is never implied by a public Salesforce marker or an existing Experience Cloud result.
Experience Cloud guest observability
OrgRecon maps the bounded public surface and validates anonymous behavior through supported, non-mutating transports.
- Routes and public pages
- Components and framework artifacts
- Controller and action references
- Guest-readable objects and schemas
- Field-value presence without value retention
- Evidence-backed exposure findings
Salesforce platform posture
Salesforce targets receive useful external posture coverage even when no Experience Cloud guest surface is confirmed.
- Salesforce target qualification
- Public identity and OAuth metadata
- Public endpoints and response states
- Technology and framework signals
- Related Salesforce domain relationships
- Customer versus Salesforce responsibility
External internet posture
Selected public controls provide additional context around the submitted Salesforce host and owner-controlled edge.
- DNS and domain posture
- TLS certificates and protocols
- HTTP security controls
- Mail security records
- Public files and exposed components
- Dangling-service bindings
Agentforce public surfaces
Public Agentforce entry points will be inventoried without claiming agent access or execution unless deterministic anonymous evidence proves it.
- Public agents and embedded widgets
- Advertised capabilities and bootstrap markers
- Anonymous session and no-action boundaries
- Evidence and fixture release gates
Heroku correlation
Public applications related to the authorized Salesforce environment will be correlated without expanding ownership or scan scope automatically.
- Public Heroku applications
- Custom domains and certificate identity
- Origin exposure and routing relationships
- Dangling bindings and takeover evidence
Industry-aware risk
Observed exposure will be contextualized by supported industry data classes without changing deterministic evidence or inventing tenant behavior.
- Health and life-sciences context
- Financial-services context
- Education and public-sector context
- Evidence-based severity calibration
More Salesforce public surfaces
Each module ships independently only after its deterministic evidence, privacy, safety, fixture, report, and release gates pass.
See what an evidence-backed Salesforce finding looks like.
Follow an illustrative exposure from anonymous observation to remediation without creating an account.