Your data never leaves your org.
Sojourn is a native managed package built to pass AppExchange security review on the first submission. Here is what that means in practice, and how we check it on every change.
No outside calls
No callouts, Named Credentials, Connected Apps, or third-party JavaScript. Nothing Sojourn records is sent anywhere.
No metadata changes
No Metadata API, Tooling API, or session IDs. Setup lives in Sojourn's own records, and the Flows you create stay yours.
Your permissions apply
Every query and write in a user's context runs in user mode, so people only see and change what their object and field permissions allow.
Two documented exceptions
The capture engine records every change regardless of who saved it. It is designed to run in system context and write only Sojourn's own objects.
Never blocks a save
If tracking fails, your user's save still succeeds. The failure becomes a Tracking Error that an admin can repair in one click.
Deletion is your decision
Nothing deletes your data automatically. Purge is opt-in and scheduled, exports first, archives to a big object, and is logged.
Checked by machines, not by promise.
| Salesforce Code Analyzer v5, AppExchange rules | 0 Critical, 0 High |
| Test coverage, every Apex class | 90% minimum |
| Bulk tests | 200 records |
| Negative tests prove user mode denies access | Required |
Three permission sets.
| Sojourn Admin | Enable objects, run backfill and purge, manage goals and business hours. |
| Sojourn Manager | Reports and dashboards on intervals and daily summaries. |
| Sojourn User | The timeline on record pages, with read access to goals and tracked objects. |