OrgRecon
Owner-authorized Salesforce assessment

Your public Salesforce site may reveal more than its pages show.

OrgRecon discovers public Experience Cloud surfaces, proves what anonymous visitors can access, and turns deterministic evidence into clear remediation.

Verified owners only Approved hosts only No Salesforce record contents retained
partners.northstar.example
Sign in to continue What a visitor sees
Public routeObserved
Aura surfaceDiscovered
Guest request1 record returned
Field presenceExposure confirmed
Page view ≠ complete access picture

Discover. Prove. Explain. Verify.

Every stage produces a distinct conclusion. Discovery is never presented as exposure, and an incomplete result is never presented as clean.

External discovery

Map the public Salesforce surface.

OrgRecon first qualifies the submitted target, then follows bounded public evidence across routes, artifacts, components, actions, APIs, objects, and related Salesforce hosts.

  • Provenance retainedEvery candidate records where it was discovered.
  • Boundary preservedDiscovery creates inventory—not an exposure finding.
Anonymous validation

Test the observable guest behavior.

Supported, non-mutating requests run without customer credentials. Returned records, schemas, and field-value presence are classified independently.

  • Evidence requiredOnly deterministic anonymous observations can confirm exposure.
  • Limits statedDenied, blocked, unsupported, and inconclusive remain distinct—not clean.
Evidence-bound explanation

Turn proof into an owner action.

Each finding traces target → route → artifact → component or action → response → object → field classification. Raw customer values are discarded.

  • Scanner decidesDeterministic rules create findings and severities.
  • AI explainsThe assistant cites curated report evidence and cannot invent or change findings.
Reproducible verification

Rescan the fix—not the intention.

After remediation, OrgRecon repeats the deterministic guest validation and compares the outcome with the previous immutable report.

  • Same proof standardThe new scan must reach a definitive result through supported evidence.
  • Resolution earnedA finding is fixed only when the new evidence supports that conclusion.

Experience the conclusion.

Use the evidence-bound AI assistant to understand each finding and get clear, step-by-step guidance for fixing it—based only on the completed report.

Northstar Partner Portal

11 open findings5 confirmed guest exposures
Assessment outcome

Anonymous validation confirmed sensitive field-value presence in 5 Salesforce objects. Salesforce reported 2,188,880 matching records; OrgRecon classified presence and counts without downloading every row. Six additional public-control findings affect DNS, TLS, HTTP, mail, public files, and a dangling service binding.

5Guest-readable objects
2,188,880Salesforce-reported matching records
6External posture findings
7Sensitive categories
3 Critical3 High3 Medium2 Low
Evidence and privacy boundary

Owner-authorized anonymous assessment · No customer credentials used · No raw field values, record IDs, tokens, cookies, or raw response bodies retained.

Retained for reproducibility: object and field names, Salesforce-reported counts, value-presence classifications, and evidence provenance.
Critical finding

Five Salesforce objects returned sensitive field values to a guest context

Bounded anonymous responses reported the illustrative record totals below. OrgRecon classified schema and field-value presence; it did not download every row.

Stored report evidence

Object API names, Salesforce-reported aggregate counts, schema field names and types, value-presence classifications, and anonymous validation provenance.

Customer_Profile__c · total_count=842731 · Email__c (Email)=value_observed · aura_record_field_probeDiscarded after classification: field contents, record IDs, raw response bodies, tokens, and cookies.
External internet posture

Selected public controls around the Salesforce host

These findings add owner-controlled DNS, mail, edge, and public-service context. Each conclusion is backed by the public signal shown below.

Normalized report evidence

See the observations that produced the finding.

Each blob is a privacy-safe projection of discovery, anonymous response, schema, sensitivity, and provenance. Select one to ask AI what it proves and what to review.

External internet posture evidence

Public signals behind the posture findings

Each projection retains only the observation required to reproduce the deterministic rule. Select one to see what it proves—and what it does not.

Evidence-bound assistant

Ask AI about the selected finding.

Selected finding · Customer_Profile__c

How should I remediate anonymous access to Customer_Profile__c?

OrgRecon confirmed that anonymous Salesforce responses returned records and value-present sensitive fields for Customer_Profile__c.

  1. Open the Experience Cloud site’s Guest User Profile.
  2. Review object Read access, field-level access, sharing rules, and exposed Apex paths for Customer_Profile__c.
  3. Publish the change and rescan until the anonymous request is denied or no records are returned.
Answer grounded only in the selected finding’s normalized, redacted evidence. This public interaction does not call a live model.

See what OrgRecon evaluates now—and what comes next.

Current and planned modules stay visibly separate. A future module is never implied by a public Salesforce marker or an existing Experience Cloud result.

Experience Cloud guest observability

OrgRecon maps the bounded public surface and validates anonymous behavior through supported, non-mutating transports.

  • Routes and public pages
  • Components and framework artifacts
  • Controller and action references
  • Guest-readable objects and schemas
  • Field-value presence without value retention
  • Evidence-backed exposure findings

Salesforce platform posture

Salesforce targets receive useful external posture coverage even when no Experience Cloud guest surface is confirmed.

  • Salesforce target qualification
  • Public identity and OAuth metadata
  • Public endpoints and response states
  • Technology and framework signals
  • Related Salesforce domain relationships
  • Customer versus Salesforce responsibility

External internet posture

Selected public controls provide additional context around the submitted Salesforce host and owner-controlled edge.

  • DNS and domain posture
  • TLS certificates and protocols
  • HTTP security controls
  • Mail security records
  • Public files and exposed components
  • Dangling-service bindings
Coming Soon

Agentforce public surfaces

Public Agentforce entry points will be inventoried without claiming agent access or execution unless deterministic anonymous evidence proves it.

  • Public agents and embedded widgets
  • Advertised capabilities and bootstrap markers
  • Anonymous session and no-action boundaries
  • Evidence and fixture release gates
Coming Soon

Heroku correlation

Public applications related to the authorized Salesforce environment will be correlated without expanding ownership or scan scope automatically.

  • Public Heroku applications
  • Custom domains and certificate identity
  • Origin exposure and routing relationships
  • Dangling bindings and takeover evidence
Coming Soon

Industry-aware risk

Observed exposure will be contextualized by supported industry data classes without changing deterministic evidence or inventing tenant behavior.

  • Health and life-sciences context
  • Financial-services context
  • Education and public-sector context
  • Evidence-based severity calibration
Coming Soon

More Salesforce public surfaces

Each module ships independently only after its deterministic evidence, privacy, safety, fixture, report, and release gates pass.

Service & KnowledgePublic support portals, articles, attachments, and guest isolation
CommerceStorefront identity, catalogs, public APIs, and customer-data isolation
MarketingForms, preference centers, tracking domains, and enumeration boundaries
Data, Analytics & TableauPublic embeds, metadata boundaries, guest dashboards, and token handling
MuleSoft & public APIsGateways, developer portals, API documents, authentication, and CORS
Public Slack integrationsPublic integration inventory only—not workspace, channel, member, or message auditing

See what an evidence-backed Salesforce finding looks like.

Follow an illustrative exposure from anonymous observation to remediation without creating an account.