Skip to main content
This page provides an overview of how ShiftUp handles data security, access, and AI processing when deployed in a Salesforce environment. ShiftUp has passed Salesforce’s comprehensive security audit, including vulnerability scanning and manual penetration testing.

Compliance

ShiftUp is SOC 2 certified. Compliance documentation, including security details and certifications, is available on the ShiftUp Trust Portal.

Service status

Check whether ShiftUp services are online at the ShiftUp Status Portal. The status portal reports the current availability of ShiftUp services.
Security Architecture

Product Architecture

ShiftUp is a SaaS solution that helps companies build a high-quality sales pipeline and advance deals faster using AI agents that perform deep, sales-focused research and generates:
  • Account Plans
  • Opportunity Strategies
  • Relevant Stakeholders & Contact Details
  • Conversational Roadmaps
  • Personalized Outreach Messaging & Cadences
  • Data is never shared across customers

ShiftUp Architecture Foundations

  • Salesforce Managed Package: A Salesforce-approved managed package installed directly in the customer’s Salesforce org.
  • ShiftUp AI Platform: An external AI service leveraged by the managed package to execute agentic workflows and maintain vector databases for research data.

Data Location

  • ShiftUp creates managed Custom Objects for Seller Profiles, Account Plans, Opportunity Strategies, and integration events.
  • AI-generated outputs are written back to the customer’s Salesforce org within ShiftUp managed objects and ShiftUp services. ShiftUp retains generated output research for use in subsequent analyses of the same organization.

Data Ownership

  • Customers retain full ownership of all data stored in their Salesforce org.
  • If a customer stops using ShiftUp, all data remains in Salesforce unless the managed package is explicitly uninstalled.
  • Research data is deleted from the ShiftUp upon contract termination or upon request.

What Triggers an Analysis

  • An Account is added to a Seller Profile.
  • A scheduled refresh (daily or weekly, configured by the customer).
  • A user initiates an on-demand refresh or update request.
  • An Account Note is added to the Account.

Integration Access & Permissions

  • The ShiftUp Platform connects to Salesforce via an External Client Application included in the managed package.
  • Authentication uses OAuth client credentials and runs as a customer-defined integration user.
  • The permissions of this integration are strictly limited to those granted to that user.

ShiftUp Provides an Out-of-the-Box Integration Permission Set

  • ShiftUp managed Objects
  • Required Apex classes
  • Flows

Customers Control Any Additional Permissions

  • Standard Salesforce Objects
  • API access
  • Apex REST service
  • Never shared across customers

Existing ShiftUp Data

  • Previously generated Account Plans and strategies are read to determine what requires updating.

Multi-Tenancy & Data Segregation

  • The ShiftUp AI Platform is multi-tenant. Each request is authenticated using an API key and Salesforce org ID.
  • Internal workflows are logically isolated and keyed by org ID to prevent cross-org access.

AI Model Training

  • ShiftUp does not build, fine-tune, or train AI models using customer data.
  • The platform uses managed AI models from either hosted open source models or trusted managed providers; contractually guaranteed inference data is not used for training.
  • Example providers include OpenAI, Google, Anthropic, Voyage AI, and Mistral AI.

Salesforce Sharing Model & User Access

  • ShiftUp supports private sharing models.
  • Account Plans and Seller Profiles can be configured as private objects.
  • Account Plan ownership can be synchronized with the related Account Owner.
  • Only users assigned ShiftUp permission sets can access ShiftUp’s functionality.

API Usage

  • ShiftUp uses bulkified and composite REST APIs to minimize Salesforce API consumption.
  • Typical usage is approximately 10 inbound calls per analyzed account.
  • Customers are encouraged to configure Salesforce API usage alerts.

External Data Sources & Trust

  • ShiftUp research is public web sources via search providers and custom web scrapers.
  • Stakeholder enrichment may include LinkedIn and other third-party data providers.

External Content is Treated as Untrusted & Processed With:

  • Relevance filtering
  • Freshness checks
  • Evidence requirements with citations and multiple sources, where possible.