Trust & compliance

Salesforce DevOps Security

AppExchange-reviewed, GDPR, HIPAA, ISO 27001, SOC 2, and NEN 7510 compliant, with zero footprint in your Salesforce org.

Certifications & standards

Compliance built in

The badges Salesforce security teams check for, already in place.

01

AppExchange security review

Serpent passed Salesforce's AppExchange security review, the same bar every listed managed package must clear.

02

GDPR compliant

Data handling follows GDPR requirements for EU customers and their end users, contractually and technically.

03

HIPAA compliant

Healthcare teams can run Serpent alongside PHI-adjacent Salesforce orgs under HIPAA-aligned safeguards.

04

ISO 27001 certified

Serpent's information security management system is independently certified against ISO 27001.

05

SOC 2 compliant

Serpent's security controls are independently audited against the SOC 2 trust services criteria.

06

NEN 7510 compliant

Meets the Dutch healthcare information security standard for teams operating in the Netherlands.

07

AES-256 encryption

All data is encrypted at rest and in transit with AES-256, the industry standard for sensitive data.

Trust pillars

The four pillars of Serpent's Salesforce DevOps security.

How Serpent protects your metadata, credentials, and releases, from your org to the audit trail.

01

Zero org footprint

Serpent runs on standard Salesforce APIs, so nothing is installed, packaged, or patched inside your org.

02

Encrypted everywhere

Every credential, metadata payload, and deployment is encrypted with AES-256, both at rest and in transit.

03

Controlled access

Role-based access control decides who can view, approve, or ship, and every action lands in the audit trail.

04

Independently audited

Serpent's controls are independently certified and audited against ISO 27001, SOC 2, and the standards enterprise buyers check.

Architecture

How Serpent handles your data

Zero footprint in your org, encrypted everywhere, scoped to what you release.

Zero org footprint

Serpent uses standard Salesforce APIs only. Nothing gets installed, packaged, or patched inside your org.

Encryption everywhere

Every deployment, credential, and metadata payload is encrypted with AES-256, both at rest and in transit.

You control what leaves your org

Serpent only reads and stores the metadata and data you scope into a release. Nothing else is touched.

Infrastructure

Secure hosting on Microsoft Azure

Serpent runs on Azure, with regional data centers, certified infrastructure, and isolated networks.

Hosted on Microsoft Azure

Serpent instances and storage run on Microsoft Azure's globally distributed data centers, which support data residency and regional hosting requirements.

Azure certifications

Microsoft Azure holds SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS, HIPAA, and other industry-specific standards.

Physical and network isolation

Azure restricts physical data center access to authorized personnel. Serpent services run inside dedicated Azure Virtual Networks (VNets) for network isolation.

Common questions

Salesforce DevOps security, answered

Zero org footprint, AES-256 encryption, and the standards we hold: ISO 27001, SOC 2, GDPR, HIPAA.

Does Serpent install anything in my Salesforce org?
No. Serpent uses standard Salesforce APIs only, so nothing is installed, packaged, or patched inside your org.
Is Serpent AppExchange security reviewed?
Yes. Serpent passed Salesforce's AppExchange security review, the same standard every listed package must meet.
Is my data encrypted?
Yes. All data is encrypted with AES-256, both at rest and in transit.
Is Serpent GDPR compliant?
Yes. Serpent's data handling meets GDPR requirements for EU customers and their end users.

Start free. No credit card, no install, no commitment.

Zero org footprint, AppExchange reviewed, and ready in under 15 minutes.

Curious about faster shipping before you dive in? Let's talk

Commitment free!